Document multi-provider model choices (Tinfoil private + GreenPT green)
This commit is contained in:
1 parent
89152f0724
commit
5724b0ca2f
3 files changed
+68
-20
No files matched your search
+28
-14
@@ -98,24 +98,38 @@ edit, and ask for review.
|
||||
|
||||
Questions about the Git itself? Write to info@inference.coop.
|
||||
|
||||
## Models and privacy
|
||||
## Models and providers
|
||||
|
||||
Inference runs through [Tinfoil](https://tinfoil.sh/inference), which provides
|
||||
**architectural** privacy: models run inside hardware enclaves (TEEs), and
|
||||
request/response bodies are encrypted end-to-end (EHBP), so even Tinfoil's own
|
||||
infrastructure can't read them. This is verifiable via remote attestation — not
|
||||
just a policy promise. A local Tinfoil proxy sidecar handles the encryption on
|
||||
our side of the gateway.
|
||||
The co-op serves models from multiple providers, named `provider/model-name` so
|
||||
members can choose both *which* model and *where* it runs. Each provider carries
|
||||
a value you can route by:
|
||||
|
||||
Three models are exposed:
|
||||
| Provider | Value | How it works |
|
||||
|---|---|---|
|
||||
| **Tinfoil** | *private* | Models run inside hardware enclaves (TEEs); request/response bodies are encrypted end-to-end (EHBP), so even Tinfoil's infrastructure can't read them. Verifiable via remote attestation. |
|
||||
| **GreenPT** | *green* | Models served on 100% renewable energy in the EU. Standard (non-enclave) hosting — cleaner energy, but privacy is a policy commitment, not architectural. |
|
||||
| **PublicAI** | *public* | (coming soon — publicly developed models.) |
|
||||
|
||||
- **DeepSeek V4.1 Flash** — default, agentic tasks.
|
||||
- **GPT-OSS 120B** — lightweight fallback.
|
||||
- **GLM-5.3 Flash** — fast, efficient.
|
||||
Five models are currently exposed:
|
||||
|
||||
The honest caveat: your **chat history** is stored on our server so you can
|
||||
revisit it, and that stored history is not encrypted in a way that prevents us
|
||||
from technically reading it. We commit not to. The full distinction — what's
|
||||
- **DeepSeek V4.1 Flash** (`deepseek-v4-1-flash`) — default, agentic tasks. *(Tinfoil)*
|
||||
- **GPT-OSS 120B** (`gpt-oss-120b`) — lightweight fallback. *(Tinfoil)*
|
||||
- **GLM-5.3 Flash** (`glm-5-3-flash`) — fast, efficient. *(Tinfoil)*
|
||||
- **Green-R** (`greenpt/green-r`) — reasoning, renewable energy. *(GreenPT)*
|
||||
- **Green-L** (`greenpt/green-l`) — lightweight, renewable energy. *(GreenPT)*
|
||||
|
||||
The three Tinfoil models currently use their bare names (no `tinfoil/` prefix);
|
||||
they'll be renamed to `tinfoil/…` in an upcoming, announced change.
|
||||
|
||||
A local Tinfoil proxy sidecar handles the enclave encryption on our side of the
|
||||
gateway.
|
||||
|
||||
The honest caveat: only **Tinfoil** offers architectural privacy. The other
|
||||
providers are chosen for their value (renewable energy, public models) but do
|
||||
not run in enclaves — prompts and responses pass through them in the ordinary
|
||||
way. Your **chat history** is also stored on our server so you can revisit it,
|
||||
and that stored history is not encrypted in a way that prevents us from
|
||||
technically reading it — we commit not to. The full distinction — what's
|
||||
architecturally private versus what's a policy commitment — is in the
|
||||
[Privacy Policy](privacy-policy.md).
|
||||
|
||||
|
||||
Reference in new issue
Block a user