def:xsr/secure≈ Azure Confidential / Nitro
Sanctuary
Confidential compute on attested TEE hardware. Verifiable correctness via def:tvo. Regulator-friendly.
Defaults
TEE class
Hardware enclave required (SGX / TDX / SEV-SNP / Nitro).
Attestation policy
How fresh attestation must be at request time.