The primitives and platforms behind verifiable data-in-use protection
Each guide defines the security boundary, what it protects, what remains outside the threat model, how attestation works, and which operating teams benefit. Use the pages together: no CPU, GPU, evidence service, or marketing label creates an end-to-end boundary by itself.
Core primitives
The shared vocabulary: protected execution boundaries and the evidence-to-authorization procedure that makes them verifiable.
-
Trusted execution environments (TEEs): boundaries, properties, and fit
What a hardware-backed trusted execution environment protects, what it leaves outside the boundary, and how to compare enclave and whole-VM approaches.
Open → -
Remote attestation: evidence, verification, and policy-gated trust
A practical explanation of attesters, evidence, verifiers, reference values, freshness, attestation results, and key release.
Open →
CPU confidential VMs
Whole-VM platforms that preserve familiar guest software while changing the host and hypervisor trust model.
-
Intel TDX: whole-VM trusted domains and attestation
How Intel Trust Domain Extensions protect confidential VMs, how TD attestation works, what remains untrusted, and who benefits.
Open → -
AMD SEV-SNP: memory encryption, integrity, and the SEV progression
How AMD SEV-SNP extends SEV and SEV-ES with memory-integrity protections, runtime attestation, and a stronger malicious-hypervisor model.
Open → -
Arm Confidential Compute Architecture: Realms, RME, and attestation
How Arm CCA Realm Management Extension isolates Realms, what the Realm Management Monitor does, and where platform implementation still matters.
Open →
Confidential accelerators
Extending a supported CPU TEE into the GPU, with its own mode, firmware, evidence, protected device path, and limitations.






