RESEARCHED PROVIDER · PRIMARY SOURCES

Phala

Confidential GPU hosting and open dstack software for deploying model-serving applications.

INPUT / OUTPUT PRIVACY

Stage 1

Partial proof

ASSESSED DEPLOYMENT

Customer-deployed GPU inference

RESEARCH REVIEW

2026-10-06 · primary-source review

Provider website

Verification labels describe capabilities established by the cited sources. This review did not perform live cryptographic attestation, reproduce production builds or complete an independent security audit.

Who actually runs the models?

Phala Cloud provides GPU confidential VMs where customers deploy vLLM and model weights. Its dstack software runs the confidential infrastructure. Inclusion covers these actual model deployments, not third-party inference aggregation through RedPill.

Deployment and TEE coverage

Assesses Phala's GPU TEE hosting capability. Each application has its own owner, serving code, endpoint, retention and keys; this is not a blanket rating for applications built on Phala.

Select a GPU TEE instance and verify both Intel TDX and NVIDIA confidential-compute state. A CPU-only confidential VM or an agent calling an external model API does not establish protected GPU inference.

At least one content layer has independently checkable technical evidence, including partial proof within a layer. The full privacy boundary is incomplete. The stage tooltip distinguishes partial findings from fully met requirements for Stage 2.

STEPS FOR STAGE 2

1 of 3 requirements for Stage 2 met. Missing proof: Request path, Logs & storage.

  1. Request pathNot established

    Private inputs and outputs across the request path, with E2EE or an equivalent attested channel that protects against intermediaries and binds keys to the accepted workload.

    Documented only. TLS and keys require review

  2. Inference executionMet

    Protected inference with a verifiable workload identity and protection covering the CPU, GPU and every place content is processed.

    Technically verifiable. CPU + GPU checks available

  3. Logs & storageNot established

    No content logging, persistent storage, human review or training. Any temporary content-derived cache must have verifiable isolation and enforced removal.

    Unknown. Retention not established

Identity and operational metadata are assessed separately below. They do not set the content stage; prompt or response content in telemetry remains part of the content-retention assessment.

Request path

Documented only

Deployment-specific. dstack supports TLS termination inside a confidential VM. The application must expose evidence and bind the channel to the expected workload. Arbitrary customer deployments can add gateways or export data, so the platform alone cannot establish an end-to-end private channel.

Inference execution

Technically verifiable

Attestable GPU CVM. Public procedures cover CPU quotes, local NVIDIA verification, application configuration hashes and pinned container images. This establishes an available verification capability for a correctly configured deployment. It does not establish the model-weight identity or security behavior of every customer application.

Logs & storage

Unknown

App-dependent. Encrypted disks protect stored data from the host, but customer serving code can retain or export content. The reviewed platform guides do not establish one content-retention policy across application logs, caches, backups or training.

Identity & metadata

Unknown

App-dependent. A confidential VM does not hide client IP addresses, account records or traffic timing. The reviewed deployment documents do not establish end-user metadata collection, linkage and deletion for each hosted inference application.

No primary evidence establishing this factor was found in the reviewed record.

Remaining trust assumptions

  • Intel TDX, NVIDIA confidential computing and their verification chains.
  • Reviewed dstack components and the application's pinned containers, endpoint and key configuration.
  • The application owner's code and update policy; host isolation does not exclude malicious application behavior.

Limits of this assessment

  • Infrastructure confidentiality is not a no-logging guarantee.
  • Model weights and external API calls need separate boundary checks.
  • Ratings describe hosting capabilities; no customer's live deployment was verified.

Primary-source record

3 sources · reviewed 2026-10-06

Back to providers

Sources reviewed 2026-10-06