chopmark — independent TEE scorecard

Six inference providers, graded on what they can actually prove about the machines serving your requests. A grade measures coverage of a proof surface: a vendor-rooted quote answering a live challenge, the endpoint bound into that quote, the boot measured, the release pinned, the GPU attested. Only independently verified checks earn points. Provider claims set expectations and never score.

Evidence is checked against vendor roots of trust — TDX quotes against Intel PCS, SEV-SNP against AMD KDS, GPU evidence against NVIDIA NRAS, supply-chain bundles against Sigstore. Every response is signed, and every grade is reproducible: chopmark verify <provider> runs the same checks this page does.

Questions, corrections, or a provider you want covered: disputes@chopmark.dev

providers

providergradecoveragelevelcheckslast verifiedidentity anchors
chutesA · 87si✓ bd✓ lv✓ mb✓ gpu✓ sc✓ fl✓L573✓ 0✗2026-09-21 06:12 UTCinstance_count=7
nearaiB · 82si⚠ bd✓ lv✓ mb✓ gpu✓ sc⚠ fl✓L5 / clean L028✓ 0✗2026-09-21 06:12 UTCmeasured_os-image-hash=da9a3d5cc196a1a7… compose_hash=7e11ac339aab9d18…
phalaB · 80si✓ bd✓ lv✓ mb✓ gpu· sc⚠ fl·L4 / clean L310✓ 0✗2026-09-21 06:12 UTCkeyset_digest=ef8a03c0c5e34931… measured_os-image-hash=bd369a8c2f9edb2b…
redpillA · 87si✓ bd✓ lv✓ mb✓ gpu✓ sc✓ fl✓L5115✓ 0✗2026-09-21 06:13 UTCinstance_count=7
tinfoilA · 85si✓ bd✓ lv✓ mb✓ gpu· sc✓ fl·L46✓ 0✗2026-09-21 06:13 UTCrelease_tag=v0.0.150
veniceF · 73si✓ bd✓ lv✓ mb✗ gpu✓ sc⚠ fl✓L214✓ 2✗2026-09-21 06:13 UTCmeasured_os-image-hash=a6eafc5f007f642d… compose_hash=c82b1a2eaf699615…

coverage: si silicon_root · bd endpoint_binding · lv liveness · mb measured_boot · gpu · sc supply_chain · fl fleet — ✓ proven ⚠ warned ✗ expected but absent · not applicable. Points are earned only by independently verified checks; claims never score.

level: L1 challenge · L2 bound · L3 measured · L4 reproducible · L5 full. The first number is how far the proof reaches; a second number is how far it reaches with no warnings at all. A caveated root of trust leaves no clean rung, so "L5 / clean L0" means full scope and nothing unqualified.

incidents

whenproviderseveritykinddetail
09-21 06:12nearaiinfofact_changemr_aggregated changed: af0e09c7eaa445446aa7ee3bf78f8fe0922cd33801d50e220a6b8a0346e64d04 → 9facb0b9261b3f0c4131c8df393559a733ce420b7da9cd5c02507c51fb19ac1c
09-21 06:12nearaiinfofact_changeinstance_id changed: f02d4425-ea4b-4479-be11-92f531a255e5 → be9af6f7-3cf1-482b-95af-0c57e4d48ac6
09-21 05:13nearaiinfofact_changeinstance_id changed: be9af6f7-3cf1-482b-95af-0c57e4d48ac6 → f02d4425-ea4b-4479-be11-92f531a255e5
09-21 04:13redpillinfofact_changeinstance_set changed: sha256:da29987b21afed0ca431a885d667ec85 → sha256:31547cb9b0f5d0d1909a342922e35c71
09-21 04:13redpillinfofact_changeinstance_count changed: 6 → 7
09-21 04:12nearaiinfofact_changeinstance_id changed: 95638958-d714-4ea1-b250-11c2643cc2c6 → be9af6f7-3cf1-482b-95af-0c57e4d48ac6
09-21 04:12nearaiinfofact_changemeasurement_config changed: 8xh200 [10.1.0] v1.3.1 → 8xh200 [10.2.1, NVSW0] v1.3.1
09-21 04:12chutesinfofact_changeinstance_count changed: 6 → 7
09-21 04:12chutesinfofact_changeinstance_set changed: sha256:a6ad79200757768bdb441106736f8dce → sha256:acbf9e113b84225776544da66cd2ff93
09-21 03:12nearaiinfofact_changemr_aggregated changed: 4795f34815c118192aa6ce38f0cf360ec9e9954790f782aafd3132406aec2a4c → af0e09c7eaa445446aa7ee3bf78f8fe0922cd33801d50e220a6b8a0346e64d04
09-21 03:12chutesinfofact_changeinstance_set changed: sha256:b6529efd0f692286983dcfbdbf826e8a → sha256:a6ad79200757768bdb441106736f8dce
09-21 02:12nearaiinfofact_changemeasurement_config changed: 8xh200 [10.2.1, NVSW0] v1.3.1 → 8xh200 [10.1.0] v1.3.1
09-21 02:12nearaiinfofact_changeinstance_id changed: f02d4425-ea4b-4479-be11-92f531a255e5 → 95638958-d714-4ea1-b250-11c2643cc2c6
09-21 01:13veniceinfofact_changemeasured_compose-hash changed: 945bcfade2aec53a19da7638774a99caea11395ec03e572a13357a0c63b152b4 → c82b1a2eaf6996154a5f39ae621643f034b082d5e51edd3d2ba6009273881d86
09-21 01:13veniceinfofact_changemr_aggregated changed: 2afe299caa25e667948f92fc2d440cd2fcba1fcf0ab7a6f56643972687ced4aa → 34255d6a2d970cacce85137e41cdc8435e556b7c140420c411b95f7cbb58cfc6
09-21 01:13veniceinfofact_changeinstance_id changed: cc796618bcd5a6b22907d8de7ac414a968d6a1aa → 7bb9af0ac5b0e22dde3903218f58e56f743164a1
09-21 01:13veniceinfofact_changecompose_hash changed: 945bcfade2aec53a19da7638774a99caea11395ec03e572a13357a0c63b152b4 → c82b1a2eaf6996154a5f39ae621643f034b082d5e51edd3d2ba6009273881d86
09-21 01:13redpillinfograde_transitiongrade ERR → A ()
09-21 01:12nearaiinfofact_changeinstance_id changed: ddace810-48c8-4a55-86b2-41a867ccfd97 → f02d4425-ea4b-4479-be11-92f531a255e5
09-21 01:12nearaiinfofact_changemeasurement_config changed: 8xh200 [10.1.0] v1.3.1 → 8xh200 [10.2.1, NVSW0] v1.3.1

default history

providergradeworstdowngradesincidentsunresolvedreported loss
chutesAF15858
nearaiBC1402402
phalaBB01616
redpillAC3181181
tinfoilAB177
veniceFF3142142

A rating is only as good as its record of failures. An unreachable sweep never counts as a downgrade or a worst grade. GET /defaults serves this signed.

quality labels

task setmodelresultjudgeendpoint integrity
judged@1.0.0e2ee-deepseek-v4-flash6 pass · 0 failmodel:deepseek-ai/DeepSeek-V3.2-TEE@1 (A 87 L5/clean L5)B 73 L5/clean L0
instruction@1.0.0e2ee-deepseek-v4-flash7 pass · 0 failexact-match@1B 73 L5/clean L0
formatting@1.0.0e2ee-deepseek-v4-flash6 pass · 0 failjson-has@1B 73 L5/clean L0
classification@1.0.0e2ee-deepseek-v4-flash6 pass · 1 failone-of@1B 73 L5/clean L0
extraction@1.0.0e2ee-deepseek-v4-flash7 pass · 0 failexact-match@1B 73 L5/clean L0
reasoning@1.0.0e2ee-deepseek-v4-flash9 pass · 0 failexact-match@1B 73 L5/clean L0

Each set is signed and carries a verifiable reference to the scorecard's verdict on the endpoint that produced the outputs, so one artifact answers what was served, whether it was any good, and what machine served it. A judge id beginning model: is a model verdict carrying the judge's own attested standing. GET /labels streams the archive.

verify these claims

GET /scores · GET /score?provider=X · GET /provider?provider=X · GET /grade?provider=X&at=T · GET /allow?provider=X&min_grade=B · GET /allows?providers=X,Y · GET /spec · GET /defaults · GET /incidents · GET /evidence · GET /labels · GET /pubkey — all responses signed ed25519/JCS.

signer pubkey: d0488b99f10d265b78ad40cc22fed544dce45c4668a4468b947692dee0f31314

generated 2026-09-21T06:25:42Z