Venice
Venice's documented self-hosted Private tier, separated from its upstream-model proxy routes.
INPUT / OUTPUT PRIVACY
Stage 0Privacy claimed
ASSESSED DEPLOYMENT
Venice-controlled Private tier
Verification labels describe capabilities established by the cited sources. This review did not perform live cryptographic attestation, reproduce production builds or complete an independent security audit.
Who actually runs the models?
Venice documents self-hosted open-weight models and Venice-controlled GPUs. Private mode also includes partner infrastructure, so its label alone does not establish self-hosting. Only the claimed Venice-controlled hosting tier is included; partner API routes are excluded.
Deployment and TEE coverage
Assesses normal text inference on Venice-controlled GPUs. Anonymous frontier-model routes, partner-hosted Private routes, and NEAR AI/Phala TEE and E2EE routes are excluded. The reviewed catalog does not identify the serving host for every Private model, so no particular model is asserted to be Venice-hosted.
TEE/E2EE support belongs to selected partner-hosted models, not the whole platform or this assessed hosting tier. The 2026-10-06 public text catalog advertised 12/128 entries supporting TEE attestation and 12/128 supporting E2EE. Capability flags are claims, not live attestation or evidence of Venice-operated GPU workers.
Why Stage 0?
Stage requirementsPrivacy is claimed or promised by policy, but independently checkable technical proof of content protection has not been established for the assessed path.
STEPS FOR STAGE 1
Stage 1 requires technical proof for at least one content layer. None is established in the reviewed record.
Any one proven step earns Stage 1. All three must be proven for Stage 2.
- Request pathNot met
Private inputs and outputs across the request path, with E2EE or an equivalent attested channel that protects against intermediaries and binds keys to the accepted workload.
Operator access. Venice can process plaintext
- Inference executionNot met
Protected inference with a verifiable workload identity and protection covering the CPU, GPU and every place content is processed.
Operator access. Operator remains trusted
- Logs & storageNot established
No content logging, persistent storage, human review or training. Any temporary content-derived cache must have verifiable isolation and enforced removal.
Documented only. Cache lifecycle unresolved
Identity and operational metadata are assessed separately below. They do not set the content stage; prompt or response content in telemetry remains part of the content-retention assessment.
Request path
Operator accessTLS proxy. Normal Private-mode requests use HTTPS through Venice's proxy without client-side encryption to an attested workload. Venice remains trusted with plaintext in transit. An E2EE-capable model ID alone does not enable E2EE; the separate partner flow requires client verification and encryption.
Inference execution
Operator accessPolicy-based inference. The scoped Private tier relies on behavioral and contractual controls. Reviewed documentation does not establish a confidential workload or attestation-bound key that excludes Venice's administrators from plaintext execution. Partner enclave protections cannot raise the rating for Venice's own hosting.
Logs & storage
Documented onlyDocumented ZDR. Venice documents no content logging for normal inference and contract-enforced zero retention for Private mode. Its caching guide describes reuse of processed prompt tokens across requests, but does not establish the scoped hosting tier's cache isolation and deletion controls. No technical retention enforcement is established; browser history, media and external tools are outside this text-inference scope.
Identity & metadata
Documented onlyAccount & usage records. Documentation lists account/wallet and API-key identifiers, IP/device data, request times, model selection, token usage and billing records. The privacy policy uses purpose-based retention with legal and backup exceptions rather than a complete fixed schedule. Identity masking from upstream providers does not make the user anonymous to Venice.
Remaining trust assumptions
- Venice's self-hosting claim; Private-mode flags do not prove the serving GPU operator.
- Venice's proxy, inference software and administrators honor their handling commitments.
- Account, billing and security records are handled separately from prompt content.
Limits of this assessment
- Inclusion is scoped to documented own hosting, not Venice's aggregated catalog.
- No public per-model hosting map was established; catalog owned_by is not evidence of physical hosting.
- Partner TEE/E2EE is available, but is excluded from this provider's own-hosting score.
- Policy statements do not establish technical enforcement; no live attestation or security audit was performed.
Primary-source record
7 sources · reviewed 2026-10-06
Sources reviewed 2026-10-06