Muse’s Secure VM is described as having the same limit today (public detail is thin). Keep states its limit here, in the product. Security profiles ›
Proof on stage
Don’t trust the story. Read the counter.
The PDF-brief demo runs an agent through a vendor SOW behind a host-side eBPF pin — deny_udp plus gateway-only ports. It expects egress_connects: 0, read from Keep’s journal and FluxVM’s drop_reasons.
Until Keep 0.2 runs on real SNP/TDX with a user-held key, evidence stays software-test — never “the operator cannot read this.” Muse’s Secure VM has the same limit today.
FluxVM’s multi-tenant controls are opt-in and are not a public-cloud boundary.
Muse details here are as publicly described; public detail is thin. Corrections welcome.