The primitives and platforms behind verifiable data-in-use protection

Each guide defines the security boundary, what it protects, what remains outside the threat model, how attestation works, and which operating teams benefit. Use the pages together: no CPU, GPU, evidence service, or marketing label creates an end-to-end boundary by itself.

Core primitives

The shared vocabulary: protected execution boundaries and the evidence-to-authorization procedure that makes them verifiable.

  1. Trusted execution environments (TEEs): boundaries, properties, and fit

    What a hardware-backed trusted execution environment protects, what it leaves outside the boundary, and how to compare enclave and whole-VM approaches.

    Open
  2. Remote attestation: evidence, verification, and policy-gated trust

    A practical explanation of attesters, evidence, verifiers, reference values, freshness, attestation results, and key release.

    Open

CPU confidential VMs

Whole-VM platforms that preserve familiar guest software while changing the host and hypervisor trust model.

  1. Intel TDX: whole-VM trusted domains and attestation

    How Intel Trust Domain Extensions protect confidential VMs, how TD attestation works, what remains untrusted, and who benefits.

    Open
  2. AMD SEV-SNP: memory encryption, integrity, and the SEV progression

    How AMD SEV-SNP extends SEV and SEV-ES with memory-integrity protections, runtime attestation, and a stronger malicious-hypervisor model.

    Open
  3. Arm Confidential Compute Architecture: Realms, RME, and attestation

    How Arm CCA Realm Management Extension isolates Realms, what the Realm Management Monitor does, and where platform implementation still matters.

    Open

Confidential accelerators

Extending a supported CPU TEE into the GPU, with its own mode, firmware, evidence, protected device path, and limitations.

  1. NVIDIA Confidential Computing: extending a CPU TEE to the GPU

    How NVIDIA GPU confidential mode, protected transfers, attestation, CC-On, and CPU confidential VMs form an end-to-end boundary.

    Open