> Markdown version of [/videos/100013-building-trust-through-private-and-verifiable-ai](https://www.wearedevelopers.com/videos/100013-building-trust-through-private-and-verifiable-ai). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Building Trust Through Private and Verifiable AI Can you run cloud LLMs on sensitive data without exposing user prompts? Project PVC achieves this using Trusted Execution Environments. Learn to deploy verifiable, zero-trust AI infrastructure. - **Speakers:** [Mingshen Sun](https://www.wearedevelopers.com/@mingshen-sun) - **Event:** World Congress 2026 Europe - **Published:** July 9, 2026 - **Duration:** 22:30 - **URL:** https://www.wearedevelopers.com/videos/100013-building-trust-through-private-and-verifiable-ai ## Summary The rapid adoption of large language models for processing sensitive information, such as personal health data, presents significant privacy challenges. Because the most powerful AI infrastructure runs on centralized cloud hardware, user prompts and context are typically exposed to service providers, administrators, and model owners. To address the need for "similar protections as end-to-end encryption" for AI, Project Private Verifiable Compute (PVC) provides an open-source architecture for context-aware processing that guarantees user privacy and verifiable transparency. By leveraging privacy-enhancing technologies (PET) like confidential computing and Trusted Execution Environments (TEEs), PVC ensures that data is encrypted entirely in use, rendering it inaccessible to anyone outside the cryptographic boundary. Project PVC achieves minimal trust requirements through three technical pillars: private processing, private storage, and verifiable transparency. At its core, customized hardware execution environments powered by components like CPU and GPU memory encryption agents guarantee isolation, while oblivious HTTP mechanisms mask traffic routing and user-controlled keys secure stored context. Crucially, the platform utilizes hardware-signed remote attestation, enabling independent third-party verification of software instances, Trust Computing Base (TCB) versioning, and policy enforcement. This verifiable transparency extends through reproducible build pipelines, allowing organizations to securely serve modern AI frameworks like vLLM over sensitive datasets. Ultimately, Project PVC enables organizations to leverage cloud-scale AI environments for highly sensitive workloads without compromising security or regulatory expectations. By utilizing a hardened OS within a confidential VM and enforcing zero-privilege access for cluster administrators, developers can confidently deploy verifiable LLM agents across hybrid or public clouds. This robust security architecture removes historical compliance barriers, unlocking new business innovations and fostering deep clinical or commercial trust between end users and cloud-hosted AI. **Keywords:** private verifiable compute, trusted execution environments, confidential computing, hardware-based isolation, memory encryption agent, remote attestation, oblivious HTTP, user-controlled encryption keys, reproducible builds, privacy-enhancing technologies, trust computing base, confidential VM, zero-privilege access, LLM security architecture, encrypted data processing, open-source AI privacy ## Chapters 1. **Challenges of protecting sensitive data in cloud AI** (01:10) — Processing sensitive health and personal data in cloud environments introduces major user privacy concerns. 1. **Identifying security vulnerabilities in cloud AI workflows** (03:30) — Traditional remote server processing exposes sensitive user prompts and context to unauthorized administrators or model owners. 1. **Utilizing trusted execution environments for data protection** (05:50) — Hardware-based isolation and memory encryption shield data in use from infrastructure providers during processor execution. 1. **Establishing robust security guarantees in AI processing** (08:39) — Implementing cryptographic measurement and hardened operating systems prevents privileged access while ensuring complete traffic anonymity. 1. **Securing contextual storage and proving verifiable transparency** (11:37) — User-controlled encryption keys secure stored documents while hardware vendor attestation enables independent software assurance verification. 1. **Architectural deployment and open source project benefits** (13:44) — Architecting oblivious routing and reproducible builds unlocks new business innovations by mitigating default cloud AI risks. 1. **Deploying private verifiable compute environments locally and remotely** (16:41) — Comprehensive documentation and local clustering tools allow immediate testing of confidential computing setups without specialized infrastructure. 1. **Demonstrating remote attestation in confidential AI chatbots** (17:49) — Inspecting network traffic reveals specific CPU and GPU measurements verifying the integrity of the remote execution environment. ## Related Moments - [Securing data in use with confidential cloud computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) (from "Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing") - [Advancing confidential computing with open source multi-way collaboration](https://www.wearedevelopers.com/videos/1036-tiktok-s-privacy-innovation) (from "TikTok's Privacy Innovation") - [Hardware security features necessary for compliance and responsible AI](https://www.wearedevelopers.com/videos/1132-bringing-ai-everywhere) (from "Bringing AI Everywhere") - [Navigating data privacy boundaries and adversarial model reliability](https://www.wearedevelopers.com/videos/260-getting-started-with-machine-learning) (from "Getting Started with Machine Learning") - [Hardware-based trusted execution environments for confidential computing](https://www.wearedevelopers.com/videos/100129-building-securing-and-governing-ai-infrastructure-in-the-era-of-agentic-ai) (from "Building, securing and governing AI infrastructure in the Era of Agentic AI") - [Cloud infrastructure deployment and industry use cases](https://www.wearedevelopers.com/videos/1036-tiktok-s-privacy-innovation) (from "TikTok's Privacy Innovation") ## Related Articles - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges](https://www.wearedevelopers.com/magazine/488-panel-discussion-responsible-ai-in-practice-real-world-examples-and-challenges) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [WWC24 Talk - Scott Hanselman - AI: Superhero or Supervillain?](https://www.wearedevelopers.com/magazine/469-wwc24-talk-scott-hanselman-ai-superhero-or-supervillain) ## Related Jobs - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [Principal Engineer - AI Search & Vector Infrastructure](https://www.wearedevelopers.com/jobs/ext/353953-principal-engineer-ai-search-vector-infrastructure) at **Redis**