Confidential inference on a TEE for banking PII
TEE and Secure Inference- proposed
- voting
- running · 59d
- measuring
- concluded
Preregistration · v1 · 22 Jun 2026 · immutable after start
Hypothesis
A mid-size open-weight model served inside a GPU TEE in an AU region delivers under 1.4× the latency and under 1.6× the cost of the same model outside the enclave, with attestation a bank's security team accepts as evidence that plaintext PII never left the enclave.
Kill condition
Kill if latency exceeds 2× outside-enclave by day 20, if attestation cannot be verified end-to-end from the client side, or if the bank's security team declines the attestation model in the design review.
Running notes · fed from harness sessions and by the pair
- manual20 Aug 2026LF Lena Fischer
Walked the bank's security team through attestation. Accepted in principle; they want the verifier to be independent of the cloud provider. That is a tooling gap, not a kill.
- harness24 Jul 2026PR Priya Raman
enclave serving; attestation chain verified client-side; latency 1.28x; cost 1.7x on current pricing
- manual22 Jun 2026PR Priya Raman
Type 4: client-like data under agreement; governance signed 30 June. Commercial rationale: two banking RFPs name confidential inference. Predicted 1.3× latency, 1.5× cost, attestation accepted with conditions, confidence 0.45.
Harness notes are auto-captured from Claude Code sessions: model, date, commit, session reference. Never the transcript, code or paths.