Verify, don’t trust.
Saxeo sells compute you can prove. So every claim on this page is checkable live, by you, right now. The numbers below are read straight from the running gateway, not a status graphic.
Recorded gateway health, sampled continuously and served at GET /v1/status. Uptime is computed from persisted probes; it is null until enough samples exist, never fabricated. Refreshes every 30 seconds.
The confidential tier is TEE-attested for the saxeo-confidential-* models. Other tiers are not confidential. Below is the live, DCAP-verified quote the gateway checks before serving any confidential request.
Every billable response is signed by the key below (secp256k1 / EIP-191). Pin this address and verify any receipt offline against it, or paste one here to check it now. See the receipts docs.
Paste the x-sable-receipt header (or the sable.receipt stream event) and its signature. The check runs against the public POST /v1/receipts/verify endpoint and recovers the signer.
What we do not claim.
Trust is what’s left after the overclaims are removed. These are the limits of what Saxeo proves, stated plainly, because the honesty is the point.
The confidential tier pins MRTD — the enclave’s base image (firmware, kernel, initrd) — and not RTMR3, the workload build. So a verified attestation proves a genuine Intel TDX enclave running the expected base image; it does not prove which build of the serving software is inside it. The pin is on MRTD deliberately: the backend serves from a pool of enclaves whose RTMR3 differs between instances, so pinning the workload verified only a fraction of requests and failed closed at random on the rest. One consequence follows, and we state it rather than let it be inferred: gpu_verified is recorded, not proven, because the GPU-CC configuration was only ever covered by the workload measurement.
On these tiers the model host’s servers see the prompt in plaintext. Anonymized routing hides who is asking from the vendor; it does not hide what is asked. Only the confidential tier is TEE-attested.
A counter-signed receipt proves which machine served a request (who to hold responsible), not that the work it returned was correct. We label attribution as attribution.
The double-blind lanes are live wherever /v1/models lists them. They separate identity from request — the vendor never learns who is asking — but the vendor’s servers still process the plaintext. It is a privacy property, not a confidentiality guarantee over the payload.
Zero third-party machines serve Saxeo traffic today. What runs is this gateway and its configured backends. We do not use present-tense network or marketplace language for supply that doesn’t exist yet.
Saxeo Vault records and proves issuer-declared entries with hash-chained events and public anchoring. Saxeo does not custody assets, appraise them, or enforce ownership.
Prompts, completions, and submitted code are never persisted or logged. A receipt carries metadata and a content fingerprint: enough to verify what ran, never enough to reconstruct it.