21PacketsContact Us
Healthcare

Protected data in use · Architecture

Map the service path for protected data in use.

Run an approved sensitive workload inside a hardware-backed trusted execution environment on a supported host.

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path. Evaluation evidence includes attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results.Healthcare · Confidential ExecutionProtected data in useVerified service path and review points01ValidatedService Endlet02Attestedconfidentialenvironment03Approvedworkload and keyrelease04Protectedprocessing05Governed outputpathEvaluation evidenceattestation state · workload identity · key release conditionsEach control point and result is verified against the selected environment.

Primary capability

Confidential Execution

How it works

Trace the protected service path from admission to evidence.

Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.

01

Establish identity and scope

Identify sensitive workload, Service Endlet, supported confidential-computing host, key service; validate participating Endlets before admission.

02

Build the protected service path

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path

03

Capture decision evidence

Review attestation state, workload identity, key release conditions, policy enforcement, network paths with the responsible teams.

Architecture flow

Trace the protected service path and its control points.

01

validated Service Endlet

02

attested confidential environment

03

approved workload and key release

04

protected processing

05

governed output path

Inputs

sensitive workload, Service Endlet, supported confidential-computing host, key service, representative data source, policy controls

Path

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path

Evidence

attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results

Quick answers

Protected data in use FAQs

Which technical path should the team review?+

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path

Which evidence should reviewers collect?+

attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results

Who should review the architecture?+

security architecture, platform engineering, data owners, application owners, compliance

Continue the evaluation path

Evaluate protected data in use with a representative scope.

Determine whether the selected workload can run inside an attested environment with controlled key release and network access.

Continue to Evaluation