Document Tinfoil TEE switch + proxy sidecar

This commit is contained in:
inference-bot committed 2026-09-09 13:28:29 -06:00
1 parent 566c95529d
commit 3fb725d1a3
1 file changed
+3 -1
+3 -1
View File
@@ -53,7 +53,9 @@ The gateway currently exposes two models:
### Privacy
Privacy is a core value. The current LLM backend (Ollama Cloud) is a policy-based privacy model. The roadmap is to move to [TEE-protected inference (via Tinfoil)](https://tinfoil.sh/inference), which provides architectural—not just policy—privacy guarantees.
Privacy is a core value. Inference now runs through [Tinfoil](https://tinfoil.sh/inference), which provides **architectural** privacy: models run inside hardware enclaves (TEEs), and request/response bodies are encrypted end-to-end with the Encrypted HTTP Body Protocol (EHBP), so even Tinfoil's own infrastructure cannot read them. This is verifiable via remote attestation — not just a policy promise.
Because Tinfoil requires EHBP-encrypted request bodies (it rejects plaintext with `426 EHBP_REQUIRED`), the LiteLLM gateway routes through a local [Tinfoil proxy](https://github.com/tinfoilsh/tinfoil-proxy) sidecar, which verifies the enclave attestation and handles the encryption. LiteLLM talks plaintext OpenAI to the proxy; the proxy encrypts and forwards to the enclave.
## Governance