Is it another proxy on top? What stops the provider from reading/storing the prompts at the LLM execution level?
As long as the prompt is not encrypted at some point, and I don't think LLMs can run on encrypted prompts, then it can be read.
What if the GPU has a custom bios flash that somehow logs the unencrypted prompts?
Is it another proxy on top? What stops the provider from reading/storing the prompts at the LLM execution level?