An open API service indexing awesome lists of open source software.

Confidential Computing

Confidential Computing is the protection of data in use by performing computation in a hardware-based, attested Trusted Execution Environment. A Trusted Execution Environment (TEE) is an environment that provides a level of assurance of the following three properties: data integrity, data confidentiality, and code integrity. TEEs may have additional attributes such as code confidentiality, programmability, recoverability, and attestability. Confidential Computing aims to reduce the ability for the owner/operator/pwner of a platform to access data and code inside TEEs sufficiently such that this path is not an economically or logically viable attack during execution.

https://github.com/microsoft/openvmm

Home of OpenVMM and OpenHCL.

confidential-computing rust vmm

Last synced: 14 May 2025

https://github.com/enarx/enarx

Enarx: Confidential Computing with WebAssembly

confidential-computing webassembly

Last synced: 25 Apr 2025

https://github.com/apache/incubator-teaclave-sgx-sdk

Apache Teaclave (incubating) SGX SDK helps developers to write Intel SGX applications in the Rust programming language, and also known as Rust SGX SDK.

confidential-computing rust sgx tee trusted-execution-environment universal-secure-computing

Last synced: 14 May 2025

https://github.com/apache/mesatee-sgx

Apache Teaclave (incubating) SGX SDK helps developers to write Intel SGX applications in the Rust programming language, and also known as Rust SGX SDK.

confidential-computing rust sgx tee trusted-execution-environment universal-secure-computing

Last synced: 05 Mar 2025

https://github.com/edgelesssys/constellation

Constellation is the first Confidential Kubernetes. Constellation shields entire Kubernetes clusters from the (cloud) infrastructure using confidential computing.

cloud-security confidential-computing data-encryption kubernetes kubernetes-security

Last synced: 14 May 2025

https://github.com/apache/incubator-teaclave

Apache Teaclave (incubating) is an open source universal secure computing platform, making computation on privacy-sensitive data safe and simple.

confidential-computing faas function-as-a-service rust secure-multiparty-computation sgx tee trusted-execution-environment trustzone universal-secure-computing

Last synced: 16 May 2025

https://github.com/inclavare-containers/inclavare-containers

A novel container runtime, aka confidential container, for cloud-native confidential computing and enclave runtime ecosystem.

cloud cloud-native cncf confidential-computing confidential-container container containers enclave intel-sgx kubernetes oci oci-runtime runtime sgx sgx-enclave tee trusted-applications

Last synced: 15 Dec 2025

https://github.com/edgelesssys/ego

EGo is an open-source SDK that enables you to develop your own confidential apps in the Go programming language.

confidential-computing confidential-microservices enclave golang intel-sgx sgx

Last synced: 18 Jun 2025

https://github.com/mithril-security/blindai

Confidential AI deployment with secure enclaves :lock:

ai confidential-computing enclave inference intel-sgx machine-learning onnx privacy python3 rust sgx

Last synced: 09 Oct 2025

https://github.com/intel/confidential-computing-zoo

Confidential Computing Zoo provides confidential computing solutions based on Intel SGX, TDX, HEXL, etc. technologies.

attestation cloud confidential-computing containers enclave key-management sgx tdx

Last synced: 16 Mar 2025

https://github.com/edgelesssys/marblerun

MarbleRun is the control plane for confidential computing. Deploy, scale, and verify your confidential microservices on vanilla Kubernetes. 100% Go, 100% cloud native, 100% confidential.

confidential-computing confidential-microservices distributed-systems enclave golang intel-sgx kubernetes microservice service-mesh sgx

Last synced: 11 Apr 2025

https://github.com/apache/teaclave-trustzone-sdk

Teaclave TrustZone SDK enables safe, functional, and ergonomic development of trustlets.

confidential-computing rust secure-computing tee trusted-execution-environment trustzone

Last synced: 04 Sep 2025

https://github.com/apache/incubator-teaclave-trustzone-sdk

Teaclave TrustZone SDK enables safe, functional, and ergonomic development of trustlets.

confidential-computing rust secure-computing tee trusted-execution-environment trustzone

Last synced: 15 May 2025

https://github.com/veracruz-project/veracruz

Main repository for the Veracruz privacy-preserving compute project, an adopted project of the Confidential Compute Consortium (CCC).

confidential-computing cryptography distributed-systems enclave nitro-enclaves privacy privacy-enhancing-technologies rust sel4 sgx tls trustzone wasm webassembly

Last synced: 16 Jan 2026

https://github.com/microsoft/regorus

Regorus - A fast, lightweight Rego (OPA policy language) interpreter written in Rust.

c confidential-computing cpp csharp golang interpreter java javascript no-std opa policy-as-code python rego rust wasm

Last synced: 31 Jan 2026

https://github.com/dstack-tee/dstack

Deploy any app to TEE.

confidential-computing intel-tdx tee

Last synced: 04 Apr 2025

https://github.com/edgelesssys/edgelessdb

EdgelessDB is a MySQL-compatible database for confidential computing. It runs entirely inside a secure enclave and comes with advanced features for collaboration, recovery, and access control.

confidential-computing database enclave mariadb mysql sgx sql

Last synced: 30 Dec 2025

https://github.com/edgelesssys/edgelessrt

Edgeless RT is an SDK and a runtime for Intel SGX. It combines top-notch Go support with simplicity, robustness and a small TCB. Developing confidential microservices has never been easier! C++17 and Rust (experimental) are also supported.

confidential-computing confidential-microservices enclave golang intel-sgx rust sgx trusted-execution-environment

Last synced: 18 Jun 2025

https://github.com/confidential-containers/trustee

Attestation and Secret Delivery Components

attestation confidential-computing key-management

Last synced: 16 Jan 2026

https://github.com/islet-project/islet

An on-device confidential computing platform

confidential-computing rust

Last synced: 20 Apr 2025

https://github.com/capeprivacy/nitrogen

Nitrogen is a tool for deploying web services to AWS Nitro Enclaves.

aws confidential-computing docker nitro-enclaves security

Last synced: 04 Jul 2025

https://github.com/capeprivacy/tf-trusted

tf-trusted allows you to run TensorFlow models in secure enclaves

confidential-computing machine-learning secure-enclaves security sgx

Last synced: 20 Apr 2025

https://github.com/riscv/riscv-smmtt

This specification will define the RISC-V privilege ISA extensions required to support Supervisor Domain isolation for multi-tenant security use cases e.g. confidential-computing, trusted platform services, fault isolation and so on.

access-control ap-tee confidential-computing io-mpt smgeien smmpt smmtt smqosid smsdedbga smsdetrca smsdia smsdid supervisor-domains trusted-computing trusted-execution-environment

Last synced: 01 Mar 2026

https://github.com/riscv-non-isa/riscv-ap-tee

This repo holds the work area and revisions of the non-ISA specification created by the RISC-V AP-TEE TG. This specification defines the programming interfaces (ABI) to support the Confidential VM Extension (CoVE) confidential computing architecture for RISC-V application-processor platforms.

confidential-computing confidential-vm h-extension security smmtt supervisor-domains tee tsm virtualization

Last synced: 24 Dec 2025

https://github.com/sjtu-ipads/hedb

Towards A Secure Yet Maintainable Encrypted Database

confidential-computing database-management encrypted-database maintanance postgres

Last synced: 09 Mar 2026

https://github.com/virtee/sev-snp-measure

Calculate AMD SEV/SEV-ES/SEV-SNP measurement for confidential computing

attestation confidential-computing security

Last synced: 07 Sep 2025

https://github.com/SJTU-IPADS/HEDB

Towards A Secure Yet Maintainable Encrypted Database

confidential-computing database-management encrypted-database maintanance postgres

Last synced: 20 Apr 2025

https://github.com/ibm/ace-riscv

Assured confidential execution (ACE) implements VM-based trusted execution environment (TEE) for RISC-V with focus on a formally verified and auditable security monitor.

confidential-computing coq formal-verification refinedrust riscv rust-lang security trusted-computing trusted-execution-environment virtualization

Last synced: 02 May 2025

https://github.com/R3Conclave/conclave-core-sdk

SDK for creating confidential SGX enclaves in Java, Kotlin and Python

confidential-computing java javascript kotlin python sgx sgx-enclave

Last synced: 20 Apr 2025

https://github.com/cc-api/evidence-api

Unified API to Access TCG Compliant measurement, event log, quote in Confidential Computing Environment.

confidential-computing trusted-computing

Last synced: 21 Jan 2026

https://github.com/cosmian/ciphercompute

The free EAP version of the Cosmian Collaborative Confidential Computing platform. Try it!

confidential-computing cryptography distributed-computing multiparty-computation

Last synced: 03 Aug 2025

https://github.com/capeprivacy/pycape

The Cape Privacy Python SDK

confidential-computing nitro nitro-enclaves python

Last synced: 12 Apr 2025

https://github.com/intel/confidential-cloud-native-primitives

Build Trusted Chain for Cloud Native in Confidential Computing Envrionment

cloud-native confidential-computing measurement tcb tdx tpm trusted-computing

Last synced: 11 Jan 2026

https://github.com/qascade/dcr

A PoC framework to orchestrate interoperable Differentially Private Data Clean Room Services using Intel SGX hardware as root of trust.

confidential-computing data data-security datacleanroom differential-privacy golang gssoc gssoc23 intel-sgx intel-sgx-sdk

Last synced: 15 Jan 2026

https://github.com/capeprivacy/functions

Sample functions for Cape Privacy

confidential-computing enclaves nitro nitro-enclaves python

Last synced: 12 Apr 2025

https://github.com/Fraunhofer-AISEC/cmc

Remote attestation for Trusted and Confidential Computing platforms (TPM, AMD SEV-SNP, Intel SGX/TDX)

cloud-security confidential-computing golang remote-attestation

Last synced: 31 Jan 2026

https://github.com/foxboron/go-tpm-keyfiles

TPM 2.0 TSS keyfile library

confidential-computing go-tpm tpm tpm2 tss

Last synced: 08 Oct 2025

https://sectrs-acai.github.io/acai

Protecting Accelerator Execution with Arm Confidential Computing Architecture (USENIX Security 2024)

armcca armv9 confidential-computing

Last synced: 20 Apr 2025

https://github.com/salrashid123/confidential_space

Constructing Trusted Execution Environment (TEE) with GCP Confidential Space

confidential-computing google-cloud-platform trusted-execution-environment

Last synced: 01 Mar 2026

https://github.com/flare-foundation/flare-ai-kit

🚧 SDK for building verifiable AI Agents on Flare using Confidential Space

ai confidential-computing flare-network sdk

Last synced: 18 Feb 2026

https://github.com/kinvolk/azure-cvm-tooling

Libraries and tools for Confidential Computing on Azure

attestation azure confidential-computing tpm2

Last synced: 10 Jan 2026

https://github.com/kriskwiatkowski/TEE-TLS-delegator

Solution to harden TLS security by storing private keys and delegating operations to the Trused Execution Environment

confidential-computing tee trusted-execution-environment trustzone

Last synced: 23 Apr 2025

https://github.com/inclavare-containers/tng

Trusted Network Gateway: A tool for establishing secure communication tunnels in confidential computing.

confidential-computing network tee

Last synced: 05 Feb 2026

https://github.com/enarx/steward

A Confidential Computing-Aware Certificate Authority

confidential-computing remote-attestation

Last synced: 14 Jun 2025

https://github.com/enarx/drawbridge

A Confidential Computing-Aware Workload Repository

confidential-computing enarx webassembly

Last synced: 12 Dec 2025

https://github.com/apache/teaclave-crates

A collection of ported and TEE-tailored Rust dependencies.

confidential-computing rust sgx tee trusted-execution-environment trustzone

Last synced: 13 Sep 2025

https://github.com/salrashid123/tpm_daemonset

Kubernetes Trusted Platform Module (TPM) DaemonSet

confidential-computing grpc kubernetes trusted-platform-module

Last synced: 12 Jul 2025

https://github.com/google/cc-device-plugin

A Kubernetes device plugin that exposes Confidential Computing devices to workloads in Google Kubernetes Engine (GKE) clusters.

confidential-computing device-plugin gcp gke golang google kubernetes remote-attestation

Last synced: 06 Mar 2026

https://github.com/edgelesssys/marblerun-tensorflow-demo

Privacy preserving machine learning demo using TensorFlow, running as an sgx-enclave with Gramine, orchestrated by MarbleRun

confidential-computing kubernetes marblerun sgx tensorflow

Last synced: 18 Jun 2025

https://github.com/stefano-garzarella/snp-svsm-vtpm

AMD SEV-SNP PoC with SVSM, KBS proxy, virtio-blk device, and stateful vTPM

confidential-computing edk2 linux qemu snp svsm vtpm

Last synced: 18 Jun 2025

https://github.com/cosmian/mpc_millionaires

CipherCompute: A more elaborated version of Yao's millionaire problem. Secret compute of KPIs

confidential-computing cryptography distributed-computing multiparty-computation

Last synced: 22 Mar 2025

https://github.com/aginies/virt-scenario

Prepare a Virtual Machine libvirt XML config and the host to match a specific scenario usage

alp confidential-computing host libvirt opensuse qemu scenarios secure-computation security sev sev-es suse virtual-machine virtualization xml xml-schema

Last synced: 09 Oct 2025

https://github.com/Maxul/zerocache

A cloud-oriented middlebox for network confidential computing

confidential-computing enclave middlebox

Last synced: 20 Apr 2025

https://github.com/anjuna-security/apm-secure-deployments

Scripts for secure deployments of the Anjuna Policy Manager

attestation confidential-computing deployment enclave terraform

Last synced: 13 Mar 2026

https://github.com/collapsinghierarchy/encproc-decryptor

encproc-decryptor is the client-side decryption utility designed to work in tandem with the encproc engine—your Encrypted Processing as a Service solution.

confidential-computing encrypted homomorphic-encryption processing

Last synced: 10 Aug 2025

https://github.com/giancarlolelli/enclave.net

This repository contains the code and roadmap for the Enclave.NET library, a managed wrapper around the Open Enclave SDK. This library allows app developers to build Intel SGX-aware applications using managed .NET code.

attestation cloud-native confidential-computing enclave intel-sgx open-enclave remote-attestation sovereign-cloud

Last synced: 06 Jan 2026

https://github.com/cosmian/mpc_join

CipherCompute: Blind Join for Confidential Data Science and Federated Learning using MPC

confidential-computing cryptography distributed-computing multiparty-computation

Last synced: 15 Apr 2025

https://github.com/stefano-garzarella/snp-svsm-efi-secret

AMD SEV-SNP PoC with SVSM, KBS proxy, and Linux's efi_secrets

confidential-computing kbs linux qemu

Last synced: 07 Aug 2025

https://github.com/lsds/cc-deathstarbench

Port of the DeathStar benchmark for microservices to a confidential computing setting.

confidential confidential-computing go microservices

Last synced: 02 Apr 2025

https://github.com/enarx/mmledger

A ledger for confidential computing (CC) shims for tracking memory management system calls

confidential-computing enarx shim

Last synced: 12 Mar 2026

https://github.com/mkulke/mkosi-playground

Building azure images with mkosi

azure confidential-computing mkosi secureboot

Last synced: 12 Feb 2026

https://github.com/thibauult/tee-mock-server

A mock server written in Go that generates signed JWT tokens for simulating Google Cloud Confidential Space authentication

attestation-service confidential-computing google-cloud google-cloud-platform mock-server tee trusted-execution-environment

Last synced: 13 Feb 2026

https://github.com/edgelesssys/osm-bookstore-demo

Deploy MarbleRun with OpenServiceMesh, demonstrated with OSM's bookstore demo

confidential-computing kubernetes service-mesh

Last synced: 18 Jun 2025

https://github.com/edgelesssys/edgelessdb-marblerun-demo

Demo application to showcase interaction of EdgelessDB and MarbleRun

confidential-computing database kubernetes mysql

Last synced: 05 Oct 2025

https://github.com/cc-api/confidential-cluster

Trusted Kubernetes Cluster for Confidential Computing

confidential-computing kubernetes tdx

Last synced: 21 Jan 2026

https://github.com/tufteddeer/openssh-tdx-remote-attestation

OpenSSH with support for Intel TDX remote attestation

confidential-computing intel-tdx ssh

Last synced: 04 Nov 2025

https://github.com/cyntrisec/ephemeralml

Confidential AI inference with cryptographic proof of ephemeral execution. Loads models inside TEEs, returns embeddings + signed Attested Execution Receipts.

aws confidential-computing encryption hpke machine-learning nitro-enclaves rust tee

Last synced: 18 Feb 2026

https://github.com/hollowman6/terraform

Terraform code to spin a AMD SEV-SNP Confidential Kubernetes cluster using AWS EC2 instances

confidential-computing kubernetes terraform

Last synced: 26 Jul 2025

https://github.com/salrashid123/cs_mesh

Service->Service mTLS using Envoy and Consul Service Discovery on GCP Confidential Space

confidential-computing google-cloud-platform hashicorp-consul tls trusted-execution-environment

Last synced: 16 Mar 2025

https://github.com/datosh/intro-to-cc

Demo for my Introduction to Confidential Computing (CC) talk

amd-sev-snp confidential-computing confidential-vm

Last synced: 07 May 2025

https://github.com/rjzak/cert-buddy

Parse the CSR from Enarx that goes to Steward https://github.com/enarx/enarx/

confidential-computing enarx

Last synced: 26 Mar 2025

https://github.com/salrashid123/gke_sandbox

GKE Sandbox for Confidential ML Inference

confidential-computing gke-cluster google-cloud machine-learning

Last synced: 16 Mar 2025

https://github.com/battle-crown/go-ten

Official Golang implementation of the TEN protocol

blockchain confidential-computing crypto encryption ethereum evm l2 layer2 tee web3

Last synced: 26 Jul 2025

https://github.com/cyntrisec/confidential-ml-transport

Attestation-bound encrypted tensor transport for confidential ML inference over VSock/TCP. Binary framing, X25519+ChaCha20Poly1305 AEAD, 3-message attested handshake.

aead attestation aws-nitro-enclaves chacha20poly1305 confidential-computing encryption hpke machine-learning rust secure-transport tee tensor vsock x25519

Last synced: 12 Feb 2026

https://github.com/tiver-10046/go-ten

Official Golang implementation of the TEN protocol

blockchain confidential-computing crypto encryption ethereum evm l2 layer2 tee web3

Last synced: 29 Jun 2025