Privacy begins before the request
Encryption in transit is only one part of a private inference system. The client also needs evidence about the environment that will decrypt and process the request.
Enclave’s design puts the attestation check before secret release. If a quote or measurement policy fails, the request does not proceed to key release.
One composite boundary
A GPU confidential mode does not by itself describe the CPU environment that coordinates inference. The backend specification requires a composite CPU and GPU quote checked against vendor roots and the current policy.
A policy that can change
Measurement policy versioning allows approved serving images and security updates to evolve. Static measurement pinning is not the intended operating model. Registry changes and revocations must be enforced.
What the preview can demonstrate
The dashboard offers both successful and failed attestation simulations. Failure blocks the preview before a receipt or usage charge is created. This demonstrates the control flow; it is not remote hardware verification.
