TurboPrivate docsCreate API account

Privacy proofs

Inspect the evidence from a session instead of relying only on a privacy statement. Each check has a specific scope: a valid signature is not proof of every privacy claim.

What you can check

EvidenceWhat it establishesWhat it does not establish
Live Room challengeA response bound to your fresh nonce and capability hash, checked against the declared trust policy.Independent hardware identity when the trust level is transit-only.
Signed response receiptA Room key signed the commitments; the live client checks their binding to its request and response.The answer's factual accuracy or secrecy from the host operator.
Signed close acknowledgmentThe Room key signed a terminal lifecycle record when one is returned.Physical erasure or absence of copies made while data was live.

Current protection is transit-only unless genuine hardware attestation is verified. Encrypted transport and software signatures do not prove host confidentiality. Read Security & privacy for processing and retention boundaries.

Signatures and receipts

Responses carry an Ed25519 signature over their exact commitments. Clients verify it during the session. JavaScript exposes room.exportSessionProof() and verifySessionProof(bundle); Python exposes room.export_session_proof() and verify_session_proof(bundle). A receipt proves which Room key signed specific bytes. It does not prove that the model's statement is true, and its operator-identity strength depends on the attestation that bound the Room key.

Export and verify offline

turboprivate check --proof session-proof.json
turboprivate verify session-proof.json

The check closes its Room before exporting. The JSON contains the descriptor, attestation report, signed lifecycle and receipts, without prompts, answers or secret credentials. It still contains account references and usage metadata; share it deliberately. Existing files are never overwritten.

An SDK snapshot covers its current Room and the last 256 receipts, with an explicit omitted-receipt count. Export before a Room replacement if you need that older Room's evidence. Call export after close to include a signed terminal acknowledgment when available.

The offline verifier checks signatures and Room bindings against the key inside the bundle. It does not prove an independent hardware identity, live freshness, a complete transcript, plaintext contents or physical erasure. An unsigned “absent” response is not a signed destruction acknowledgment.

Use proofs in your application

JavaScript: call room.exportSessionProof(), then pass the bundle to verifySessionProof(bundle) imported from @turboprivate/sdk. Python: use room.export_session_proof() and verify_session_proof(bundle). Preserve the returned verification details, including trust level and missing or omitted evidence; do not reduce them to a claim of complete privacy.

The CLI check makes a real, billable model request and requires a live model and credits. Offline verification reads an existing file and requires neither a model session nor an API key. A failed check should be investigated, not bypassed.