Home / Companies / TrustedRouter / Blog / Post Details
Content Deep Dive

ZDR is a vague promise. Attestation is precise proof

Blog post from TrustedRouter

Post Details
Company
Date Published
Author
Joseph Perla
Word Count
457
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

TrustedRouter argues that privacy claims, zero-retention policies, and open-source code alone cannot prove that an AI routing service’s live infrastructure cannot access prompts, because conventional gateways decrypt requests in ordinary server processes that operators could potentially inspect or alter. It says its public TLS endpoint runs inside a measured GCP Confidential Space workload, where the private TLS key and prompt-handling logic remain isolated, while a separate control plane manages accounts, credits, and metadata without receiving prompt or output content. Clients can verify fresh attestation evidence tied to the TLS certificate and compare the workload’s issuer, audience, source commit, image reference, and image digest against publicly published release information before sending requests. The service distinguishes its own privacy boundary from that of downstream model providers, publishing each provider’s retention and confidential-computing posture, with its ZDR and end-to-end encrypted routes failing closed if compliant providers are unavailable. It concludes that verifiable attestation offers stronger evidence of which code processes prompts than policy statements or labels such as “zero data retention.”

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.