Run confidential compute in a TEE
Use a TEE's attestation as evidence: verify a provider's Intel TDX, AMD SEV-SNP, AWS Nitro or NVIDIA confidential GPU quote, then send it confidential work.
A trusted execution environment (TEE) runs code in memory the host cannot read. On Tenzro Network 1 a TEE is evidence, not custody: its attestation is a hardware-signed statement of what code is running and on which platform, and the network verifies that statement in full against the vendor's certificate chain before anyone relies on it. Keys are still rooted in a TPM, Secure Enclave or passkey; the TEE proves where the work ran.
Supported platforms are Intel TDX, AMD SEV-SNP, AWS Nitro Enclaves and NVIDIA confidential-computing GPUs.
This tutorial covers both sides: a provider that offers attested compute, and a caller that verifies a provider before sending it sensitive work.
Prerequisites
- Provider: a node running on TEE-capable hardware (a TDX or SEV-SNP confidential VM, a Nitro Enclave host, or a confidential-computing GPU), with a hardware-rooted identity and a posted bond.
- Caller: the
tenzroCLI, ortenzro-sdkfor TypeScript, and a funded account.
Part 1: offer attested compute
1. Detect the TEE
tenzro tee detectExpected output names the platform the node found, for example intel-tdx, and its capabilities. If nothing is detected, the machine is not running inside a confidential environment and cannot serve the TEE role.
2. Start the node with the TEE role
tenzro-node --roles ai,tee --data-dir ./data
tenzro provider register --type tee --did <your-did>The node enrolls its attestation with the network. Callers and routers can then filter for your node when they require TEE execution.
3. Produce and check your own quote
tenzro tee attest --provider auto --format json > quote.json
tenzro tee verify --provider tdx --quote <quote-hex>verify checks the quote's signature, its certificate chain up to the vendor's root and its measurements. A quote that fails any check is rejected; there is no fallback that accepts unverified evidence. Use sev-snp, nitro or gpu for the other platforms.
Part 2: send confidential work
4. Find TEE providers
tenzro tee providers --rpc https://rpc.tenzro.xyzOr from TypeScript:
import { TenzroClient } from "tenzro-sdk";
const tz = TenzroClient.mainnet();
const { providers } = await tz.tee.listTeeProviders();5. Verify the provider before you trust it
Ask the provider's node for a fresh quote and verify it yourself:
tenzro tee attest --provider auto --rpc https://PROVIDER_RPC --format json
tenzro tee verify --provider tdx --quote <quote-hex>const result = await tz.tee.verifyAttestation(quoteHex, "intel-tdx");
if (!result.valid) throw new Error(result.message ?? "attestation rejected");Compare the measurement in the quote with the one you expect for the software you want to run. A valid quote for the wrong code is still the wrong code.
6. Run inference that requires a TEE
Ask the router to place a request only with providers whose attestation verifies:
tenzro inference request qwen3-8b "Summarise this contract clause." \
--require-tee \
--rpc https://rpc.tenzro.xyzThe provider runs the request inside the enclave and signs the result with a key bound to its attestation, so the answer can be tied to the verified environment that produced it. Inputs and outputs can be encrypted to the enclave's public key, so the host operating system never sees them in cleartext.
7. Pay for attested results
Settlement for confidential work is metered per use, like any other inference. A result whose attestation does not verify is not accepted, and a provider that returns one fails the request and loses reputation.
Next steps
- TEE for per-vendor verification in detail.
- Trust and provenance to combine attestation with certifications.
- Run a trainer node to take Confidential-tier training runs.