21PacketsContact Us
Healthcare

Protected data in use · Evaluation

Evaluate protected data in use against agreed evidence.

One approved processing workload on a supported confidential-computing host using representative non-production data.

validated Service Endlet → attested confidential environment → approved workload and key release → protected processing → governed output path. Evaluation evidence includes attestation state, workload identity, key release conditions, policy enforcement, network paths, and execution results.Healthcare · Confidential ExecutionProtected data in useVerified service path and review points01ValidatedService Endlet02Attestedconfidentialenvironment03Approvedworkload and keyrelease04Protectedprocessing05Governed outputpathEvaluation evidenceattestation state · workload identity · key release conditionsEach control point and result is verified against the selected environment.

Primary capability

Confidential Execution

Evaluation plan

Test a representative scope against agreed acceptance criteria.

Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.

01

Select the operational scope

One approved processing workload on a supported confidential-computing host using representative non-production data.

02

Verify the technical path

Have representatives from security architecture, platform engineering, data owners, application owners, compliance review the architecture path and policy boundaries.

03

Review the decision evidence

Determine whether the selected workload can run inside an attested environment with controlled key release and network access.

Acceptance criteria

Define success with observable evidence and a decision.

Use representative systems, named owners, and a controlled operational scenario.

01

The evaluation uses one approved workload, a supported confidential-computing host, representative non-production data, and defined key-release conditions.

02

Security, platform, data, application, and compliance owners confirm the workload identity, attestation policy, and allowed network paths.

03

The team records attestation state, workload identity, key release, policy enforcement, network paths, and execution results.

04

The results show whether the workload executes in the attested environment with the agreed access controls.

Operational outcome

Protect selected code, keys, and clinical data while they are actively processed on a supported confidential-computing host.

Evaluation scope

One approved processing workload on a supported confidential-computing host using representative non-production data.

Decision

Determine whether the selected workload can run inside an attested environment with controlled key release and network access.

Quick answers

Protected data in use FAQs

What is a practical evaluation scope?+

One approved processing workload on a supported confidential-computing host using representative non-production data.

What should the team verify?+

1. The evaluation uses one approved workload, a supported confidential-computing host, representative non-production data, and defined key-release conditions. 2. Security, platform, data, application, and compliance owners confirm the workload identity, attestation policy, and allowed network paths. 3. The team records attestation state, workload identity, key release, policy enforcement, network paths, and execution results. 4. The results show whether the workload executes in the attested environment with the agreed access controls.

Who should review the result?+

security architecture, platform engineering, data owners, application owners, compliance

Plan the evaluation

Plan an evaluation for protected data in use.

Bring the scope, systems, owners, and operating constraint. We’ll map the 21Packets evaluation path with your team.

Book a working session