Who serves
your model.
Each provider with the hardware and verifiers the router recorded, when it last verified them, and a link to check it yourself. Providers the router has not verified are marked Unverified.
Providers
Every provider the router lists, with what the router itself has verified about it. “Attested” means the router checked a hardware quote from that provider recently. It does not show what a provider does with prompts. Anything not checked is marked Unverified, and each row links to the full record.
Reading the router’s provider list…
Run a provider
Serve an open-weights model from confidential hardware you control. One command measures your weights, writes a pinned deployment for Phala Cloud (CPU or GPU) or your own Intel TDX host, and makes the key your router account will use. Nothing is published or paid for until you deploy and apply.
git clone https://github.com/AnyRouteRH/AnyRoute.git && cd AnyRoute
bun sidecar/src/cli.ts init- Measure and write
inithashes the weights (a SHA-256 over every file), writessidecar.yamland a compose file with every image, the weights and the sidecar source pinned by hash, and stores a router key in a private file. Only the key’s SHA-256 goes in the configuration. - DeployOn Phala Cloud,
phala deploywith the compose file. On your own TDX host,docker compose up -d. The model server has no route out. - Check it
doctorreads your endpoint the way a user’s client would:/healthz, the shape of/attest, that the served digest is your weights, that the certificate carries the attestation name and key, and that a response carries a receipt signed by the attested key. - Apply
apply --submitfiles your provider application. An operator reviews it before anything is routed. Once the router has verified your endpoint, it appears in the list above and the verify page shows the digests it recorded.
bun sidecar/src/cli.ts init --yes --target phala-gpu \
--weights ./my-model --hf-repo <owner/name> --hf-revision <40-hex commit> \
--model-image <vllm image>@sha256:<digest> --id my-model
bun sidecar/src/cli.ts doctor --dir anyroute-provider --url https://<your endpoint>
bun sidecar/src/cli.ts apply --dir anyroute-provider --url https://<your endpoint> --router https://<router> --submit- The sidecar attests the Intel TDX virtual machine. It does not collect NVIDIA confidential-computing evidence, so a GPU’s state is not covered.
doctordoes not repeat Intel’s signature check on the quote. The router does that, and says so on the verify page.- Data-policy fields in your application are your own declaration. The router shows them as declared, not verified.