
Introducing the Enclave Router - Provable Privacy and Model Integrity for all PPQ users
Every chat request to PayPerQ now runs inside an AWS Nitro enclave that PPQ cannot see into. Your prompts are encrypted before they leave your device, PPQ only ever handles billing metadata, and you can verify all of it yourself.
PayPerQ is now, by default, blind to the content of your chat queries. Since mid-September, 2026, every chat request made through the PPQ.AI web app or API is served inside an AWS Nitro enclave: an isolated hardware environment that PPQ's servers, staff and logs cannot read into, and neither can AWS. Your prompt is encrypted before it leaves your device and is not decrypted until it reaches the enclave. PPQ's own backend sees a credit check and billing and request metadata, never your content.
We are calling this the Enclave Router. This post explains what the Enclave Router does, what it stops us from doing, and, since a privacy promise is only worth what you can check, how to verify it for yourself.
Why we built it
Every AI router on the market currently sits between you and a model can read the content of your queries. That is how the architecture works: your prompt has to be decrypted somewhere to be sent to the provider, and that somewhere is usually the service's own servers. PPQ has always promised not to store or log your prompts. But a promise is a policy, and a policy can change, be breached, or be compelled.
It also turns out that "the router in the middle" is exactly where things go wrong. In April 2026 security researchers reported finding 26 LLM routers in the wild secretly injecting malicious tool calls and stealing credentials from the requests passing through them, one of which drained a client's $500k wallet. In September, an independent investigation found that CrofAI, which sold access to models like Kimi K3 at prices nobody else could match, was quietly answering those requests with smaller, cheaper models bought from OpenRouter and returned under the Kimi K3 label.
The Enclave Router replaces our promise with hardware and published code. It is the difference between "we won't look" and "we can't", and between "trust us, that was Claude" and a signed receipt that proves it.
How the Enclave Router works

- Your request is encrypted on your device to a key that only the enclave holds, and travels to the enclave over a connection that terminates inside it. Nothing on the way, including PPQ's own servers, can read it.
- The enclave sends a credit check to PPQ's backend: which model, and is there balance. No content.
- The enclave decrypts the request and sends it to the model's provider (Anthropic, Google, AWS Bedrock, Fireworks, OpenRouter, etc). The provider sees the prompt, as it must, since that is where the model runs. It sees PPQ's credentials, not you.
- The provider's response comes back into the enclave and is encrypted to you there.
- The enclave sends a billing event to PPQ's backend: token counts, model, cost, and potential error data. Again, no content.
- You receive the response plus a signed receipt stating which provider and which model actually served you.
The enclave's code is open source and reproducibly built, so anyone can check that the enclave running in production is the code that was published. The solid lines in the diagram carry your content; the dashed lines carry only billing metadata. That is the whole design.
What the Enclave Router prevents PPQ from doing
Reading or keeping your queries. Your request is decrypted only inside the enclave. PPQ's backend and PPQ's logs never see the request content at all; only billing and request metadata (which model, how many tokens, whether an error occurred) reach PPQ's backend. There is nothing to harvest, sell or hand over: PPQ cannot release the content of your queries to a third party, or produce it under a subpoena, because it never holds it in an extractable way.
Altering the answers. The provider's response is decrypted inside the enclave and then encrypted back to you. PPQ cannot change a word, and the only code that handles the reply in the clear is the published, measured code anyone can read. This is exactly what the 26 malicious routers mentioned above were caught doing: rewriting responses in flight to inject tool calls and steal credentials. An enclave has no way to do it.
Quietly serving a different model from the one you requested. The worry is that you ask for Claude and PPQ secretly serves you a cheaper, less capable model instead. The enclave rules that out in two ways. First, its code binds each model family to its provider, with OpenRouter as the only fallback: a request for a Claude model can go to Anthropic or to OpenRouter, and nowhere else, and likewise for GPT, Gemini and others. Second, every streamed response carries a routing receipt, signed by the enclave, stating the model you asked for, the provider the enclave actually connected to, and the exact model id it sent there. Attestation proves the enclave is running the published code; the receipt proves where that code sent your request. Between them there is no room for a quiet swap.
The same goes for AWS. The enclave runs on AWS hardware, and AWS cannot read or manipulate it either. The Nitro System is built so that no AWS operator, however privileged, can log in to the host or read the memory of what runs on it, and AWS states that this holds "including in fulfillment of a law enforcement request". The design is described in The Security Design of the AWS Nitro System and was independently reviewed by NCC Group, who "found no gaps in the Nitro System that would compromise these security claims."
Don't take our word for it: the PPQ Privacy Verifier
The PPQ Privacy Verifier is a small, open-source proxy you run on your own machine. Point any OpenAI- or Anthropic-compatible client at it instead of at PPQ directly. When it starts, it fetches the enclave's attestation and checks it against the published code measurement. If they do not match, it refuses to send anything. If they do, every request you make is encrypted with EHBP (Encrypted HTTP Body Protocol) to a key that only that verified enclave holds, and the response is decrypted back on your machine.
You get the same privacy without it: every request enters the enclave either way. What the Verifier adds is that you checked the enclave, rather than trusting PPQ to have done it. If you want to go one step further, verify-receipt.mjs in the enclave repository checks a routing receipt's signature against the enclave's attestation, so you can confirm not just that the enclave is genuine but that your request went where you paid for it to go.
What about PPQ's end-to-end encrypted TEE models?
PPQ also serves open-weight models such as Kimi and GLM from inside a Tinfoil enclave, where the model itself runs, so not even the provider can read your prompt. These are the models PPQ labels E2EE, and we introduced them earlier this year.
The two work together. The Enclave Router hides your prompt from PPQ; for frontier models like Claude and GPT the provider still sees it, because that is where the model runs. With an E2EE model, the provider is Tinfoil, and Tinfoil cannot read your prompt either. E2EE requests still pass through the Nitro enclave for billing, and the Privacy Verifier can check Tinfoil's enclave for you as well.
What the Enclave Router does not cover yet
Today the Enclave Router handles chat only: every chat completion, from the web app or the API, is served inside the enclave. Everything else PPQ offers is not yet routed through it. Image, video and music generation, text to speech, speech to text and the other media endpoints are still handled by PPQ's backend directly. PPQ still promises not to log those queries, but we are not yet proving it the way we are for chat.
Bringing those request types into the enclave is planned, and our Privacy Policy will be updated as each one moves over.
How the rest of PPQ adds to this
PPQ has no accounts. You do not sign up, and giving an email address is optional. You buy credits, you get a credit id, and that id is all PPQ needs to serve you. Most users buy those credits with cryptocurrency: Bitcoin (on-chain or Lightning), Monero, stablecoins and other coins.
Put together with the enclave, that splits what anyone can know about you into pieces that never meet:
- PPQ knows a credit id, how it was funded, and billing metadata: which model, how many tokens, when. If the credits were bought with crypto, none of that points at a person.
- The model's provider sees your prompt, but the request arrives from PPQ's enclave under PPQ's credentials. The provider sees PPQ, not you.*
- Tinfoil, for E2EE models, sees neither your prompt nor you.
So the party that could read your prompt does not know who you are, and the party that knows how you paid cannot read your prompt. The content and the identity never sit in the same place.
Two caveats. Paying by card attaches your card details to your credit id at PPQ, though still not at the provider; pay with crypto if that matters to you. And your IP address is visible to PPQ's network edge like any web request, so use a VPN if you want that hidden too.
* OpenAI is currently the one exception. It requires a per-customer identifier on every request, so that one user's policy violation is scoped to that user rather than to all of PPQ. For OpenAI models the enclave attaches a keyed hash of your credit id. OpenAI can tell that a set of requests came from the same customer, but cannot turn the hash back into a credit id, let alone a person. This is disclosed in our Privacy Policy.
What is PayPerQ?

PayPerQ is a pay-per-query AI service that gives you instant access to hundreds of chat, image, video, and audio AI models in one place. Unlike traditional ChatGPT subscription that charges $20+ per month, PPQ users pay only for what they use—averaging just $4 a month.
Account registration optional. No monthly commitments. Privacy focused. Credit cards and all major cryptos accepted. Just top up with as little as 10 cents and start using premium AI immediately.
Why Use PayPerQ?
- Access hundreds of AI models from all major providers in one place
- Pay per use - no subscriptions, no wasted money on unused credits
- No registration required - start using AI in seconds
- Start small - top up with as little as 10 cents
- Privacy-first - conversational data stored locally by default
- Average cost: ~1 cent per query
Getting Started
- Visit ppq.ai
- Top up your balance (crypto or credit card, as little as 10 cents)
- Select your model and start chatting
No account creation needed—just fund and go.