Encrypted Zone:
Hardware-attested policy enforcement for closed source software at scale
Encrypted zone (EZ) is a private computing platform that separates data governance from business logic using hardware-attested, containerized microservices and policy-as-code.
No DSLs, no centralized gateways. By executing data protection policies as hardware-attested microservices, EZ allows you to provide verifiable transparency for your service's data handling with a minimal audit surface without exposing proprietary code.
Benefits
Verifiable privacy and compliance for proprietary code
EZ uses open source policy-as-code to ground software behavior in a verifiable, hardware-attested policy. This differentiation allows closed source workloads to remain governed by auditable privacy rules and reduces audit overhead by excluding irrelevant code from the audit scope.
Risk mitigation
By requiring explicit RPC-level declarations for all data transmissions, EZ protects against intentional exfiltration and accidental leakage.
Effortless integration
EZ's containerization framework integrates seamlessly with OCI builds and modern control planes like Kubernetes and Istio. The EZ SDK provides a "lift and shift" migration path for existing code and tooling without requiring full code rewrites.
Scalable enclave connectivity
EZ provides an enclave-agnostic framework that supports secure, enclave-terminated network channels between nodes and integrates with sidecar proxies to manage platform-specific integrations like DNS and monitoring at cloud scale.
Transparency
EZ is designed to integrate with transparency infrastructure and transparent software releasing, enabling experts in the general public to audit the entire history of the policy-as-code layer.
Learn more about Encrypted Zone
Learn more about the encrypted zone's architecture, technology dependencies, and how it can help you achieve verifiable privacy for your service.