/learn
The educational hub
The what, why, who, and how of agent execution boundaries and confidential computing. We publish a silicon-verified confidential agent execution path and a public threat model — the depth most teams keep internal.
/learn/rung-1
Category-defining explainers
Start here — what agent execution boundaries and confidential computing actually are. A platform engineer searching for agent execution boundary concepts or microVM vs. container comparisons should land here.
What is an agent execution boundary?
The plain-language explainer of what confidential agent execution is and why it matters. The “control point moved” thesis from first principles.
Read →
MicroVMs vs. containers vs. gVisor for AI agents
The honest isolation comparison. Why a separate kernel matters for untrusted agent code. The CVE history.
Read →
What is confidential computing? (for platform engineers)
SEV-SNP/TDX explained for the engineer who’s heard the term but never deployed it. The two-layer attestation binding. Why nesting is impossible.
Read →
What is hardware attestation?
The concept: a CPU-signed report that proves the execution environment was untampered. VCEK→ARK chains, TPM Quotes, why they matter for key release.
Read →
/learn/rung-2
The differentiation
Go deeper — how the architecture works and what the security model guarantees. These articles take a reader who understands the category to one who understands why this product.
Why agents change the enterprise security boundary
The control-point thesis. Where SWGs/CASBs go blind. Why the execution boundary is the new control point.
Read →
Why your CISO blocks managed agent sandboxes
Data residency, DPAs, attestation gaps, subpoena exposure. The regulated-enterprise buying friction — named.
NeuronEdge Enclave vs. E2B / Daytona / Modal / containers
The honest feature-level breakdown + where each wins.
Read →
Self-hosted vs. managed: the agent infrastructure decision
When self-host is right (regulated, sovereign, on-prem) vs. when managed is right (startup, non-sensitive).
/learn/rung-3
Proof and adoption
Get hands-on — the quickstart, the threat model, and the silicon bring-up report.
Run a confidential agent workload on Azure DCasv5
A documented silicon bring-up runbook for confidential agent execution, start to finish.
The threat model, explained
The trust boundaries, the honest claim ceiling, what’s proven vs. what’s not.
Read →
The 5-minute self-host quickstart
Install → create → exec → snapshot → fork. Python + TypeScript SDKs.
Read →
Benchmarks methodology
Measurement points, percentiles, what we measure + what we don’t gate on.
The audit chain, explained for a security reviewer
How the signed Merkle chain works, how nee audit verify detects tampering, the honest WORM caveat.
Start with the quickstart. Read the threat model.
Each section builds on the last. Start with the quickstart, then read the threat model for the full claim ceiling.