Architecture / Components

Client

On the client side, the user interacts with the Privatemode proxy, which effectively serves as the API endpoint for any inference requests to the LLM. Ideally, the proxy is deployed on the user's machine or within a secure and trusted network. JavaScript and TypeScript applications can use the Privatemode SDK instead, which performs the same tasks inside the application.

Privatemode-proxy

The client-side Privatemode proxy acts as the trust anchor of the Privatemode API. Ensuring its integrity and authenticity during setup is crucial for maintaining the overall security of the system.

The Privatemode proxy performs three main tasks:

  1. Attesting the server side: The Privatemode proxy verifies the Contrast Coordinator using remote attestation. This process indirectly confirms that the Coordinator

    • properly verifies all AI workers.
    • facilitates secure key exchanges.

    In essence, this step ensures the integrity and authenticity of Privatemode API's server side.

  2. Encrypting outgoing prompts and decrypting incoming responses: Upon successful attestation, the Privatemode proxy agrees on a secret key with the secret service, which releases it only to attested AI workers. This key enables end-to-end encryption between the Privatemode proxy and the confidential computing environment of the AI worker, ensuring private communication.

  3. Adding authorization to inference requests: During configuration, the Privatemode proxy is set up with an authorization token. This token is automatically added to all inference requests to authenticate and authorize them.

By performing these tasks, the Privatemode proxy ensures secure and trustworthy interactions between the client and the AI infrastructure.