Where the trust stops
The gateway proves what it is running, to hardware and to a public log.
A receipt is only as good as the thing that wrote it. The Sumplus gateway runs inside an AMD SEV-SNP confidential machine and publishes a hardware report plus the head of its own call chain. This page reads both live from production.
Hardware report
| Mode | mock |
|---|---|
| Measurement | 2f86ed76802af9119576dec439fd4025cff25c607f4fdd4082b45b1950791ded |
| Binary | c7ab54fb390e3052aef5c1266db55541b8b43d10454172506ca006cdd9df7a96 |
| Model list digest | eaf141061b218b81624e6a6d7d0dafb541dc2fe9b6787309a92f2e8ed75fb71f |
| Provider list digest | 2c2ece3da3be318d260de87482c6a3a9536476e8afa623c2fea80af6c12dd3ea |
| Uptime | 44 hours |
Public anchor
The chain head is published to Sigstore Rekor. That log runs outside Sumplus, so an entry once written cannot be quietly revised by the party it describes.
| Log index | 3072280860 |
|---|---|
| Entry | 108e9186e8c5677aa2fb47adb42d147723ff4dd25bfa48c4ff39d26a3d1711aee8a5d77deabb55b2 |
| Log | https://rekor.sigstore.dev |
| Measurement anchored | 2f86ed76802af9119576dec439fd4025cff25c607f4fdd4082b45b1950791ded |
Check it without this page:
curl -s https://router.sumplus.xyz/attestation
curl -s https://router.sumplus.xyz/v1/rekor