The most common question we're asked is “isn't this just a secure enclave?” It isn't — and the difference is the whole thing.
Confidential Computing is real, and useful. A Trusted Execution Environment decrypts your data inside an enclave, proves its configuration with an attestation, and keeps the operator out. But follow the chain and a reader is always still there — it has just moved.
The plaintext is decrypted inside the enclave — so whatever has privilege inside that boundary can see it. The reader moved from the operator to the enclave's root of trust: the silicon vendor.
An attestation is a signed statement that no one looked. It is a certificate you choose to believe — not a refusal. It tells you the enclave was measured; it cannot make the data unreadable.
The operator stands up the enclave, configures it, and runs the attestation infrastructure. Sovereignty the operator grants is not sovereignty — it is permission, and permission can be withdrawn.
One relocates the observer to a place you're asked to trust. The other refuses the read at the machine.
Confidential Computing answers “is the enclave what it claims?” We answer the question it can't: who is inside it, and why do you trust them? Our answer is no one — because there is nothing to be inside of.
We hold our own boundary as strictly as we draw theirs — because the claim is only worth what it survives.
Host-originated reads of the sovereign region return an I/O error, not data — proven on two independent NVIDIA architectures, Blackwell and Lovelace (99.98% / 99.97%). No enclave, no key held, no attestation to believe.
Today the everyday refusal is software-mediated below the driver; a privileged operator who unbinds the driver can still reach the framebuffer window. The S-Chip closes that seam structurally — the property engineered into hardware. Design-proven in RTL; roadmap to silicon.
This is the host-OS observation path — not a claim of side-channel or kernel-privilege immunity. Stated on the face of every result, because that discipline is what makes “we lead” hold.
Sovereign Computing isn't a rival enclave — it's a property a layer beneath. It runs on the same NVIDIA silicon the industry is financing by the hundreds of billions, alongside Confidential Computing, not instead of it. Where CC gives you an enclave to trust, we give you one fewer thing to trust. Both can be true on the same machine.
See the host handed an I/O error where an enclave would hand you a promise.