Frame Attestation

The live trust posture of this Frame instance: the measured enclave it runs in, the image measurement (PCR0) a bank pins, and the identity that gates operational-seed release. Read live from this service — nothing here is fabricated; the measurement shown is the one the enclave itself attested.

Measured identity

Status
—

What this proves

The policy engine runs inside a measured Trusted Execution Environment. A bank does not trust Frame's operators — it pins two values out of band and checks everything against them: the enclave measurement (PCR0) and the trust root (K_root).

  1. Attestation-gated seed release (INV5). The operational seed is wrapped so AWS KMS releases it only to an enclave whose attestation carries this exact PCR0. The untrusted parent host — which holds the AWS credentials — cannot decrypt it: KMS denies kms:Decrypt without a matching attestation.
  2. The measurement is reproducible. Rebuild the enclave image from source and you get the same PCR0 shown here — so anyone can confirm what code the measurement stands for.
  3. Verify a settlement yourself. Every settlement produces a verify-pack you can recompute in your own browser or with the offline CLI — open the verifier →