Sovereign vs. Confidential Computing

Confidential Computing moves the reader.
Sovereign Computing removes the read.

The most common question we're asked is “isn't this just a secure enclave?” It isn't — and the difference is the whole thing.

The distinction

An enclave relocates the observer. It never removes one.

Confidential Computing is real, and useful. A Trusted Execution Environment decrypts your data inside an enclave, proves its configuration with an attestation, and keeps the operator out. But follow the chain and a reader is always still there — it has just moved.

Someone still holds the key

The plaintext is decrypted inside the enclave — so whatever has privilege inside that boundary can see it. The reader moved from the operator to the enclave's root of trust: the silicon vendor.

Attestation is a promise

An attestation is a signed statement that no one looked. It is a certificate you choose to believe — not a refusal. It tells you the enclave was measured; it cannot make the data unreadable.

The operator provisions it

The operator stands up the enclave, configures it, and runs the attestation infrastructure. Sovereignty the operator grants is not sovereignty — it is permission, and permission can be withdrawn.

Side by side

Two answers to “can the operator see it?”

One relocates the observer to a place you're asked to trust. The other refuses the read at the machine.

The question
Confidential Computing
Sovereign Computing — NS
The observer
Relocated to a trusted enclave.
Removed at the read.
What you trust
The enclave, and its root of trust — the silicon vendor.
Nothing. There is no enclave to trust.
The mechanism
An encrypted enclave with an attestation handshake.
A refusal a layer beneath the driver.
A host read returns
Ciphertext, behind attestation.
An I/O error. Not data.
The guarantee is
A signed promise that no one looked.
The read does not resolve.
Who provisions it
The operator stands it up and holds the keys.
It sits beneath the operator.

Confidential Computing answers “is the enclave what it claims?” We answer the question it can't: who is inside it, and why do you trust them? Our answer is no one — because there is nothing to be inside of.

Where we are today, stated plainly

Leadership that survives the follow-up question.

We hold our own boundary as strictly as we draw theirs — because the claim is only worth what it survives.

Proven now

The read is refused on the observation path

Host-originated reads of the sovereign region return an I/O error, not data — proven on two independent NVIDIA architectures, Blackwell and Lovelace (99.98% / 99.97%). No enclave, no key held, no attestation to believe.

Structural · S-Chip

The last seam closes in silicon

Today the everyday refusal is software-mediated below the driver; a privileged operator who unbinds the driver can still reach the framebuffer window. The S-Chip closes that seam structurally — the property engineered into hardware. Design-proven in RTL; roadmap to silicon.

This is the host-OS observation path — not a claim of side-channel or kernel-privilege immunity. Stated on the face of every result, because that discipline is what makes “we lead” hold.

Not a competitor. A different layer.

We even compose with it.

Sovereign Computing isn't a rival enclave — it's a property a layer beneath. It runs on the same NVIDIA silicon the industry is financing by the hundreds of billions, alongside Confidential Computing, not instead of it. Where CC gives you an enclave to trust, we give you one fewer thing to trust. Both can be true on the same machine.

Runs on standard NVIDIA siliconComposes with your identity provider No key held, no enclave to trustThe refusal is the guarantee

Stop trusting that no one looked.
Refuse the look.

See the host handed an I/O error where an enclave would hand you a promise.