Define the operating scope
Include sensitive workload, Service Endlet, supported confidential-computing host, key service in a representative operating scope.
Protected data in use · Briefing
Run an approved sensitive workload inside a hardware-backed trusted execution environment on a supported host.
Primary capability
Confidential Execution
Operational outcome
Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.
Include sensitive workload, Service Endlet, supported confidential-computing host, key service in a representative operating scope.
validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path
Determine whether the selected workload can run inside an attested environment with controlled key release and network access.
Outcome readiness
Give network, security, and operational teams one service path to review and one decision to make.
Inputs
sensitive workload, Service Endlet, supported confidential-computing host, key service, representative data source, policy controls
Path
validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path
Evidence
attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results
Quick answers
sensitive workload, Service Endlet, supported confidential-computing host, key service, representative data source, policy controls
Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.
Determine whether the selected workload can run inside an attested environment with controlled key release and network access.
Continue the evaluation path
Determine whether the selected workload can run inside an attested environment with controlled key release and network access.
Continue to Architecture