RESEARCHED PROVIDER · PRIMARY SOURCES

NEAR AI

NEAR AI's own confidential GPU fleet, assessed separately from its third-party and Incognito API routes.

INPUT / OUTPUT PRIVACY

Stage 1

Partial proof

ASSESSED DEPLOYMENT

NEAR-hosted Confidential TEE tier

RESEARCH REVIEW

2026-10-06 · primary-source review

Provider website

Verification labels describe capabilities established by the cited sources. This review did not perform live cryptographic attestation, reproduce production builds or complete an independent security audit.

Who actually runs the models?

The Confidential TEE tier runs models on NEAR AI's own GPU fleet. Its 3P Confidential TEE and Incognito tiers route to other providers; both are excluded from this entry.

Deployment and TEE coverage

Only NEAR's own model deployments are assessed. Use canonical model IDs and verify the NEAR model evidence as well as the gateway; gateway-only verification is insufficient to identify the inference provider.

NEAR documents Intel TDX and NVIDIA confidential GPUs for its own private inference nodes. Incognito models execute outside this boundary. Third-party TEE models have different verification chains and SDK coverage.

At least one content layer has independently checkable technical evidence, including partial proof within a layer. The full privacy boundary is incomplete. The stage tooltip distinguishes partial findings from fully met requirements for Stage 2.

STEPS FOR STAGE 2

2 of 3 requirements for Stage 2 met. Missing proof: Logs & storage.

  1. Request pathMet

    Private inputs and outputs across the request path, with E2EE or an equivalent attested channel that protects against intermediaries and binds keys to the accepted workload.

    Technically verifiable. Same-connection TLS binding

  2. Inference executionMet

    Protected inference with a verifiable workload identity and protection covering the CPU, GPU and every place content is processed.

    Technically verifiable. CPU + GPU confidential nodes

  3. Logs & storageNot established

    No content logging, persistent storage, human review or training. Any temporary content-derived cache must have verifiable isolation and enforced removal.

    Unknown. Full API lifecycle unclear

Identity and operational metadata are assessed separately below. They do not set the content stage; prompt or response content in telemetry remains part of the content-retention assessment.

Request path

Technically verifiable

Verified gateway. The documented gateway flow can verify fresh gateway evidence, bind the actual TLS connection and check NEAR model evidence. Standard HTTPS alone does not perform these checks. Direct completions endpoints are experimental and have verification limitations, so they are outside the assessed path.

Inference execution

Technically verifiable

NEAR model evidence. Verify every returned NEAR model-attestation candidate with provider=near before a completion. Canonical IDs and x-no-aliasing prevent a model alias from silently changing the assessed route. Response signatures are separate checks; their availability alone does not prove all required deployment properties.

Logs & storage

Unknown

Retention gap. Private inference documentation describes protected processing and no provider access for the scoped tier. The reviewed sources do not establish a complete lifecycle for content logs, prompt caches, stored conversations and backups. The previously indexed Cloud privacy PDF returned HTTP 404 during review; no retention guarantee is inferred from it.

Identity & metadata

Documented only

Account & usage. The gateway manages API keys, authentication, usage tracking and billing. Confidential model execution does not hide these records or traffic metadata. A complete metadata retention schedule and independently checkable deletion controls were not established.

Remaining trust assumptions

  • Intel and NVIDIA hardware isolation and attestation roots.
  • The verified gateway, private model-node code and client verification policy.
  • Selection of NEAR's own Confidential TEE tier rather than a routed upstream model.

Limits of this assessment

  • The NEAR AI brand and a TEE gateway do not imply every catalog model is NEAR-hosted or confidential.
  • Gateway and model verification are distinct; experimental direct endpoints have limitations.
  • No live cryptographic verification or complete retention audit was performed.

Primary-source record

3 sources · reviewed 2026-10-06

Back to providers

Sources reviewed 2026-10-06