Private compute & AI
Lit Protocol vs Tinfoil
Verify the runtime. Govern what it can do.
Private inference needs protection from the host. Applications that also use credentials, tools, or wallets need a clear authority model for those actions.
Scope: Lit’s on-chain approval method for confidential containers, Tinfoil hosted inference, and Tinfoil Containers. Contact Lit to plan training or inference.
Operator authority
Three questions about operator authority.
| Control | Lit · On-chain approvals | Tinfoil |
|---|---|---|
| Who can change the permissions? | Approvers designated by the deployment’s on-chain governance authorize changes to container code or network policy. Each change creates a new measured release.[1][2] | Tinfoil controls the hosted inference application. With Containers, customers define their application’s permissions through its code and configuration. Review who can publish changes to that configuration.[5][3] |
| Who can approve replacement code? | The approvers authorized by the governance contracts can approve runtime releases. The key-management system checks on-chain approval and hardware attestation before releasing keys. Deploying new code is not enough.[2][6] | Tinfoil publishes the hosted inference releases; Container customers publish their application configuration. The SDK checks the running software against published build evidence. Review who can approve changes to both the application and its underlying runtime.[5][3] |
| Who can stop access? | The runtime host can stop execution. Key release also depends on the key-management service. On-chain approval does not guarantee continued service or recovery.[1][2] | Hosted inference and Containers depend on Tinfoil’s running service. Verification can identify the software serving a request; it cannot require the provider to keep serving requests. Evaluate data persistence and recovery separately.[5][3] |
Who can change the permissions?
- Lit · On-chain approvals
- Approvers designated by the deployment’s on-chain governance authorize changes to container code or network policy. Each change creates a new measured release.[1][2]
- Tinfoil
- Tinfoil controls the hosted inference application. With Containers, customers define their application’s permissions through its code and configuration. Review who can publish changes to that configuration.[5][3]
Who can approve replacement code?
- Lit · On-chain approvals
- The approvers authorized by the governance contracts can approve runtime releases. The key-management system checks on-chain approval and hardware attestation before releasing keys. Deploying new code is not enough.[2][6]
- Tinfoil
- Tinfoil publishes the hosted inference releases; Container customers publish their application configuration. The SDK checks the running software against published build evidence. Review who can approve changes to both the application and its underlying runtime.[5][3]
Who can stop access?
- Lit · On-chain approvals
- The runtime host can stop execution. Key release also depends on the key-management service. On-chain approval does not guarantee continued service or recovery.[1][2]
- Tinfoil
- Hosted inference and Containers depend on Tinfoil’s running service. Verification can identify the software serving a request; it cannot require the provider to keep serving requests. Evaluate data persistence and recovery separately.[5][3]
The Lit advantage
On-chain rules govern runtime key access
Lit requires on-chain approval for changes to container code and network policy. The attested runtime must match an approved release before receiving its keys.[1][2]
How confidential AI worksWhat control means in practice
For AI, assess control over data, credentials, releases, and outputs separately. Tinfoil offers a direct private-inference product. Lit uses on-chain approval to authorize container releases and their network policies. The team confirms model support, hardware capacity, and what you can verify for each deployment.[5][1]
Shared protections
Both provide software verification and hardware isolation. Tinfoil’s SDK checks attested software against published build evidence and encrypts requests to the enclave.[3][4]
Sources and review scope
These comparisons use published documentation and the source code linked below. We have not audited or tested the providers’ live systems. Configurations vary, and source code alone does not establish who currently owns a deployed contract or how it is configured.