| Before | After | ||
|---|---|---|---|
| 11 | Get started with the Guide Start exploring the PCC design by learning about the extraordinary security requirements of the system. | 11 | Explore our Core Requirements Start exploring the PCC design by learning about the extraordinary security requirements of the system. |
| 14 | For the full set of topics covered in the guide, see Navigating the Security Guide . | 14 | Topics Core Requirements Core Security & Privacy Requirements Dive into understanding PCC by learning about the extraordinary security requirements of the system. |
| 15 | Stateless Computation and Enforceable Guarantees The PCC node is designed to safeguard user data and enforce that it is not retained once request processing is complete. | ||
| 16 | No Privileged Runtime Access PCC is designed without privileged interfaces that might expose user data. | ||
| 17 | Non-Targetability PCC is designed to ensure that an attacker cannot target specific PCC users. | ||
| 18 | Verifiable Transparency Security researchers can verify the PCC privacy and security guarantees. | ||
| 19 | Hardware and Software Hardware Root of Trust Custom-built server hardware ensures security properties are immutable. | ||
| 20 | Hardware Integrity Hardware used for PCC is subject to rigorous security processes. | ||
| 21 | Software Foundations PCC nodes run a purpose-built operating system designed for protecting user data. | ||
| 22 | Software Layering The PCC node software is designed to ensure transparency of all components. | ||
| 23 | Request Processing Request Flow Anonymous request routing helps ensure non-targetability. | ||
| 24 | Attested Request Handling We designed the PCC application protocol to preserve client anonymity and efficiently route traffic through the PCC fleet. | ||
| 25 | Runtime Configuration and Assets PCC supports runtime-configurable properties and cloud-distributed assets to manage node behavior during boot sessions. | ||
| 26 | Transitive Trust PCC nodes establish transitive trust in other nodes by validating attestations on behalf of a user’s device. | ||
| 27 | PCC Applications Stateless Inference The PCC inference engine enables high performance while keeping user data private. | ||
| 28 | Private Filter Service Answers probabilistic membership queries from other PCC components without the queries leaving the trust boundary. | ||
| 29 | PCC Agent PCC Agent executes application-specific workflows on proxy nodes, coordinating tool invocations across PCC nodes. | ||
| 30 | Multi-Turn Agent The Multi-Turn Agent coordinates conversational and tool-using workflows over a persistent connection, with bounded cross-request state. | ||
| 31 | Visual Lookup Privacy-preserving lookup of visual entities using embedding-based search and private information retrieval (PIR). | ||
| 32 | Private Information Retrieval A cryptographic technique for retrieving data from servers outside the PCC trust boundary without revealing which records were accessed. | ||
| 33 | Home Kit Secure Video Analysis The HomeKit Secure Video analysis workflow generates natural-language video descriptions and embeddings for HomeKit Secure Video recordings. | ||
| 34 | Media Decoding A dedicated PCC worker decodes untrusted compressed video and images into pixel buffers, isolated from the workflows that consume them. | ||
| 35 | Visual Generation PCC runs the Apple Diffusion Model to generate images. | ||
| 36 | Embedding Generation An embedding tool that generates text and video embeddings. | ||
| 37 | Speech Synthesis PCC Agent synthesizes spoken audio inside the PCC trust boundary. | ||
| 38 | Transparency and Management Release Transparency PCC attestation capabilities support independently verifiable transparency. | ||
| 39 | Management & Operations PCC nodes support privacy-aware management, observation, and debug capabilities. | ||
| 40 | Security Analysis Anticipating Attacks How PCC’s security and privacy mechanisms stand up to anticipated threats. | ||
| 41 | Source Code To simplify security research, source code is available for certain security-critical PCC components. | ||
| 42 | Virtual Research Environment Virtual Research Environment Interact with and debug the PCC software stack. | ||
| 43 | Get Started with the VRE Configure your system to run the PCC Virtual Research Environment (VRE). | ||
| 44 | Interact with the VRE Issue requests to and configure the VRE. | ||
| 45 | Research Variant Use the research variant to dive deeper into PCC. | ||
| 46 | Shadow Tunneling Replace compute cloud apps with controllable proxies to exercise arbitrary behaviors in the VRE. | ||
| 47 | Inspecting Releases Use the VRE tools to inspect releases in the transparency log. | ||
| 48 | Reference Release Notes PCC Software Release Notes. | ||
| 49 | Reporting Issues Reporting issues with Private Cloud Compute. | ||
| 50 | Appendix: Secure Boot Tags The format of an Image4 manifest. | ||
| 51 | Appendix: Trust Cache Format The internal structure of a TrustCache. | ||
| 52 | Appendix: Secure Boot Ticket Canonicalization The construction of a release from an Image4 ticket. | ||
| 53 | Appendix: System Configuration The node’s configuration parameters. | ||
| 54 | Appendix: Runtime configuration consumers The daemons and services that consume configuration that you can update at runtime. | ||
| 55 | Appendix: Attestation Bundle Contents The contents and validation of an attestation bundle. | ||
| 56 | Appendix: Transparency Log The protocol for communication with the transparency log service. | ||
| 57 | Appendix: Apple Intelligence Report The transparency data available on client devices. | ||
| 58 | Appendix: Tool Gateway Protocol The wire formats and connection life cycle of the tool gateway protocol. | ||
| 59 | Appendix: PCC Application Identifiers The cloud applications that run on PCC nodes, the identifiers they’re known by, and the cryptexes that distribute them. | ||
Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.