chopmark — independent TEE scorecard

Six inference providers, graded on what they can actually prove about the machines serving your requests. A grade measures coverage of a proof surface: a vendor-rooted quote answering a live challenge, the endpoint bound into that quote, the boot measured, the release pinned, the GPU attested. Only independently verified checks earn points. Provider claims set expectations and never score.

Evidence is checked against vendor roots of trust — TDX quotes against Intel PCS, SEV-SNP against AMD KDS, GPU evidence against NVIDIA NRAS, supply-chain bundles against Sigstore. Every response is signed, and every grade is reproducible: chopmark verify <provider> runs the same checks this page does.

Questions, corrections, or a provider you want covered: disputes@chopmark.dev

providers

providergradecoveragelevelcheckslast verifiedidentity anchors
chutesA · 87si✓ bd✓ lv✓ mb✓ gpu✓ sc✓ fl✓L564✓ 0✗2026-09-21 09:12 UTCinstance_count=6
nearaiB · 82si⚠ bd✓ lv✓ mb✓ gpu✓ sc⚠ fl✓L5 / clean L028✓ 0✗2026-09-21 09:12 UTCmeasured_os-image-hash=da9a3d5cc196a1a7… compose_hash=7e11ac339aab9d18…
phalaB · 80si✓ bd✓ lv✓ mb✓ gpu· sc⚠ fl·L4 / clean L310✓ 0✗2026-09-21 09:12 UTCkeyset_digest=ef8a03c0c5e34931… measured_os-image-hash=bd369a8c2f9edb2b…
redpillA · 87si✓ bd✓ lv✓ mb✓ gpu✓ sc✓ fl✓L5100✓ 0✗2026-09-21 09:13 UTCinstance_count=6
tinfoilA · 85si✓ bd✓ lv✓ mb✓ gpu· sc✓ fl·L46✓ 0✗2026-09-21 09:13 UTCrelease_tag=v0.0.150
veniceF · 73si✓ bd✓ lv✓ mb✗ gpu✓ sc⚠ fl✓L214✓ 2✗2026-09-21 09:13 UTCmeasured_os-image-hash=a6eafc5f007f642d… compose_hash=945bcfade2aec53a…

coverage: si silicon_root · bd endpoint_binding · lv liveness · mb measured_boot · gpu · sc supply_chain · fl fleet — ✓ proven ⚠ warned ✗ expected but absent · not applicable. Points are earned only by independently verified checks; claims never score.

level: L1 challenge · L2 bound · L3 measured · L4 reproducible · L5 full. The first number is how far the proof reaches; a second number is how far it reaches with no warnings at all. A caveated root of trust leaves no clean rung, so "L5 / clean L0" means full scope and nothing unqualified.

incidents

whenproviderseveritykinddetail
09-21 09:13redpillinfofact_changeinstance_set changed: sha256:31547cb9b0f5d0d1909a342922e35c71 → sha256:da29987b21afed0ca431a885d667ec85
09-21 09:13redpillinfofact_changeinstance_count changed: 7 → 6
09-21 09:12nearaiinfofact_changemr_aggregated changed: af0e09c7eaa445446aa7ee3bf78f8fe0922cd33801d50e220a6b8a0346e64d04 → 9facb0b9261b3f0c4131c8df393559a733ce420b7da9cd5c02507c51fb19ac1c
09-21 09:12nearaiinfofact_changeinstance_id changed: 47cc097b-4a8e-4a5e-a377-cb5a1e987301 → f02d4425-ea4b-4479-be11-92f531a255e5
09-21 09:12chutesinfofact_changeinstance_count changed: 7 → 6
09-21 09:12chutesinfofact_changeinstance_set changed: sha256:acbf9e113b84225776544da66cd2ff93 → sha256:3e775dd4f61a8aec35f72497ecf6d532
09-21 08:12nearaiinfofact_changemeasurement_config changed: 8xh200 [10.2.1] v1.3.1 → 8xh200 [10.2.1, NVSW0] v1.3.1
09-21 08:12nearaiinfofact_changeinstance_id changed: 2ef8eb6c-7855-4522-a2ce-a95d4fd5e937 → 47cc097b-4a8e-4a5e-a377-cb5a1e987301
09-21 07:13veniceinfofact_changemeasured_compose-hash changed: c82b1a2eaf6996154a5f39ae621643f034b082d5e51edd3d2ba6009273881d86 → 945bcfade2aec53a19da7638774a99caea11395ec03e572a13357a0c63b152b4
09-21 07:13veniceinfofact_changecompose_hash changed: c82b1a2eaf6996154a5f39ae621643f034b082d5e51edd3d2ba6009273881d86 → 945bcfade2aec53a19da7638774a99caea11395ec03e572a13357a0c63b152b4
09-21 07:13veniceinfofact_changeinstance_id changed: 7bb9af0ac5b0e22dde3903218f58e56f743164a1 → cc796618bcd5a6b22907d8de7ac414a968d6a1aa
09-21 07:13veniceinfofact_changemr_aggregated changed: 34255d6a2d970cacce85137e41cdc8435e556b7c140420c411b95f7cbb58cfc6 → 2afe299caa25e667948f92fc2d440cd2fcba1fcf0ab7a6f56643972687ced4aa
09-21 07:12nearaiinfofact_changemr_aggregated changed: 9facb0b9261b3f0c4131c8df393559a733ce420b7da9cd5c02507c51fb19ac1c → af0e09c7eaa445446aa7ee3bf78f8fe0922cd33801d50e220a6b8a0346e64d04
09-21 07:12nearaiinfofact_changemeasurement_config changed: 8xh200 [10.2.1, NVSW0] v1.3.1 → 8xh200 [10.2.1] v1.3.1
09-21 07:12nearaiinfofact_changeinstance_id changed: be9af6f7-3cf1-482b-95af-0c57e4d48ac6 → 2ef8eb6c-7855-4522-a2ce-a95d4fd5e937
09-21 06:12nearaiinfofact_changemr_aggregated changed: af0e09c7eaa445446aa7ee3bf78f8fe0922cd33801d50e220a6b8a0346e64d04 → 9facb0b9261b3f0c4131c8df393559a733ce420b7da9cd5c02507c51fb19ac1c
09-21 06:12nearaiinfofact_changeinstance_id changed: f02d4425-ea4b-4479-be11-92f531a255e5 → be9af6f7-3cf1-482b-95af-0c57e4d48ac6
09-21 05:13nearaiinfofact_changeinstance_id changed: be9af6f7-3cf1-482b-95af-0c57e4d48ac6 → f02d4425-ea4b-4479-be11-92f531a255e5
09-21 04:13redpillinfofact_changeinstance_set changed: sha256:da29987b21afed0ca431a885d667ec85 → sha256:31547cb9b0f5d0d1909a342922e35c71
09-21 04:13redpillinfofact_changeinstance_count changed: 6 → 7

default history

providergradeworstdowngradesincidentsunresolvedreported loss
chutesAF16060
nearaiBC1409409
phalaBB01616
redpillAC3183183
tinfoilAB177
veniceFF3146146

A rating is only as good as its record of failures. An unreachable sweep never counts as a downgrade or a worst grade. GET /defaults serves this signed.

quality labels

task setmodelresultjudgeendpoint integrity
judged@1.0.0e2ee-deepseek-v4-flash6 pass · 0 failmodel:deepseek-ai/DeepSeek-V3.2-TEE@1 (A 87 L5/clean L5)B 73 L5/clean L0
instruction@1.0.0e2ee-deepseek-v4-flash7 pass · 0 failexact-match@1B 73 L5/clean L0
formatting@1.0.0e2ee-deepseek-v4-flash6 pass · 0 failjson-has@1B 73 L5/clean L0
classification@1.0.0e2ee-deepseek-v4-flash6 pass · 1 failone-of@1B 73 L5/clean L0
extraction@1.0.0e2ee-deepseek-v4-flash7 pass · 0 failexact-match@1B 73 L5/clean L0
reasoning@1.0.0e2ee-deepseek-v4-flash9 pass · 0 failexact-match@1B 73 L5/clean L0

Each set is signed and carries a verifiable reference to the scorecard's verdict on the endpoint that produced the outputs, so one artifact answers what was served, whether it was any good, and what machine served it. A judge id beginning model: is a model verdict carrying the judge's own attested standing. GET /labels streams the archive.

verify these claims

GET /scores · GET /score?provider=X · GET /provider?provider=X · GET /grade?provider=X&at=T · GET /allow?provider=X&min_grade=B · GET /allows?providers=X,Y · GET /spec · GET /defaults · GET /incidents · GET /evidence · GET /labels · GET /pubkey — all responses signed ed25519/JCS.

signer pubkey: d0488b99f10d265b78ad40cc22fed544dce45c4668a4468b947692dee0f31314

generated 2026-09-21T09:37:20Z