Don't take our word that this Space is private β check it. This page challenges the live enclave to
prove, cryptographically and right now, that your messages are handled by hardware the operator can't read, running
only the code we published.
Loading the published measurementβ¦
If the enclave is asleep (it scales to zero when idle) this starts it first β up to ~2β3 minutes.
This Space's enclave policy
A Space declares which enclave builds may ever hold its key. Only its owner can widen that list, and doing so starts a new epoch every member can see.
Verified enclave policy
Read straight from the policy the enclave measured at launch β the text is believed only because its digest is the live PCR17.
What a pass proves
πGenuine secure hardware. The attestation is signed by AWS's Nitro Security Module and chains to AWS's root β not something the operator can forge.
πThe exact code we published. The measurement (PCR0) is a fingerprint of the running image; it matches the one pinned here, which is built from open source you can reproduce.
πOperator-blind. Inside the enclave, memory is sealed from the host; your key is sealed to the attested enclave, so the platform relays only ciphertext.
β±οΈLive, not replayed. The proof is bound to a fresh random challenge from your browser β a recorded old attestation would be rejected.