Learn · Security architecture

Confidential Computing: Enclaves & Proof

Confidential computing — running workloads inside hardware-isolated enclaves the host cannot inspect — solves a technical problem. VirtEngine solves the adjacent marketplace problem: proving to a paying counterparty that confidentiality actually holds, before secrets are delivered.

A person's face in profile, lit from the side.
Confidentiality you can verify, not just trust.

The trust gap in rented compute

When a workload runs on someone else's hardware, the operator can normally read its memory. Trusted execution environments (TEEs) close that hole in silicon, producing attestations: hardware-signed evidence of exactly what code, in exactly what configuration, is running inside the enclave.

But an attestation is only useful if the counterparty can verify it and act on it. That is the part VirtEngine puts on-chain.

Attestation as chain state

The enclave module (x/enclave) records and verifies TEE attestations against the state machine's expectations. A provider's confidential-compute capability becomes a verifiable on-chain claim — and a filterable attribute. Tenants can constrain orders to attested enclave execution, so unverified capacity never even matches.

Secrets released only after proof

The encryption module (x/encryption) implements envelope encryption to specific recipients. In confidential workflows, workload secrets — keys, model weights, sensitive configuration — are sealed so they can only be delivered into an enclave whose attestation has verified. The sequence is proof first, secrets second, and it is enforced by protocol machinery rather than provider goodwill.

The rest of the assurance stack

Confidential workloads can use attested execution, chain-anchored mTLS (x/cert) on supported off-chain connections, auditor-signed provider attributes (x/audit), and fraud/dispute processes. VEID may be an offer-specific risk signal, but it does not establish workload confidentiality or service quality by itself.

Where to apply it

The pattern fits wherever data or models must not be exposed to the infrastructure operator: regulated datasets, proprietary model weights during training or inference, key-handling services, and multi-party computations where participants trust the enclave but not each other.

Asked about confidential computing

What is an attestation?

Hardware-signed evidence of exactly what code, in exactly what configuration, runs inside the enclave — verifiable by any counterparty, not just the operator's claim.

x/enclave module

When do our secrets move?

Only after attestation verifies. Envelope-encrypted payloads deliver into the proven enclave — proof first, secrets second — enforced by protocol machinery rather than provider goodwill.

x/encryption module

What can we show procurement?

On-chain attestations, auditor-signed provider attributes, optional VEID proofs where an offer requires them, mTLS channels, and signed metered usage — evidence to examine as part of a confidentiality review.

More questions → FAQ