Research Note

Private Cloud Compute Architecture and Assurance Record

Apple's [Private Cloud Compute Security Guide](https://security.apple.com/documentation/private-cloud-compute/) describes PCC as a server-compute system for Apple Intelli

Aug 4, 20262 min readBy Dalton Anderson
In this article

Private Cloud Compute Architecture and Assurance Record

What Apple claims

Apple's Private Cloud Compute Security Guide describes PCC as a server-compute system for Apple Intelligence requests that need larger models than the device can provide.

Apple states that PCC uses Apple silicon, a hardened operating system, stateless computation on personal user data, no privileged runtime access, non-targetability, remote attestation, publicly logged software measurements, and software made available for researcher inspection.

Apple's Release Transparency documentation says devices send private requests only to nodes whose runtime measurements match authorized builds in an append-only transparency log. Researchers can obtain referenced binaries, reproduce measurements, and inspect the software using the Virtual Research Environment.

Apple also publishes selected source in the security-pcc repository and offers a security-bounty path for findings.

In June 2026, Apple published Expanding Private Cloud Compute, describing PCC deployment on Google Cloud while claiming that PCC's hardware, software, privacy, and transparency properties remain enforced. This is a material architecture and dependency update that a 2024 explainer could not include.

Assurance boundary

All architecture statements above are Apple first-party claims and artifacts. Public code, binaries, measurements, logs, and research environments can improve inspectability. Their availability does not by itself prove that a particular independent party has reviewed every component, that every deployed request followed the documented path, or that the system is suitable for every data class and threat model.

A product decision must still consider the device, feature, request class, execution environment, external-service handoff, endpoint security, account state, network, logging, policy, jurisdiction, and acceptable residual trust.

Editorial rule

Use "Apple says," "Apple documents," or "the architecture is designed to" for first-party properties. Reserve "verified" for a named method, artifact, scope, date, and reviewer.

Sources

Follow the evidence.

  1. support.apple.com: 121582support.apple.com
  2. support.apple.com: 118105support.apple.com
  3. open.spotify.com: 3HwL2aWitmMezTHw5n19iFopen.spotify.com
  4. youtu.be: ZQGKh2ulJ3Yyoutu.be
  5. security.apple.com: private cloud computesecurity.apple.com
  6. security.apple.com: appendix appleintelligencereportsecurity.apple.com
  7. support.apple.com: 100100support.apple.com
  8. apple.com: wwdc24 highlightsapple.com
  9. security.apple.com: expanding pccsecurity.apple.com
  10. apple.com: apple intelligence is available today on iphone ipad and macapple.com
  11. support.apple.com: 108771support.apple.com
  12. security.apple.com: releasetransparencysecurity.apple.com
  13. support.apple.com: 121115support.apple.com
  14. daltonanderson.ghost.io: apples wwdc 2024 ai ios 18 whats next for youdaltonanderson.ghost.io
  15. gsma.com: RCC.71 v3.0gsma.com
  16. github.com: security pccgithub.com
  17. gsma.com: rcs universal profile 4 1 stronger foundations for secure messaginggsma.com
  18. apple.com: introducing apple intelligence for iphone ipad and macapple.com
  19. support.apple.com: 122195support.apple.com

From this episode

Two useful next steps.

Research Note · 1 min

WWDC 2024 Announcement State Record

Apple held the WWDC24 keynote on June 10, 2024. Its [WWDC24 Highlights](https://www.apple.com/newsroom/2024/06/wwdc24-highlights/) page is the canonical event-level recor

Episode Story · 1 min

Revisiting My WWDC 2024 Apple Intelligence Reaction

A sourced retrospective on Venture Step E021, Apple Intelligence, iOS 18, RCS, iPad Calculator, and what changed after WWDC 2024.

Return to the episode