Implementation · Apple Private Cloud Compute
Evidence & limits
On this page
R3In production for showing users which software serves their AI requests, not which model
ReadinessMedium confidence
PCC is a production service whose attestation, transparency log and research tools are public, but no independent evaluation has examined its attestation chain as a whole.
Assessed use: showing users which software serves their AI requests, not which model
Rubric assessment
- R1 met: Apple published the design, the claim that devices send data only to nodes that attest to publicly listed software, and a threat model that includes attackers with physical access to a node 1.
- R2 met: the software images, a research environment that boots them and part of the source code are public 1 2. Independent researchers sent queries to the production service from macOS and iOS clients between December 2025 and March 2026 4.
- R3 met: PCC is production-grade and available as the server side of Apple Intelligence (provider-reported) 1, and independent researchers have used the production service 4. Its transparency log, binaries and research environment are public 2. The attestation check is made by Apple's own client software, and no other party is documented relying on it for a verification decision.
- R4 not met. The two independent public analyses are narrow. A peer-reviewed study reverse-engineered the client and found request-authentication flaws, which Apple addressed only in its documentation. Its subject is request privacy, not attestation 4. A researcher working in Apple's research environment reports that a node with tampered configuration files passed Apple's attestation check, and Apple fixed the path-handling bug behind it 5 6. Neither evaluates the attestation and transparency chain as a whole. The 2026 deployment on Google Cloud uses Intel TDX and NVIDIA confidential computing 3. Independent researchers with physical access forged TDX attestations and paired them with relayed H100 attestations 7. No published work tests whether Apple's use of two independent roots of trust resists that attack.
Gaps to the next level
- An independent public evaluation of the attestation and transparency-log chain, including what attestation covers at runtime, that leaves no critical flaw open.
- Evidence that the Google Cloud deployment's attestation resists attackers with physical access to TDX and NVIDIA hardware.
- Reproducible builds, so that published binaries can be checked against published source.
Assessed 2026-09-25 against rubric v1.1.
Evidence
- Researchers at the Hasso Plattner Institute, TU Darmstadt and IMDEA Networks reverse-engineered PCC's client and sent custom queries to the production service between December 2025 and March 2026 4. They found that one-time request tokens could be reused, that a signature check was skipped and that token salts let requests be linked. Apple clarified its documentation but did not change the checks 4. The study, peer-reviewed at WiSec 2026, concerns request privacy, not attestation.
- An independent researcher working in Apple's research environment reports a path-traversal flaw (CVE-2026-20685) that let a node's configuration be altered while its attestation stayed unchanged 5 6. Apple fixed it and paid a $150,000 bounty 5.
- Apple reports that for the Google Cloud deployment it will publish all binaries and give researchers access to live nodes in research mode 3.
Limitations
- The published checks concern software releases. Apple reports that model assets share the code's integrity protection 1, and its research environment runs demonstration models 2.
- PCC ships compiled binaries without reproducible builds or symbols, which its independent analysts say leaves room for differences between the specification and what is shipped 4.
- In the one published attack, the researcher found that attestation appeared to cover installed software but not writable configuration files 5.
- In early 2026 the independent analysts found no PCC API for third parties 4. Apple reports that developers in its App Store Small Business Program with fewer than 2 million first-time downloads can use its models on PCC, once Apple assigns them an entitlement 8.
- The Google Cloud deployment runs on Intel TDX and NVIDIA confidential computing 3. Independent researchers with physical access have forged TDX attestations 7 9, and one team relayed H100 attestations to a workload outside TEE protection 7.
Known flaws
Blockers
Published binaries cannot be rebuilt from source and carry no symbols, so checking what the attested software does needs reverse engineering.
Outside developers can use PCC only with an entitlement from Apple, which is limited to small developers.