Establish identity and scope
Identify sensitive workload, Service Endlet, supported confidential-computing host, key service; validate participating Endlets before admission.
Protected data in use · Architecture
Run an approved sensitive workload inside a hardware-backed trusted execution environment on a supported host.
Primary capability
Confidential Execution
How it works
Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.
Identify sensitive workload, Service Endlet, supported confidential-computing host, key service; validate participating Endlets before admission.
validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path
Review attestation state, workload identity, key release conditions, policy enforcement, network paths with the responsible teams.
Architecture flow
Inputs
sensitive workload, Service Endlet, supported confidential-computing host, key service, representative data source, policy controls
Path
validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path
Evidence
attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results
Quick answers
validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path
attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results
security architecture, platform engineering, data owners, application owners, compliance
Continue the evaluation path
Determine whether the selected workload can run inside an attested environment with controlled key release and network access.
Continue to Evaluation