Research Note
Private Cloud Compute Architecture and Assurance Record
Apple's [Private Cloud Compute Security Guide](https://security.apple.com/documentation/private-cloud-compute/) describes PCC as a server-compute system for Apple Intelli
In this article
Private Cloud Compute Architecture and Assurance Record
What Apple claims
Apple's Private Cloud Compute Security Guide describes PCC as a server-compute system for Apple Intelligence requests that need larger models than the device can provide.
Apple states that PCC uses Apple silicon, a hardened operating system, stateless computation on personal user data, no privileged runtime access, non-targetability, remote attestation, publicly logged software measurements, and software made available for researcher inspection.
Apple's Release Transparency documentation says devices send private requests only to nodes whose runtime measurements match authorized builds in an append-only transparency log. Researchers can obtain referenced binaries, reproduce measurements, and inspect the software using the Virtual Research Environment.
Apple also publishes selected source in the security-pcc repository and offers a security-bounty path for findings.
In June 2026, Apple published Expanding Private Cloud Compute, describing PCC deployment on Google Cloud while claiming that PCC's hardware, software, privacy, and transparency properties remain enforced. This is a material architecture and dependency update that a 2024 explainer could not include.
Assurance boundary
All architecture statements above are Apple first-party claims and artifacts. Public code, binaries, measurements, logs, and research environments can improve inspectability. Their availability does not by itself prove that a particular independent party has reviewed every component, that every deployed request followed the documented path, or that the system is suitable for every data class and threat model.
A product decision must still consider the device, feature, request class, execution environment, external-service handoff, endpoint security, account state, network, logging, policy, jurisdiction, and acceptable residual trust.
Editorial rule
Use "Apple says," "Apple documents," or "the architecture is designed to" for first-party properties. Reserve "verified" for a named method, artifact, scope, date, and reviewer.
Sources
Follow the evidence.
- support.apple.com: 121582support.apple.com
- support.apple.com: 118105support.apple.com
- open.spotify.com: 3HwL2aWitmMezTHw5n19iFopen.spotify.com
- youtu.be: ZQGKh2ulJ3Yyoutu.be
- security.apple.com: private cloud computesecurity.apple.com
- security.apple.com: appendix appleintelligencereportsecurity.apple.com
- support.apple.com: 100100support.apple.com
- apple.com: wwdc24 highlightsapple.com
- security.apple.com: expanding pccsecurity.apple.com
- apple.com: apple intelligence is available today on iphone ipad and macapple.com
- support.apple.com: 108771support.apple.com
- security.apple.com: releasetransparencysecurity.apple.com
- support.apple.com: 121115support.apple.com
- daltonanderson.ghost.io: apples wwdc 2024 ai ios 18 whats next for youdaltonanderson.ghost.io
- gsma.com: RCC.71 v3.0gsma.com
- github.com: security pccgithub.com
- gsma.com: rcs universal profile 4 1 stronger foundations for secure messaginggsma.com
- apple.com: introducing apple intelligence for iphone ipad and macapple.com
- support.apple.com: 122195support.apple.com