Encrypted zone (EZ) is a private computing platform that separates data governance from business logic using hardware-attested, containerized microservices and policy-as-code.

No DSLs, no centralized gateways. By executing data protection policies as hardware-attested microservices, EZ allows you to provide verifiable transparency for your service's data handling with a minimal audit surface without exposing proprietary code.

Benefits

EZ uses open source policy-as-code to ground software behavior in a verifiable, hardware-attested policy. This differentiation allows closed source workloads to remain governed by auditable privacy rules and reduces audit overhead by excluding irrelevant code from the audit scope.
By requiring explicit RPC-level declarations for all data transmissions, EZ protects against intentional exfiltration and accidental leakage.
EZ's containerization framework integrates seamlessly with OCI builds and modern control planes like Kubernetes and Istio. The EZ SDK provides a "lift and shift" migration path for existing code and tooling without requiring full code rewrites.
EZ provides an enclave-agnostic framework that supports secure, enclave-terminated network channels between nodes and integrates with sidecar proxies to manage platform-specific integrations like DNS and monitoring at cloud scale.
EZ is designed to integrate with transparency infrastructure and transparent software releasing, enabling experts in the general public to audit the entire history of the policy-as-code layer.
Learn more about the encrypted zone's architecture, technology dependencies, and how it can help you achieve verifiable privacy for your service.