Confidential Compute AI Models

collections/confidential-compute · 17 models

Each of these has a route served from a trusted execution environment. The enclave publishes an attestation covering the code that touches your prompt, which makes the guarantee checkable instead of promised.

Models

17

Labs

8

model creators

From (input)

$0.05

per 1M tokens

Max context

1M

Private routes

17 / 17

up to E2EE

In this collection17

Ordered by strongest privacy.

Zhipu
GLM 5.2
z-ai/glm-5.2
E2EE

GLM 5.2 running in a Trusted Execution Environment (TEE). Z.AI's flagship model for long-horizon tasks with enhanced reasoning and project-level engineering context, with hardware attestation evidence available for independent verification.

E2EE|524K context|$1.75/M input|$5.75/M output
Gemma
Gemma 4 26B A4B Uncensored
google/gemma-4-26b-a4b-uncensored
E2EE

Gemma 4 26B A4B Uncensored running in a Trusted Execution Environment (TEE). An uncensored variant of Google's Gemma 4 MoE model with 25.2B total / 3.8B active parameters, supporting multimodal input across text and images, with hardware attestation evidence available for independent verification.

E2EE|64K context|$0.19/M input|$0.88/M output
Qwen
Qwen 2.5 7B
qwen/qwen-2.5-7b
E2EE

Qwen 2.5 7B Instruct running in a Trusted Execution Environment (TEE). A compact model with strong coding, math, and multilingual capabilities supporting 29+ languages, with hardware attestation evidence available for independent verification.

E2EE|32K context|$0.05/M input|$0.13/M output
Qwen
Qwen 3.6 35B A3B FP8
qwen/qwen-3.6-35b-a3b-fp8
E2EE

Qwen 3.6 35B A3B FP8 running in a Trusted Execution Environment (TEE). A fast mixture-of-experts model with ~3B active parameters per token. Hardware attestation evidence is available for independent verification of enclave identity and configuration.

E2EE|32K context|$0.182/M input|$1.18/M output
Gemma
Gemma 4 31B
google/gemma-4-31b-instruct
TEE

Gemma 4 31B served in a Tinfoil verified confidential enclave.

TEE|262K context|$0.40/M input|$1.00/M output
Kimi
Kimi K3
moonshotai/kimi-k3
TEE

Kimi K3 served in a Tinfoil verified confidential enclave.

TEE|262K context|$4.00/M input|$20.00/M output
Meta
Llama 3.3 70B
meta-llama/llama-3.3-70b
TEE

Llama 3.3 70B served in a Tinfoil verified confidential enclave.

TEE|131K context|$1.75/M input|$2.75/M output
OpenAI
OpenAI GPT OSS 120B
openai/gpt-oss-120b
TEE

OpenAI GPT OSS 120B served in a Tinfoil verified confidential enclave.

TEE|131K context|$0.15/M input|$0.60/M output
Nomic Embed Text
nomic-ai/nomic-embed-text
TEE

Nomic Embed Text served in a Tinfoil verified confidential enclave.

TEE|8K context|$0.05/M input|Verify/M output
DeepSeek
DeepSeek V4 Flash
deepseek/deepseek-v4-flash
Private

DeepSeek V4 Flash is an efficiency-focused MoE model with 284B total parameters (13B active) and a 1M-token context window. It's tuned for fast inference and high-throughput use cases while still holding up on reasoning and coding tasks.

Private|1M context|$0.09/M input|$0.18/M output
Zhipu
GLM 5.3 Flash
z-ai/glm-5.3-flash
Private

GLM-5.3 Flash is a reasoning model designed for coding, sustained agentic work, and production workloads. It is suited for long-horizon software engineering, complex reasoning, and workflows that combine text with visual context.

Private|1M context|$0.15/M input|$0.50/M output
Zhipu
GLM 5.3
z-ai/glm-5.3
Private

GLM-5.3 is a large-scale reasoning model from Z.ai, built for complex software engineering and long-horizon agent tasks. It supports text input and output with a 1M-token context window, and improves on GLM-5.2 in coding and in the balance between performance and token efficiency.

Private|1M context|$1.75/M input|$5.50/M output
Qwen
Qwen 3.8 27B
qwen/qwen-3.8-27b
Private

Qwen 3.8 27B is a native vision-language dense model with 27B parameters. It improves coding, professional work, research, and long-horizon agentic tasks, with flexible thinking control and image and video understanding. It supports a native 262K-token context window.

Private|262K context|$0.45/M input|$3.20/M output
Qwen
Qwen3 VL 30B A3B Instruct
qwen/qwen3-vl-30b-a3b
Private

Meet Qwen3-VL — the most powerful vision-language model in the Qwen series to date. This generation delivers comprehensive upgrades across the board: superior text understanding & generation, deeper visual perception & reasoning, extended context length, enhanced spatial and video dynamics comprehension, and stronger agent interaction capabilities.

Private|262K context|$0.15/M input|$0.60/M output
Kimi
Kimi K2.6
moonshotai/kimi-k2.6
Private

Kimi K2.6 is an open-source, native multimodal agentic model from Moonshot AI with 1T total parameters and 32B active parameters. It excels at long-horizon coding, coding-driven design, agent swarm orchestration, and proactive autonomous execution with 256K context windows.

Private|256K context|$0.75/M input|$3.50/M output
DeepSeek
DeepSeek V3.2
deepseek/deepseek-v3.2
Private

DeepSeek-V3.2 is an efficient large language model with DeepSeek Sparse Attention (DSA) for long contexts. It features strong reasoning and tool-use skills, achieving top results on the 2025 IMO and IOI.

Private|160K context|$0.33/M input|$0.48/M output
Qwen
Qwen3 32B
qwen/qwen3-32b
Private

Qwen3 is the latest generation of large language models in Qwen series, offering a comprehensive suite of dense and mixture-of-experts (MoE) models. Built upon extensive training, Qwen3 delivers groundbreaking advancements in reasoning, instruction-following, agent capabilities, and multilingual support

Private|41K context|$0.08/M input|$0.28/M output

This list is rebuilt from the live catalog rather than stored as a snapshot, so it tracks pricing, context windows, and privacy tiers as providers change them. Ordering is yours to pick, and there is no popularity option: prompts are never retained, and the usage metadata kept for billing is not turned into a public ranking.

Explore more collections

Strongest guarantee in this collection:E2EE

Confidential Compute AI Models - AnonRouter