Your supervisor now tests the architecture.Give them one you can prove
DORA turned resilience from a policy binder into a test: exit strategies get demonstrated, concentration gets challenged, third-party access gets audited. enclaive is the sealed infrastructure built to answer those questions with evidence — when configured with customer-controlled keys and attestation-based release policies, the operator has no readable path, custody stays with you, and the exit is addressed in architecture rather than only in an annex.
Compliance-first reader? The DORA page maps the platform article by article.

All three share one root: in conventional architecture, whoever operates the infrastructure can technically reach the data. Confidential computing removes that root rather than managing it — and hardware attestation turns every claim into something your auditor, your risk committee and your supervisor can check.
Start where the risk committee says no today — typically data platforms, analytics and customer-facing services — and expand as the evidence accumulates.
When configured with customer-controlled keys and attestation-based release policies: only the institution. Data stays encrypted in use and keys remain in your custody, so no cloud administrator, provider or platform operator (enclaive included) holds a readable path.
Only attested workloads — verified builds of your own software. Everything else fails attestation and receives no key material.
Continuously — encryption posture, attestation logs and key events are generated as tamper-evident evidence in operation. Examination preparation becomes an export, not a project.
Which requirement, which control
ICT risk, the third-party register, exit strategies and the RTS encryption expectations — article by article.
Data-in-use encryption as the state-of-the-art technical measure, with the DPIA argument prepared.
Outsourcing and IT requirements addressed through the same control set.
NIST-standardized algorithms and crypto-agility, ahead of supervisory timelines.
Each mapping is downloadable, built to be dropped into supervisory correspondence — and honest about what no product can do for you.
What financial institutions ask
Does this satisfy DORA's encryption requirements?
The technical standards under DORA expect encryption of data at rest, in transit — and, where relevant to the risk profile, in use. Confidential computing is how the third one becomes operational rather than aspirational. It supports DORA compliance; it does not replace governance, resilience testing, contractual arrangements or the register of information, all of which remain your obligations. The precise mapping, including what stays your responsibility, is on the DORA page.
Do we have to re-architect core systems to use this?
It coexists with them. Where policy or certification requires a hardware root of trust, the vHSM bridges to certified physical HSMs — including via the Utimaco integration — while extending attested key custody to the cloud workloads your appliances were never built to follow.
We have certified physical HSMs. Does this replace them?
It coexists with them. Where policy or certification requires a hardware root of trust, the vHSM bridges to certified physical HSMs — including via the Utimaco integration — while extending attested key custody to the cloud workloads your appliances were never built to follow.
Can we actually run AI on customer data?
That's a data-protection and governance question as much as a technical one — what the platform changes is the technical premise: models and prompts run encrypted in use, and with customer-controlled keys and attestation-based release nothing readable reaches an external operator, while interactions land in tamper-evident audit and attestation logs. That's a foundation on which a DPIA can reach yes.
How would we test the exit strategy claim?
By executing it — the honest test. Sealed workloads carry their protection model across providers, so a controlled exit exercise (redeploy a representative workload to a second provider, verify attestation, measure the effort) is a scoped project, not a thought experiment. Application dependencies and provider-specific managed services stay part of the exercise. Supervisors increasingly appreciate the difference.
Doesn't adding enclaive add another ICT third party to our DORA register?
It depends on how we are contracted — directly with you, or as a subcontractor within an existing provider relationship — and each case is captured differently. Either way, the register of information remains the financial entity's legal obligation. What we do is make it straightforward to discharge: enclaive supplies the vendor documentation your register entry requires, and, configured with customer-controlled keys and attestation-based release, the entry describes a third party without a readable path to your data.
Can we see it on our own workload before any commitment?
Yes — a technical evaluation under NDA on a representative workload is the standard entry, with your security architects and, if you wish, your auditors involved from the start. Bring the workload your risk committee last said no to.
Bring the project your risk committee blocked
The cloud migration, the AI initiative, the analytics platform — tell us where it stalled and which finding stalled it. We'll show you the sealed version, with the evidence your supervisor gets to check.
.png)
