Skip to content

Providers / bond and attestation

Who answers
your call.

Every provider with its bond, its canary record, the hardware the router verified and when it last checked. A provider the router has not verified is marked Unverified.

Providers

“Attested” will mean the router checked a hardware quote from that provider recently. It says what software is running, not what a provider does with prompts. Anything not checked is labelled Unverified, and each row will link to its full record.

No providers on record yet

Providers are listed once they post their 10,000 USDG bond and pass their first canary set. Nothing here is hidden: the list is empty because bonding has not opened.

Run a provider

Planned CLI

Serve an open-weights model from confidential hardware you control. One command measures your weights, writes a pinned deployment and makes the key your account will use. Nothing is published or paid until you deploy, bond and apply. The tool is in development and not yet published.

Terminal · one command, it asks the rest
npx verifyroute-provider init
  1. 01

    Measure and write

    init hashes your weights (SHA-256 over every file), writes a pinned deployment where every image, the weights and the sidecar are fixed by digest, and creates the key your router account will use. Only the key's hash goes in the configuration.

  2. 02

    Deploy

    Run the pinned deployment on your own confidential virtual machine. The model server gets no route out to the internet.

  3. 03

    Check it

    doctor reads your endpoint the way a client would: health, the shape of /attest, that the served digest matches your weights, and that a reply carries a receipt signed by the attested key.

  4. 04

    Bond and apply

    apply files your application; you post the 10,000 USDG bond on Robinhood Chain. After review and a first canary pass, the provider appears in the list above.

Terminal · without questions
npx verifyroute-provider init --yes --target tdx-gpu \
  --weights ./my-model --hf-repo <owner/name> --hf-revision <40-hex commit> \
  --model-image <inference image>@sha256:<digest> --id my-model
npx verifyroute-provider doctor --dir vr-provider --url https://<your endpoint>
npx verifyroute-provider apply  --dir vr-provider --url https://<your endpoint> --submit
  • The sidecar attests the confidential virtual machine. GPU confidential-computing evidence is a separate check and is reported separately.
  • doctor does not repeat the hardware vendor's signature check on the quote. The router does, and the verify page says so.
  • Data-policy fields in an application are the provider's own declaration. They are shown as declared, never as verified.