Notifications
Clear all
Topic starter
July 5, 2026 10:59 am
I've been reading the docs for IronClaw's new TEE runtime. They claim the enclave "seals secrets at rest" using the platform's hardware root of trust.
I understand the concept of sealing, but I'm unclear on how to verify it's actually happening. Is it just a file encryption claim, or is the key truly bound to the TEE's measurement?
What would be a simple, concrete test I could run on my own test system? Something that would fail if the sealing was just software-based. I'm thinking about power cycling or modifying the enclave binary, but I'm not sure what to look for in the output.