If this is “self hosted ML” then that’s great, and it is secure!
…
That obviously isn’t their business model.
(Or is it? Did I totally misunderstand the offering?)
import blindai
blindai.api.Completion.complete("I love AI…
...I dunno, I feel like they'll say something like:- You have a client side encryption key
- You encrypt the data before you submit it
- The encrypted data is put on the image along with our Magic Sauce
- In the secure enclave, the data in encrypted and processed
- The result is encrypted
- The encrypted result is returned to you
- You decrypt it locally!
The problem with that is there's a whole lot of magic hand waving about how the secure key that theoretically never leaves your local side, ends up inside the container image without them having access to it.
How does it actually work?