We Ship a Weaker Trust Model Than the Name Suggests, and the Difference Is the Whole Page
What we run is not the property this term describes, and saying which is the reason for the page.
What the phrase promises
Run a model on somebody else's hardware such that the operator cannot see your input and you cannot see their model. Both sides get what they need and neither learns the other's secret.
That is a strong property. It is also a specific one, obtained through hardware enclaves or cryptographic techniques with real overheads, and it is either present or it is not.
The phrase gets used loosely for anything privacy-adjacent running on remote compute, which is how a buyer ends up believing they bought the strong version.
Why it matters commercially rather than academically
Because it decides whether you can send a regulated input to a third party's machine at all.
If the operator genuinely cannot observe the input, the compute provider is not a data processor in the way that matters, and a whole category of contractual and regulatory work shrinks. If the operator merely promises not to look, you have an ordinary vendor relationship with an ordinary risk profile, and every obligation that comes with one.
Same architecture diagram, different legal position. That is the gap worth being careful about.
What we actually run
Our node product ships a build that runs models on operator hardware using a standard runtime with GPU acceleration. An operator downloads it and runs it.
The operator can see the inputs. What makes the arrangement trustworthy today is not sealing but accountability: an operator is identified, has posted a stake, and faces consequences for misbehaviour that can be detected.
That is a weaker and more conventional trust model, and it is easy to mistake for the strong one because both involve running somebody else's work on somebody else's machine.
Sealed inference itself is not built. No enclave attestation, no cryptographic guarantee that the operator cannot observe an input. There is no roadmap date, and naming that as a boundary is more useful than a quarter we have not chosen.
Why we are naming the weaker model explicitly
Because the failure mode here is not a lie, it is a reader's reasonable assumption.
A buyer who hears "confidential compute" and receives "economically accountable compute" has been misled without anyone writing a false sentence. The honest fix is to name the mechanism rather than the category, so we do: identified operators, posted stake, detectable misbehaviour, and no cryptographic seal.
What is already done is that accountability layer, plus the identity infrastructure it rests on: operators with verifiable identities, credentials that can be revoked, and a registry a counterparty can check.
The honest limit on the accountability model too
Economic accountability only works against detectable misbehaviour.
An operator who copies an input and never acts on it has done something the system cannot observe, and no stake is slashed for a thing nobody can prove. So the model deters interference with results far better than it deters quiet observation.
If your input is sensitive enough that quiet observation is the threat, this arrangement does not address it, and the strong property that would is the one we have not built.
What to ask any confidential-compute vendor
"Is there hardware attestation, and can I verify it myself?" A seal you cannot check is a promise with extra vocabulary.
"What exactly can the operator observe?" Ask for the list, not the category. For us the answer is the inputs.
"What is the penalty for observation as opposed to interference?" Most accountability designs punish the second and cannot detect the first.
"What is the overhead?" Real sealing costs real performance. A vendor claiming the strong property at no cost is claiming something unusual and should be asked to show it.
Where this leaves a decision
If your inputs cannot be exposed to a compute operator under any circumstances, we do not offer that property, and no accountability arrangement substitutes for it.
If your concern is that a remote operator might tamper with results or disappear, that is what the model we run is built against, it is honest about its own limit, and the stronger version is a thing we have not built rather than a thing we have renamed.