VEIL specification / 0005 · v0.1.0
Measured policy
Status of this document
This is a working draft of VEIL and not a standards-track document. It describes how content policy is measured, applied and recorded as designed for Verify Route. None of it is deployed yet; when a part ships, this section will say which, and the changelog will record it.
Abstract
An enclave MAY apply a content policy. If it does, the policy is part of the measured image, its rules are published, and each refusal is recorded in the receipt with the policy version. A private lane never hides a filter from the user.
1. Conventions and terms
The words MUST, MUST NOT, SHOULD, SHOULD NOT and MAY are used as in RFC 2119 and RFC 8174 when written in capitals. Terms used across the documents:
- Router: the Verify Route service that routes, prices and signs calls.
- Enclave: a confidential VM, optionally with a confidential GPU, running the sidecar and a model server.
- Sidecar: the process in the enclave that measures weights, holds keys and signs node receipts.
- Quote: hardware-signed evidence of what was measured into the enclave.
- Lane: the privacy floor of a request, one of
standard,attestedorblind.
2. Policy definition
A policy is a policy.json file naming the categories it acts on, the action for each (refuse or annotate) and the classifier model and digest. Its SHA-256 is included in the enclave bindings (see 0001).
3. Outcomes
A refused request returns policy_refused with the category and the policy digest, and is not charged beyond the classification cost. The receipt records the outcome, so a refusal is as checkable as an answer.
4. Aggregate statistics
The enclave MAY publish counts of outcomes per category with added noise and a per-request contribution bound, so that operators can report on policy use without exposing any single request.