Keeps your prompts encrypted all the way to Nexus, which runs inside a TEE (trusted execution environment). Nobody in between can read them — not us, not Dappnode.
It verifies the TEE automatically on every connection.
Open the verification page — what was checked, right now, plus the raw proof to verify independently. It never shows your prompts.
Point any OpenAI-compatible app on this Dappnode at:
Base URL: http://nexus-proofs.dappnode.private:3301/v1
API key: your normal Nexus API key
Same key, same models, same prices. Some apps have a private mode switch that does this for you — Hermes Agent is one.
Pick a model whose id starts with private/. Those run inside a TEE too,
so your prompt stays encrypted the whole way — from Nexus Proofs to Nexus, and
from Nexus to the model. Other models are run by their provider, which sees the prompt to
answer it.
- Auto Router (
nexus/auto) and PII masking do not work through Nexus Proofs. Pick a specific model. - If the TEE cannot be verified, requests stop. That is deliberate.
- Keep port 3301 on the internal network.