Skip to main content

Secure Enclave

Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave.

What is Secure Enclave?

Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave. Define which meaning applies. An enclave protects selected code and data against a stated threat model. It does not remain safe against every operating-system, firmware, physical, or side-channel compromise. For the general standard term, see Trusted Execution Environment.

Why it matters

An enclave can keep selected keys and operations separate from a general-purpose operating system. This separation can reduce exposure when other software on the device fails or is compromised.

How it works

  1. The platform places selected code, keys, or data inside an isolated execution boundary.
  2. Normal software calls a limited interface while protected operations stay inside that boundary.
  3. Where the platform supports it, sealed storage or attestation ties data or evidence to a specific protected environment.

Example

A platform authenticator creates a WebAuthn private key in hardware-backed storage and signs challenges without exposing the private key to the browser.

Pomerium boundary

Pomerium WebAuthn device identity can use a platform authenticator that is backed by secure hardware such as a Secure Enclave or TPM. Pomerium validates the WebAuthn credential result. It does not attest arbitrary code that runs in an enclave.

Limits and non-claims

  • The term secure enclave is ambiguous, so the product and threat model must be named.
  • Protection applies only to code and data that stay inside the defined boundary.
  • Firmware defects, physical attacks, side channels, and unsafe trusted code can remain relevant.

Evaluation checklist

  • Which code, keys, or data stay inside the enclave, and which host components remain trusted?
  • How does a verifier validate measurement, version, freshness, and attestation authority?
  • Which input, output, rollback, side-channel, or host-control risk remains outside the enclave?

Sources and further reading

Keep learning

Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term
Identity and AuthenticationStandards and Protocols

WebAuthn

WebAuthn is a W3C API for creating and using public-key credentials scoped to a relying party.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo