Industry · Finance & insurance

Your supervisor now tests the architecture.Give them one you can prove

DORA turned resilience from a policy binder into a test: exit strategies get demonstrated, concentration gets challenged, third-party access gets audited. enclaive is the sealed infrastructure built to answer those questions with evidence — when configured with customer-controlled keys and attestation-based release policies, the operator has no readable path, custody stays with you, and the exit is addressed in architecture rather than only in an annex.

Compliance-first reader? The DORA page maps the platform article by article.

AUDIT EVIDENCE GENERATED IN OPERATION — EXAM PREP BECOMES AN EXPORT
EXIT STRATEGY ANSWERED ARCHITECTURALLY, NOT ONLY CONTRACTUALLY
BANK-GRADE KEY CUSTODY WITH PHYSICAL HSM COEXISTENCE
MANY WORKLOADS MOVE WITHOUT APPLICATION-LEVEL REFACTORING
Three pressures, arriving from three directions
Pressure 01
The supervisor
+
Pressure 02
The outsourcing reality
+
Pressure 03
The adversary
+

All three share one root: in conventional architecture, whoever operates the infrastructure can technically reach the data. Confidential computing removes that root rather than managing it — and hardware attestation turns every claim into something your auditor, your risk committee and your supervisor can check.

What financial institutions build on it

Start where the risk committee says no today — typically data platforms, analytics and customer-facing services — and expand as the evidence accumulates.

An exit strategy that exists in architecture
+
AI and Confidential AI on customer data — inside the guardrails
+
Key custody at bank grade
+
Fraud and financial-crime collaboration without pooling data
+
Privileged access, structurally reduced
+
Insurance: claims & underwriting analytics
+
Digital banks & fintechs: custody as market entry
+
BUILT FOR AN EXAMINER'S QUESTIONS
Who can access the data?

When configured with customer-controlled keys and attestation-based release policies: only the institution. Data stays encrypted in use and keys remain in your custody, so no cloud administrator, provider or platform operator (enclaive included) holds a readable path.

What ran against it?

Only attested workloads — verified builds of your own software. Everything else fails attestation and receives no key material.

Can you prove it?

Continuously — encryption posture, attestation logs and key events are generated as tamper-evident evidence in operation. Examination preparation becomes an export, not a project.

THE REGULATORY SURFACE, MAPPED

Which requirement,
which control

Each mapping is downloadable, built to be dropped into supervisory correspondence — and honest about what no product can do for you.

FAQ

What financial institutions ask

Q·01

Does this satisfy DORA's encryption requirements?

The technical standards under DORA expect encryption of data at rest, in transit — and, where relevant to the risk profile, in use. Confidential computing is how the third one becomes operational rather than aspirational. It supports DORA compliance; it does not replace governance, resilience testing, contractual arrangements or the register of information, all of which remain your obligations. The precise mapping, including what stays your responsibility, is on the DORA page.

Q·02

Do we have to re-architect core systems to use this?

It coexists with them. Where policy or certification requires a hardware root of trust, the vHSM bridges to certified physical HSMs — including via the Utimaco integration — while extending attested key custody to the cloud workloads your appliances were never built to follow.

+
Q·03

We have certified physical HSMs. Does this replace them?

It coexists with them. Where policy or certification requires a hardware root of trust, the vHSM bridges to certified physical HSMs — including via the Utimaco integration — while extending attested key custody to the cloud workloads your appliances were never built to follow.

+
Q·04

Can we actually run AI on customer data?

That's a data-protection and governance question as much as a technical one — what the platform changes is the technical premise: models and prompts run encrypted in use, and with customer-controlled keys and attestation-based release nothing readable reaches an external operator, while interactions land in tamper-evident audit and attestation logs. That's a foundation on which a DPIA can reach yes.

+
Q·05

How would we test the exit strategy claim?

By executing it — the honest test. Sealed workloads carry their protection model across providers, so a controlled exit exercise (redeploy a representative workload to a second provider, verify attestation, measure the effort) is a scoped project, not a thought experiment. Application dependencies and provider-specific managed services stay part of the exercise. Supervisors increasingly appreciate the difference.

+
Q·06

Doesn't adding enclaive add another ICT third party to our DORA register?

It depends on how we are contracted — directly with you, or as a subcontractor within an existing provider relationship — and each case is captured differently. Either way, the register of information remains the financial entity's legal obligation. What we do is make it straightforward to discharge: enclaive supplies the vendor documentation your register entry requires, and, configured with customer-controlled keys and attestation-based release, the entry describes a third party without a readable path to your data.

+
Q·07

Can we see it on our own workload before any commitment?

Yes — a technical evaluation under NDA on a representative workload is the standard entry, with your security architects and, if you wish, your auditors involved from the start. Bring the workload your risk committee last said no to.

+
Get started

Bring the project your risk committee blocked

The cloud migration, the AI initiative, the analytics platform — tell us where it stalled and which finding stalled it. We'll show you the sealed version, with the evidence your supervisor gets to check.

Regulation first?
DORA
. Custody first?
The vHSM
.

Certifications & security
Certified ISO/IEC 27001
IT Security made in Germany — TeleTrusT