A confidential virtual machine is one whose memory is encrypted with a key managed by the processor's own security hardware, so the host's software can't read it.
Sealed runs on NexQloud Sealed, on AMD SEV-SNP hardware.
What a Sealed run does:
- Releases keys only to measured code. Your documents can be decrypted only inside a machine whose code matches a published measurement.
- Shuts the doors. No SSH, console or debug access, and outbound traffic blocked except to you and your broker.
- Escalates to you. Anything the agent can't settle goes to you or your broker, never to our staff.
- Erases. The working copy is cryptographically erased at the end of the run.
- Signs. Each run ends in a receipt anyone can check against AMD's keys.
What still leaves: the claim package and CSV go to your broker, and claim totals go to billing.
Standard costs 2 points less. Read the honest limits before you rely on it.
- AMD, SEV developer page[1]
- NexQloud Drawback pricing[2]
- What are confidential VMs?
- What is confidential computing for customs data?
Written by the NexQloud Drawback team from the primary sources linked on this page.
Not legal advice. NexQloud Drawback is not a government agency.
NexQloud Drawback is software used by licensed customs brokers.
