21PacketsContact Us
Healthcare

Protected data in use · Briefing

Define the operating requirements for protected data in use.

Run an approved sensitive workload inside a hardware-backed trusted execution environment on a supported host.

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path. Evaluation evidence includes attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results.Healthcare · Confidential ExecutionProtected data in useVerified service path and review points01ValidatedService Endlet02Attestedconfidentialenvironment03Approvedworkload and keyrelease04Protectedprocessing05Governed outputpathEvaluation evidenceattestation state · workload identity · key release conditionsEach control point and result is verified against the selected environment.

Primary capability

Confidential Execution

Operational outcome

Define the operating constraint, systems, and decision.

Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.

01

Define the operating scope

Include sensitive workload, Service Endlet, supported confidential-computing host, key service in a representative operating scope.

02

Trace the protected path

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path

03

Review the decision

Determine whether the selected workload can run inside an attested environment with controlled key release and network access.

Outcome readiness

Define the systems and constraints for protected data in use.

Give network, security, and operational teams one service path to review and one decision to make.

Include sensitive workload in the selected scope.
Include Service Endlet in the selected scope.
Include supported confidential-computing host in the selected scope.
Include key service in the selected scope.
Include representative data source in the selected scope.
Include policy controls in the selected scope.

Inputs

sensitive workload, Service Endlet, supported confidential-computing host, key service, representative data source, policy controls

Path

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path

Evidence

attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results

Quick answers

Protected data in use FAQs

Which systems are in scope for protected data in use?+

sensitive workload, Service Endlet, supported confidential-computing host, key service, representative data source, policy controls

What operational outcome should the team review?+

Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.

What decision should the briefing support?+

Determine whether the selected workload can run inside an attested environment with controlled key release and network access.

Continue the evaluation path

See the architecture behind protected data in use.

Determine whether the selected workload can run inside an attested environment with controlled key release and network access.

Continue to Architecture