Reduce your trusted computing base to a minimum

Your trusted computing base (TCB) is everything that has to behave correctly for your data to stay safe: every piece of hardware and software, and every vendor and person, that could read your data or change what your systems do. If any one of them fails, gets breached, gets subpoenaed or goes rogue, you're exposed.

Security is mostly subtraction. Every party you remove from the TCB is a breach, an insider or a legal demand that can no longer reach you. Yaya Tech's job is to make that list as short as physics allows, and to prove what's left.

What a typical AI-enabled company trusts today

Party in your TCBWhat it can doHow we remove or contain it
LLM API provider (and its subprocessors)Read every prompt, document and output, and retain them under its own policyOpen-weight models on your hardware, or models running inside attested enclaves
Cloud operator (staff, control plane)Read VM memory and disks, and snapshot running workloadsConfidential VMs (AMD SEV-SNP, Intel TDX): memory is encrypted with keys the operator never sees
Hypervisor and host OSInspect or tamper with guestsSame: hardware isolation removes them from the trust path
SaaS vendors holding your dataLeak it in their breach and expose it to their adminsReplace the risky ones with small software you own and run
Your CI/CD and build pipelineShip a backdoored binary nobody wroteReproducible builds and signed provenance: the running measurement must match source you can audit
Your admins and oursRead data and change productionNo standing access; secrets released only to attested code; every action in an immutable log
Logging and observability vendorsSee sensitive payloads, and alter or lose historyZero-retention logging of content, plus tamper-evident logs you verify yourself
Third-party dependenciesRun arbitrary code inside your appPinned, reviewed, minimal dependencies, and an SBOM checked in CI
Us (Yaya Tech)Anything you give us access toYou keep the keys, our access is scoped and logged, and the exit plan is built in

What remains, and we'll say so

No system has an empty TCB. After a Yaya Tech deployment, what you still trust is typically:

  1. The silicon root of trust: the CPU and GPU vendors (AMD, Intel, NVIDIA), their firmware and their attestation keys
  2. Your own code, now small, audited and reproducibly built
  3. Your key holders, the people and HSMs that control your root keys

We also document what confidential computing does not protect against, so nobody finds out the hard way:

  • Physical attacks on the host by someone with lab equipment and hands on the machine
  • Side channels. They're mitigated by keeping firmware up to date and by the attestation policy, but they aren't impossible.
  • Availability. A cloud can always switch you off, even if it can't read you. That's why we plan multi-site and on-prem fallbacks.
  • GPU relay. Current GPU attestation is checked at boot and isn't bound to the connection between CPU and GPU, so we prefer designs that minimize it or verify it in more than one way.
  • Metadata: traffic timing, request sizes and which endpoints you talk to

How we measure progress

Every audit starts with a TCB map: a list of every party with the power to read or change your data, and what each one would take to remove. Every build and managed deployment reports the TCB before and after. That number goes down, and you can check each line.

Talk to a security expert, free. 30 minutes, no slides. Bring the thing that worries you most.
Book a call

© 2026 Yaya Tech PBC · Palo Alto, California · serving clients worldwide · andre@yaya.tech · Privacy · Terms