Attestation
Every claim on this page is one you can check yourself. That is the only kind worth making about somebody else's code.
What is true today
Borehole reads no private repository on any machine it runs, confidential or otherwise. A private repository is surveyed by the collector on your own systems, and the repository stays there. What crosses instead.
A confidential VM in our own cloud project would stop us looking at
your code, and your code would still be on our infrastructure. So we
retired the one we built, and no environment publishes an image that
reads repositories.
/.well-known/borehole-workload
says the same in JSON.
Every report still carries a record of where its own scan ran, written by the scan as it ran. A public scan says it ran on ordinary infrastructure and was not attested. A collected survey says it came from the collector. A scan that did run in Confidential Space carries the token Google signed, and the steps below check it.
How to check a report
Fetch /r/<owner>/<repo>/<commit>/attestation.json.
It carries the raw token, the digest we published when the scan ran, and
these steps as data. Not our summary of the signed statement — the
signed statement.
- Take `execution.token`. It is a JWT signed by Google, not by us.
- Verify the signature against Google's confidential computing keys, at https://confidentialcomputing.googleapis.com/.well-known/openid-configuration
- Check `swname` is CONFIDENTIAL_SPACE and that the support attributes contain STABLE. STABLE is what rules out the debug image, which permits a shell and would make the rest of this meaningless.
- Check `submods.container.image_digest` equals `execution.published_digest`: the image we published, when the scan ran, as the one allowed to run it.
- Check `eat_nonce` equals the SHA-256 of the report, serialised as JSON with sorted keys and no whitespace — the same bytes served at <report url>.json. This is what ties the token to your report rather than to some other run of the same image.
The last step is the one people skip and the one that matters. A token proves an image ran. Only the nonce proves it ran your scan — without it, a single token could be waved at every report we ever issue.
What this does not prove
It does not prove what is inside the image. You can verify that Google signed a statement naming digest X, and that X is the digest we publish. You cannot pull X and read it, because the image is not public. What the guarantee gives you is that whatever X does, it did it on hardware nobody could observe, and that X is the same thing for you as for everyone else.
A stale token proves a past moment, not a present one. Tokens expire in about an hour. A verifier checking one months later is checking a signature over a statement made then, which is the correct thing to check and not the same as a live proof.
The published digest is a record, not a live claim. It is the one we published when the scan ran, stored on the report at that moment. Nothing is published now, and that does not reach back and change what an old token proves.
See also what happens to your code and the Privacy Policy.