Cevell Technical Architecture
Cevell is an immutable, hardware-attested minimal confidential computing operating system designed specifically for private AI inference workloads on cloud and on-premises infrastructure.
1. Hardware Silicon Attestation & Cryptographic Binding
Cevell eliminates trust in cloud providers by anchoring security in physical hardware attestation across Intel TDX, AMD SEV-SNP, and NVIDIA Hopper/Blackwell confidential GPUs with SPDM 1.2 and DICE certificate chains.
2. Dual-Partition 64-Byte REPORT_DATA Binding
Cevell binds the ephemeral TLS certificate fingerprint and HPKE public key into the 64-byte silicon quote to prevent TLS termination proxy splicing attacks.
3. Application-Layer RFC 9180 HPKE
Client prompts are encrypted end-to-end using RFC 9180 Hybrid Public Key Encryption, decryptable only inside volatile CPU enclave memory.