Capability 04

Hardware Security
Enclaves

Your most sensitive identity details live in a hardware vault, separated from the phone's main software. Even a full phone compromise can't reach them.

In Plain Words

A vault inside your phone

Your phone has a sealed compartment built into its chip — physically separate from the rest of the phone. Even the phone's own operating system can't look inside it. dZTA stores your most important secrets there.

Why software alone isn't enough

If your secrets are just files in the phone's operating system, then whoever controls that software controls your secrets. One malicious app or one vulnerability could read everything. Software locks can be picked by software.

What lives in the vault

The private keys that prove who you are, the credentials in your identity wallet, and the logic that checks access rules. They stay locked away, doing their job from behind the sealed door.

What you get

A hardware guarantee that's stronger than any password or policy: even if your phone's software is fully compromised, the vault holds. Your identity can't be copied out, and it can't be forged.

How It Works

The sealed room

Three properties make the vault trustworthy.

01

Physically separate

The vault is built into the phone's chip as its own isolated space. Software running on the phone simply can't reach it — it's not a rule, it's the hardware design.

02

Sealed, always

Once sealed, the vault proves to the rest of the system exactly what it's running and that nothing has been tampered with. You can verify the vault is genuine before trusting it.

03

Keys never leave

Private keys are generated and used inside the vault. They're never loaded into the phone's memory or sent over the network — so there's nothing to steal.

The strongest lock is made of hardware.

See how the vault anchors identity and enforcement in the full system, or talk to us about your deployment.