<oembed><type>rich</type><version>1.0</version><author_name>redshift (npub1ft…redsh)</author_name><author_url>https://nostr.ae/npub1ftt05tgku25m2akgvw6v7aqy5ux5mseqcrzy05g26ml43xf74nyqsredsh</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>I understand your concern. I&#39;m also learning this as we go. &#xA;&#xA;Just to note: &#xA;routstrd: routstr daemon that you run locally. it&#39;s a client that communicates with Routstr nodes&#xA;Routstr nodes (they run routstr-core): providers who offer AI models for sats. &#xA;&#xA;routstrd uses our sdk which in turn uses tinfoil&#39;s SDK (https://github.com/Routstr/routstr-sdk/blob/main/client/TinfoilSecure.ts) to encrypt the message body on the client side to Tinfoil&#39;s servers where decryption happens. They have TEE-terminated TLS so you can be sure that the decryption happens inside their TEE. (source: https://confidentialinference.net/providers/tinfoil). &#xA;&#xA;So Routstr nodes, nostr:npub1fetz9dt4eka56h0dpyly335v60mjf7k4gu2z7rqmptkz72e2pvhqvejzfa in this case, cannot read any of your messages, you can verify this by running a node yourself. If there is a way to read your messages it has to be on the Tinfoil side, that is if their system is not well set up. Let&#39;s look at Tinfoil:&#xA;&#xA;Here we are attesting that their TEEs run their released binary on Github. Yes, we are essentially trusting that new Github binaries don&#39;t contain any backdoors. These are the guarantees we have: &#xA;1. The enclave is real AMD SEV-SNP hardware. SEV-SNP report verified against AMD VCEK. &#xA;2. The code inside is the auditable open-source release. Sigstore bundle for tinfoilsh/confidential-model-router.&#xA;3. The measured code is what&#39;s actually running. Enclave measurement == signed release measurement&#xA;4. The request body can only be read by that enclave. EHBP encrypts to attested HPKE public key&#xA;5. A third party can&#39;t pretend to be Tinfoil. Certificate SANs bind HPKE key + attestation hash to *.tinfoil.sh&#xA;&#xA;Auditing everything is very hard for us. Happy to hear any feedback here and improve our setup and/or support better TEE inference providers if any. &#xA;&#xA;Tagging the TEE experts I know here: nostr:npub1aljazgxlpnpfp7n5sunlk3dvfp72456x6nezjw4sd850q879rxqsthg9jp nostr:npub1gzuushllat7pet0ccv9yuhygvc8ldeyhrgxuwg744dn5khnpk3gs3ea5ds nostr:npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj</html></oembed>