TurboPrivate docsCreate API account

turboprivate - API Models

TurboPrivate provides model inference for applications and tools you build or already use. This overview explains how we protect your requests, what you can verify, and the three ways to connect.

1. Who we are and what you can verify

We operate the model service. Your account pays for measured model usage through prepaid credits. Each session uses a temporary Room: a remote service that receives your encrypted requests and runs the selected model over the context you send.

How privacy works

  1. Separate account access from model content. The broker authenticates your API key, checks your balance and allocates a Room. Your client creates the secret Room capability and sends only its hash to the broker.
  2. Verify the Room and establish encryption. Your client challenges the Room, checks its trust statement and establishes session keys. Prompts and answers travel encrypted between your client and the Room; the account service receives usage metadata rather than their plaintext.
  3. Keep processing temporary. The Room decrypts the context for model execution. Closing it clears its ephemeral transport state and live keys; idle expiry is the fallback. Account, billing and usage records remain, and your application controls its own saved history.

What the evidence proves

Signed response receipts let your client check which Room key signed specific response commitments. You can export a session proof and verify its signatures and Room bindings offline. When available, a signed close acknowledgment records the Room's cleanup acknowledgment.

These checks make specific claims verifiable: the integrity of signed records and their binding to a Room key. They do not prove the model's answer is true, independently establish the host's identity, or prove physical erasure of every copy.

Current protection: encrypted transit. Without verified confidential-compute attestation, these proofs do not establish that the host operator cannot inspect plaintext during model execution. A signed cleanup acknowledgment does not rule out copies made while data was live. See Privacy proofs for the evidence and verification steps.

2. Choose how to connect: direct API, SDK or CLI

All three options use an API key and the same Room protocol. The key identifies your account; it does not open or encrypt a Room by itself. The choice is who implements the client-side protocol and how it fits into your application.

Direct API means direct use of the broker and Room protocol. It does not mean sending plaintext prompts to the public API host. The compatible inference endpoint offered by the CLI runs on your own computer; the Room and model remain remote.

Get started

Create an account in the console, add credit and generate an API key. Choose the integration above, then follow the quickstart for your first SDK request, or start with the broker contract for your own client. The capacity updates list is for model availability, separate from account registration.

Models available now

idmodelavailabilityreadscontextspeed
gemma-4-26b-a4bGemma 4 26B A4Bofflinetext, images128knot measured
qwen3.8-27bQwen3.8 27Bofflinetext, images256knot measured

Availability is live. An offline model cannot be selected and is not silently replaced. Full capabilities, context and controls are on Models & controls.