Everything on this page ships inside the product too, on every report. It is here in full so a reader can weigh it before downloading anything.
Which exact model weights ran — that is still the provider's word, not a measurement. And it is not a claim that nothing about this turn is visible: tool calls, the file paths and URLs your agent touched, sizes and timing all stay outside the encrypted content.
Seven more things the architecture does not cover, starting with the fact that the verification itself runs on our gateway rather than on your computer. Every one of them is disclosed inside the product too.
The DCAP, NRAS and TLS checks run on Amnesia AI®'s gateway before the reply reaches you, not on your own machine. For that step you are trusting us as well as the hardware, which is exactly why the report is exportable: you, or a third party, can re-run the same checks on a machine that has never run our software.
The attestation proves an enclave, not a specific set of model weights. Which model actually answered is still the provider's word rather than a measurement.
The measured launcher stack covers the proxy, telemetry agent and compose manager. The model-serving container itself is pulled at runtime and is not part of the measurement.
A Datadog agent inside the measured compose is configured to collect all container logs and ship them out of the enclave. Nothing indicates prompts are logged; the point is that this configuration is visible at all only because the compose is measured rather than asserted.
Search queries go to Brave in the clear, under one account-wide subscription token. Nothing about a search query is confidential to Brave.
The transcription model runs in a TEE, but the audio reaches it through our gateway as plaintext, because the endpoint accepts multipart uploads only. Dictation is not end-to-end encrypted.
Not every reply carries an attestation. When evidence is missing the app shows the reply as unverified rather than presenting it as attested.
Attestation covers the machine; it does not make everything invisible. These four rows are the app's own list, word for word.
your messages are encrypted to the enclave, so our gateway relays them without being able to read them — the actions your agent takes (tool calls, file paths, screenshots) it can still see.
Below is exactly what that second clause covers, on every turn.
The architecture these limits apply to is documented at Security & proof.