Skip to content

Confidential inference

Coming soon

confidential is the third data mode of the API. It is reserved for running inference in an attested confidential environment. It is not available yet: this page describes how the API behaves until it is.

  • The value is part of the API contract. data_mode can read standard, zero_retention or confidential in the belarel block, so you can write code that recognizes all three.
  • You cannot select it. Keys are created as standard or zero_retention only, and POST /v1/keys accepts only those two values for a sub-key.
  • Calls are refused. If a key in confidential mode makes an inference or embeddings call, the API answers 501 with the code not_implemented. Nothing is sent to a model and nothing is billed.
{
"error": {
"message": "Confidential inference (attested enclave) is not available yet for API keys — use a standard or zero_retention key",
"type": "api_error",
"code": "not_implemented",
"param": null
}
}

Confidential inference is meant for workloads where you need evidence about where your content is processed, not only a policy about how it is retained: the model would run in an isolated, attested environment, and a call would only be served once that environment has been verified. Until that is available and documented here, treat the mode as a placeholder and make no security decision based on it.