Private LLM API — Verifiable, Attested, Open Source
A private LLM API where privacy is cryptographically verifiable. Route to Claude, GPT, Gemini, DeepSeek through an attested gateway.
A private LLM API where "private" means cryptographically verified.
Every hosted LLM provider claims privacy. Almost none of them give you a way to verify it.
TrustedRouter routes to every major model — Claude, GPT, Gemini, DeepSeek, Kimi, Llama, Mistral — through a hardware-attested gateway. The code is open source. The image is hashed. You can check what runs.
client = OpenAI(
base_url="https://api-azure.trustedrouter.com/v1",
api_key="sk-tr-v1-..."
)
resp = client.chat.completions.create(
model="anthropic/claude-sonnet-4.6",
messages=[
{"role": "user", "content": "your prompt"}
],
)
# No logs. Source verified. Attestation on demand.
Read the source.
Every line that handles your prompt is on GitHub. Search it. Audit it. Run it locally if you want.
Hardware-rooted trust.
The gateway runs inside GCP Confidential Space. The hardware-backed attestation signs the running image. You verify the signature.
No request without attestation.
If the gateway can't prove its own integrity, traffic stops. The synthetic monitor probes this every minute and pages on the first miss.
Things that are zero, with proof.
Prompt body. Never written to disk. Never shipped to a logging service. The binary doesn't open a write handle to a prompt path. You can grep for this.
Output body. Same. The streamed response goes from upstream provider straight back to you. TR sees it in transit; it never persists.
Per-request audit trail. What TR does log: token counts, timestamps, model id, region, billing. No content. The schema is in the open-source code.
Upstream provider behavior. Out of TR's control. We publish each provider's known retention and ZDR posture on every model page so you can route deliberately.
Current routes, prices, privacy, and measured performance.
Catalog facts come from the routes currently configured in TrustedRouter. Performance uses the same cached metadata snapshot as the public leaderboard. Prompts and outputs are not part of these measurements.
| Model | Providers | Context | Input | Output | Privacy | Measured route |
|---|---|---|---|---|---|---|
Anthropic: Claude Opus 4.8anthropic/claude-opus-4.8 |
3 routes | 1,000,000 | $5.25/1M | $26.25/1M | varies 5 cited scores | 1598 ms TTFT anthropic · 100.00% available · n=5 |
OpenAI: GPT-5.5openai/gpt-5.5 |
4 routes | 1,050,000 | $5.25/1M | $31.5/1M | ZDR 3 cited scores | Warming up |
Google: Gemini 3.5 Flashgoogle/gemini-3.5-flash |
7 routes | 1,048,576 | $1.575/1M | $9.45/1M | ZDR | measured google-ai-studio · 0.00% available · n=14 |
MoonshotAI: Kimi K2.7 Codemoonshotai/kimi-k2.7-code |
19 routes | 262,144 | $0.735/1M to $0.9975/1M | $3.675/1M to $4.2/1M | ZDR 5 cited scores | measured inceptron · 0.00% available · n=14 |
Z.ai: GLM 5.2z-ai/glm-5.2 |
45 routes | 1,048,576 | $0.714/1M to $1.575/1M | $1.575/1M to $5.5125/1M | E2EE 4 cited scores | measured engy · 0.00% available · n=73 |
MiniMax: MiniMax M3minimax/minimax-m3 |
21 routes | 1,048,576 | $0.2835/1M to $0.63/1M | $1.155/1M to $2.52/1M | ZDR 4 cited scores | 2056 ms TTFT wafer · 100.00% available · n=21 |
Browse every modelReview provider policiesOpen the full leaderboardSnapshot 2026-08-05T02:34:40Z