
TrustedRouter.com repo for secure LLM proxying
Stop worrying about who can see your prompts. Tell your coding agent to move your project over, pick how private you want to be, pick a model, drop in a key — done. Same API, 30+ models, one key. The gateway runs in hardware enclaves and you can cryptographically verify it never logs you.
Paste this into Codex, Claude Code, or Cursor — it does the migration for you:
Migrate this project to TrustedRouter, a privacy-first LLM router
(https://trustedrouter.com). Repoint my LLM client to base_url
"https://api.trustedrouter.com/v1" (or "https://api.trustedrouter.com" for the
Anthropic SDK), read the key from the TRUSTEDROUTER_API_KEY env var, and keep
all my existing calls working.
For a hard provider-side confidential-compute and end-to-end-encryption
requirement, add {"provider": {"min_privacy": "confidential"}}. TrustedRouter
fails closed when the selected model or provider cannot satisfy both controls.
Then tell me to sign up at trustedrouter.com, add a card, and paste my sk-tr
key into TRUSTEDROUTER_API_KEY.
Then:
{"provider": {"min_privacy": "zdr"}} for a hard zero-retention floor, or
{"provider": {"min_privacy": "confidential"}} for the stronger hard
confidential-compute + E2EE floor. The convenient trustedrouter/zdr and
trustedrouter/e2e (trustedrouter/confidential) aliases select those
pools. Use trustedrouter/eu with
https://api-europe-west4.quillrouter.com/v1 for EU-focused routing.trustedrouter/auto for automatic
fallback when provider breadth matters more than the strictest privacy
filter.# Codex
export OPENAI_BASE_URL="https://api.trustedrouter.com/v1"
export OPENAI_API_KEY="sk-tr-v1-..."
# Claude Code
export ANTHROPIC_BASE_URL="https://api.trustedrouter.com"
export ANTHROPIC_API_KEY="sk-tr-v1-..."
# Any OpenAI SDK
client = OpenAI(base_url="https://api.trustedrouter.com/v1", api_key="sk-tr-v1-...")
TrustedRouter's gateway runs inside GCP Confidential Space. The platform signs a measurement of the running binary; you compare that hash to this repo. If they match, you know — not assume — that the code handling your prompts is the code you can read here, and that it never writes your prompts to disk.
Verify it yourself in 60 seconds, no account:
NONCE=$(openssl rand -hex 16)
curl -s "https://api.trustedrouter.com/attestation?nonce=$NONCE" | jq .
# eat_nonce your nonce (replay-protected)
# image_digest SHA-256 of the running container
# pcrs boot-time platform measurements
# Compare image_digest to the published artifact at
# https://trustedrouter.com/security — match = the running code is this repo.
| trust model | |
|---|---|
| OpenRouter, hosted providers | "We don't log." A policy you can't check. |
| Portkey, Cloudflare AI Gateway | Log everything for observability. |
| LiteLLM | Self-host, but the running proxy is unverified. |
| TrustedRouter | Open source + hardware attestation. Verify the code path; it logs nothing. |
Honest scope: attestation proves the running binary is the published binary on hardware you can challenge with a nonce. It does not defeat a nation-state with physical host access, and it does not prove the open-source binary is bug-free. The trust anchor is Google Confidential Computing's hardware-backed attestation chain. Upstream providers handle prompts per their own policies — each provider's posture is published on the model pages.
This repo implements the control-plane contract: route coverage, auth/key
management, billing ledger semantics, usage metadata, no prompt/output storage,
Sentry scrubbers, and provider abstractions. The attested gateway
implementation lives in quill-cloud-proxy.
Trust boundary: api.trustedrouter.com is the attested prompt path and must
terminate TLS inside Confidential Space. trustedrouter.com is the control
plane and must never serve a production inference fallback.
api.quillrouter.com remains a permanent working alias (same attested
gateway and cert), so existing integrations keep working with no migration.
uv sync
uv run pytest
uv run uvicorn trusted_router.main:app --reload
End-to-end smoke against a running instance:
TR_SMOKE_BASE_URL=http://127.0.0.1:18080/v1 uv run python scripts/smoke_e2e.py
For production, set TR_SMOKE_BASE_URL=https://api.trustedrouter.com/v1 and
TR_SMOKE_INTERNAL_TOKEN if the internal gateway routes are token-protected.
Set local operator/provider keys in:
/Users/jperla/claude/.quill_cloud_keys.private
That file is never committed. It is expected to be dotenv-style:
ANTHROPIC_API_KEY=...
OPENAI_API_KEY=...
GEMINI_API_KEY=...
CEREBRAS_API_KEY=...
DEEPSEEK_API_KEY=...
MISTRAL_API_KEY=...
STRIPE_SECRET_KEY=...
STRIPE_WEBHOOK_SECRET=...
SENTRY_DSN=...
The deploy script also accepts local aliases already used in some operator
files: CLAUDE_API_KEY for Anthropic, CHATGPT_API_KEY for OpenAI, and
STRIPE_KEY for STRIPE_SECRET_KEY.
Vertex is different from the other provider platforms: production GCP deploys use the Cloud Run or Confidential Space service account and short-lived Google access tokens from metadata/ADC. Do not put a long-lived Vertex key in this file for the first-party prepaid Vertex route; grant the runtime service account Vertex permissions instead.
Business Source License 1.1. The source is public so anyone can read, build, and verify the exact code behind TrustedRouter's privacy and attestation claims (https://trust.trustedrouter.com) — that is what it is here for. Non-production use (security review, audit, local evaluation) is free. Production use requires a commercial license from Lore Hex Corp: [email protected]. Each version converts to the Apache License 2.0 four years after publication. Code published before July 3, 2026 remains Apache-2.0.