OutLayer — TEE Attestation

Verifiable off-chain compute for NEAR · outlayer.ai ↗

Full per-aspect verification for app 84e03b0a12ca6eb843a18f8033046346a4390ec9.

One running instance of this app on a self-hosted Intel TDX host. Every TDX quote is Intel-DCAP-verified (signature + TCB, via Intel's PCS) and cross-checked against the on-chain approved measurements — independently re-verifiable.
testnet-worker-0142-3 Worker testnet stopped · up 30days 9h 14m 4s
last push 4m ago app_id 84e03b0a12ca6eb843a18f8033046346a4390ec9 vm_id ae328116-683f-4e5f-a210-62fa77675add attested via Intel DCAP (Intel PCS collateral) gateway 84e03b0a12ca6eb843a18f8033046346a4390ec9-8081.dstack.outlayer.ai
collection error: vm status is 'stopped'
2

TDX Hardware — Attestation

The hardware-signed TDX quote, verified against Intel's PCS collateral — the Intel DCAP signature chain, not Intel Trust Authority.

Signature ✗ TCB unknown Measurements — On-chain — n/a
verification error: no app_cert_pem in report (guest-agent unreachable?)

Quote not decoded yet — showing the measurements as reported (to be cryptographically verified).

3

Source Code — Compose

The measured app-compose that pins exactly which container images run.

compose not reported yet (agent predates app-compose forwarding)

4

Network — Zero Trust Gateway

TLS terminates inside the TEE — the gateway never sees plaintext.

guarded domain84e03b0a12ca6eb843a18f8033046346a4390ec9-8081.dstack.outlayer.ai
5

App OS

The measured dstack guest OS image. The version is read live from each CVM's vm_config; the os_image_hash is the precise, measured OS identity. dstack releases ↗.

6

KMS — deploy-time key provisioning

Deploy-time only. Governed by an on-chain contract, the dstack KMS releases this CVM's keys at boot only if its measurements are approved — those keys decrypt the deployment env file (so secrets never enter the measured compose) and provision the CVM's RA-TLS identity + disk encryption. This secures how the worker is deployed; it does not hold OutLayer's application or user secrets — those run through the OutLayer keystore (master derived in-TEE via MPC), not the dstack KMS.

key_provider unknown