Skip to main content

Security profiles

Keep never labels a cell with more evidence than it has. The profile is set on the FluxVM side (Phase 6 security_profile); Keep reads it and says so in the cockpit.

ProfileEvidenceHardware attestation?What you may claim
standardnonenoNothing — no evidence class is attached
measuredsoftware-testneverA software-test measurement; the host can still see the VM
confidential-snp / confidential-tdxsev-snp / tdx only after a verified hardware rungatedUnread-by-operator — not claimable until the launch flags flip

The attestation receipt​

The cockpit attestation object (console Keep view and /keep/cockpit) carries:

FieldMeaning
profileThe profile the cell launched with
image_hashSoft image hash (not a hardware measurement)
evidence_classnone, software-test, or — after a verified run — sev-snp / tdx
snp_launch_verified / tdx_launch_verifiedfalse until one real hardware launch flips FluxVM security.snp_launch_verified / tdx_launch_verified
host_recover_allowedWhether an operator recover path exists
operator_can_readWhether the operator can read the guest
honesty textPlain-language statement of the above

Rules the product enforces​

  • No host recover on confidential. POST /v1/sessions/{id}/host-recover is always 403 when the profile is confidential or a confidential launch is active.
  • Measured and standard need dual keys (ZYVOR_AGENT_RECOVER_KEY_A + _B) for a recover grant; the grant is audited and still labelled software-test.
  • User-held unwrap stays refuse-closed. POST /v1/vault/user-held/complete returns 403 until the verified flags are true.
  • Host guest-agent channel helpers refuse when a confidential launch is active.

Honesty​

Measured is software-test, not a TEE claim: the host can still see a measured VM. That is intentional. Until Keep 0.2 runs on real SNP/TDX hardware with a user-held key, Keep does not claim the operator cannot read the guest. Muse's Secure VM is described as having the same limit today; public detail on Muse is thin, so treat that as a characterization, not an audit.

See also Keep 0.2, confidential agent VMs, and FluxVM's security profiles.