Planned architecture
The intended inference path uses a direct public gateway and broker, with company-controlled compute nodes initiating authenticated outbound sessions. Inference nodes are not intended to expose a public listener.
Controls in implementation
- Scoped, hashed API keys and tenant authorization.
- Encrypted transport and separate service identities.
- Content-free operational telemetry and prompt/completion ZDR controls.
- Bounded capacity, cancellation, replay protection, and early overload handling.
Pending assurance
Independent review, real-hardware reliability testing, restore exercises, incident drills, signed node software, key lifecycle tests, and leakage-canary scans remain pending.