Verify it

Don't trust. Verify.

A privacy claim you cannot check is just marketing. Every part of Privasys Chat is built to produce evidence: proof of what hardware you are talking to, proof of what software it runs, and a signed record of every answer.

The hardware shows its passport.

Confidential processors can produce a signed statement of exactly what they are running, called an attestation. Think of it as a passport, issued and signed by the chip manufacturer, that lists the machine, the software it booted, and the model it loaded.

Before your first message, the chat requests a fresh attestation from the enclave and has it checked by an independent verification service. If anything does not match, from the processor's signature to the fingerprint of the AI model, you are warned before a single word leaves your browser. The checks run again throughout your session, not just at the start. The full mechanics are described in the attestation documentation.

The green shield, decoded.

In the chat sidebar, 'Secure enclaves attestations' opens the Security panel: the live, human-readable view of that evidence.

The panel is green only when every component verifies. Anyone can perform the same verification independently with the published tooling; you do not need to trust our green tick.

Reproducible answers, for audit and compliance.

Ask the same question with the same settings and you get the exact same answer, byte for byte. Most AI services cannot promise that; here it is a design goal.

Every reply carries reproducibility metadata: the model digest, the server image fingerprint, the software versions and the sampling seed that produced it. Open Metadata under any reply to see its receipt. With that receipt, the same prompt can be replayed later, by you, an auditor or a regulator, and produce the identical output. For enterprises this is the difference between “the AI said so” and a decision trail you can stand behind: answers that influenced a decision can be re-derived, checked and archived. Replies are signed by the attested hardware, so the receipt also proves where the answer came from.

Checked by an independent referee.

The attestation is not verified by the same machine that produced it. A separate attestation service, whose own code and policies are published, checks the signatures against the chip manufacturers' certificates.

This separation matters: the inference machine cannot vouch for itself, and Privasys cannot quietly change what “verified” means. Developers can call the same verification API directly; see the API documentation.

Go deeper

The full technical detail, from architecture to APIs, lives in the documentation:

See the evidence for yourself.

Sign in with the Privasys Wallet for the full verified experience, or contact us if you have specific requirements.