Skip to content

VEIL specification / 0005 · v0.1.0

Measured policy

How any content filtering in an enclave is made inspectable: part of the measured image, versioned, and recorded in the receipt.
The VEIL specification is an open draft published so anyone can review or implement it. Nothing described here is deployed by the router yet unless a section says otherwise.
Status
Draft
Version
0.1.0
Updated
2026-09-30
License
Apache-2.0 (specification text)
Related
0001,0004

Status of this document

This is a working draft of VEIL and not a standards-track document. It describes how content policy is measured, applied and recorded as designed for Verify Route. None of it is deployed yet; when a part ships, this section will say which, and the changelog will record it.

Abstract

An enclave MAY apply a content policy. If it does, the policy is part of the measured image, its rules are published, and each refusal is recorded in the receipt with the policy version. A private lane never hides a filter from the user.

1. Conventions and terms

The words MUST, MUST NOT, SHOULD, SHOULD NOT and MAY are used as in RFC 2119 and RFC 8174 when written in capitals. Terms used across the documents:

  • Router: the Verify Route service that routes, prices and signs calls.
  • Enclave: a confidential VM, optionally with a confidential GPU, running the sidecar and a model server.
  • Sidecar: the process in the enclave that measures weights, holds keys and signs node receipts.
  • Quote: hardware-signed evidence of what was measured into the enclave.
  • Lane: the privacy floor of a request, one of standard, attested or blind.

2. Policy definition

A policy is a policy.json file naming the categories it acts on, the action for each (refuse or annotate) and the classifier model and digest. Its SHA-256 is included in the enclave bindings (see 0001).

3. Outcomes

A refused request returns policy_refused with the category and the policy digest, and is not charged beyond the classification cost. The receipt records the outcome, so a refusal is as checkable as an answer.

4. Aggregate statistics

The enclave MAY publish counts of outcomes per category with added noise and a per-request contribution bound, so that operators can report on policy use without exposing any single request.