ZDR is a vague promise. Attestation is precise proof
Blog post from TrustedRouter
TrustedRouter argues that privacy claims, zero-retention policies, and open-source code alone cannot prove that an AI routing service’s live infrastructure cannot access prompts, because conventional gateways decrypt requests in ordinary server processes that operators could potentially inspect or alter. It says its public TLS endpoint runs inside a measured GCP Confidential Space workload, where the private TLS key and prompt-handling logic remain isolated, while a separate control plane manages accounts, credits, and metadata without receiving prompt or output content. Clients can verify fresh attestation evidence tied to the TLS certificate and compare the workload’s issuer, audience, source commit, image reference, and image digest against publicly published release information before sending requests. The service distinguishes its own privacy boundary from that of downstream model providers, publishing each provider’s retention and confidential-computing posture, with its ZDR and end-to-end encrypted routes failing closed if compliant providers are unavailable. It concludes that verifiable attestation offers stronger evidence of which code processes prompts than policy statements or labels such as “zero data retention.”
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.