What is Secure Enclave?
Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave. Define which meaning applies. An enclave protects selected code and data against a stated threat model. It does not remain safe against every operating-system, firmware, physical, or side-channel compromise. For the general standard term, see Trusted Execution Environment.
Why it matters
An enclave can keep selected keys and operations separate from a general-purpose operating system. This separation can reduce exposure when other software on the device fails or is compromised.
How it works
- The platform places selected code, keys, or data inside an isolated execution boundary.
- Normal software calls a limited interface while protected operations stay inside that boundary.
- Where the platform supports it, sealed storage or attestation ties data or evidence to a specific protected environment.
Example
A platform authenticator creates a WebAuthn private key in hardware-backed storage and signs challenges without exposing the private key to the browser.
Pomerium boundary
Pomerium WebAuthn device identity can use a platform authenticator that is backed by secure hardware such as a Secure Enclave or TPM. Pomerium validates the WebAuthn credential result. It does not attest arbitrary code that runs in an enclave.
Limits and non-claims
- The term secure enclave is ambiguous, so the product and threat model must be named.
- Protection applies only to code and data that stay inside the defined boundary.
- Firmware defects, physical attacks, side channels, and unsafe trusted code can remain relevant.
Evaluation checklist
- Which code, keys, or data stay inside the enclave, and which host components remain trusted?
- How does a verifier validate measurement, version, freshness, and attestation authority?
- Which input, output, rollback, side-channel, or host-control risk remains outside the enclave?
