ChutesContract
Inspiration
Everyone signs contracts they don't fully understand — offer letters, NDAs, leases, vendor SLAs, freelance agreements. Getting a lawyer to review them is slow and expensive, and the "AI contract review" tools that already exist all share the same fatal flaw for legal and confidential material: you have to trust the provider. When you paste an unsigned M&A draft or an employment agreement into a normal AI API, that text flows through someone else's host OS, hypervisor, logs, and staff, and "trust our privacy policy" is not something you can hand to a counterparty, an auditor, or a court.
We wanted to flip that. What if a contract analysis came with cryptographic proof that a specific AI model ran inside a sealed hardware enclave and never leaked your document? Chutes TEE inference made that possible, so we built ChutesContract around it.
What it does
ChutesContract turns a slow, trust-me-bro process into a fast, private, and independently verifiable one. You upload a contract and get back:
- A clause-by-clause risk breakdown (LOW / MEDIUM / HIGH with reasons).
- Plain-English translations of each clause for non-lawyers.
- Negotiation-ready redlines — specific language to push back on, prioritized.
- An overall GREEN / AMBER / RED verdict plus the single most important thing to renegotiate.
Every analysis is produced by a six-stage agent pipeline and backed by a downloadable Notarization Receipt with three verification tiers:
- Level 1 — Document Integrity: SHA-256 of the uploaded file and the analysis (tamper-evidence).
- Level 2 — Model Identity: exact model, chute ID, enclave instance, and freshness nonce.
- Level 3 — Intel TDX Enclave Proof: the base64 TDX quote and NVIDIA GPU evidence, with a one-click "Verify TDX Quote" button that checks it against a public attestation explorer running Intel DCAP verification.
That receipt is something OpenAI, Anthropic, and Google literally cannot produce.
How we built it
The core is a 6-agent pipeline, where each stage is its own Chutes call with a focused system prompt rather than one giant prompt:
- Document Parser — detects contract type and parties
- Clause Extractor — segments the contract into discrete clauses
- Risk Scorer — rates each clause LOW / MEDIUM / HIGH
- Plain-English Translator — explains each clause
- Negotiation Advisor — suggests redline language and priority
- Summary Agent — overall verdict, top risks, key change to negotiate
All stages run on a TEE-enabled model (deepseek-ai/DeepSeek-V3.2-TEE) on llm.chutes.ai. In parallel with the pipeline, we request a TDX quote and NVIDIA GPU evidence from api.chutes.ai/chutes/{id}/evidence, bound to a per-request 32-byte nonce, then assemble the notarization receipt.
The stack:
- Next.js 16 (App Router, React 19, TypeScript 5) and Tailwind CSS v4
- Chutes for TEE inference, attestation evidence, and OAuth 2.0 + PKCE sign-in (so inference is billed to the user's own account, no API keys in the browser)
- Supabase (Postgres) for durable, per-user analysis history scoped to the authenticated Chutes
sub - Web Crypto API for SHA-256 hashing and nonce generation
- A public TEE Attestation Explorer for one-click quote verification
To keep the slower TEE model (~10 tok/s) responsive, independent agents run concurrently and downstream stages return compact { id, field } arrays merged back by id, so clause text is generated once instead of re-emitted by every stage.
Challenges we ran into
- Latency on a TEE model. Confidential inference is slower (~10 tok/s), so a naive prompt chain felt glacial. We parallelized independent agents and used id-keyed merging to avoid re-generating clause text at every stage.
- Making attestation real, not decorative. Binding a per-request nonce into the TDX quote and fetching evidence in parallel — then surfacing it in a receipt anyone can independently verify — took real plumbing across
llm.chutes.aiandapi.chutes.ai. - Flaky LLM JSON. Models occasionally wrap JSON in markdown fences or emit malformed responses. We added fence-stripping, a
safeParsehelper with fallbacks, and per-agent fault isolation so one bad response degrades a single field instead of the whole analysis. - Cold enclaves. A cold TEE can hang or be unavailable, so we added per-call
AbortControllertimeouts and graceful degradation: Levels 1 and 2 of the receipt still hold even when Level 3 is temporarily "unavailable." - OAuth scope edge cases. The
chutes:invokescope authorizes inference, but we needed a clean server-key fallback for tokens lacking invoke permission.
Accomplishments that we're proud of
- A working proof-of-inference flow: every analysis ships with a hardware-signed receipt that a counterparty or auditor can verify without trusting us.
- A genuine multi-agent pipeline that stays fast and reliable despite a slow confidential model, thanks to concurrency, compact merging, and per-agent fault isolation.
- End-to-end Chutes integration — TEE inference, nonce-bound attestation, and OAuth IDP — where Chutes isn't a swappable backend but the thing that makes the product possible.
- Durable, per-user history in Postgres with user-scoped read and delete, available across devices.
- Honest graceful degradation so the app stays useful even when the enclave is cold.
What's next for ChutesContract
- Better document parsing — robust
.pdfand.docxsupport (PDF text layers, DOCX XML), beyond today's UTF-8 text path. - Lower latency — streaming responses for perceived speed, a smaller TEE model for lighter stages, and caching.
- Self-hosted verification — running our own Intel DCAP Quote Verification Library instead of relying on a public explorer, plus wiring NVIDIA NRAS GPU verification into the one-click flow.
- Deeper legal features — clause libraries, comparison against standard templates, and tracked redline exports.
- Always with the same north star: contract review you can prove, not just trust. (Still assistance, not legal advice.)
Built With
- chutes
- nextjs
- supabase
- tailwind
Log in or sign up for Devpost to join the conversation.