Skip to content Skip to footer

Proof of Cloud gets Wings

Proof of Cloud was launched with a clear premise: confidential computing cannot scale on trust alone. The alliance, initiated by Secret Network and Phala Network, and joined by Nillion, iExec, and Aleph Cloud, set out to make the physical foundations of decentralised computing verifiable through a public registry of trusted hardware, backed by both cryptographic methods and real world inspection.

Luke Bowman, COO of Secret Network, has been a public voice of that ambition. “We’re here to ensure that users can verify, not just assume, that their encrypted workloads are running on secure, tamper proof machines,” he says.

Initially, the alliance framed the work as an open, vendor-neutral coalition with governance designed to resist capture: one member, one vote, and multi signature approval for registry updates. It also described the operational backbone: machine identity verification, auditable logs, and verification ceremonies that can include physical inspection or video with multi party confirmation.

Now, the initiative moves from a statement of intent into something more product shaped. The question is no longer whether the industry needs verifiable infrastructure. It is how Proof of Cloud becomes a mechanism that developers can use, and users can understand, without adding friction.

From registry to runtime verification

A TEE can present an identity and attest to code, but that is not enough if the machine itself could be tampered with. If you have an address of a server, there is no way to prove that the server is indeed in a data centre, and therefore no proof of its geographical location.

Proof of Cloud’s first answer was the ceremony: a human verified onboarding step where multiple parties can be convinced that a machine is located in a secure facility, and its identity can be added to the alliance database. That remains the core. What is changing is what happens after onboarding.

A trust server signs a machine’s identity so that others can verify it later. This matters because a registry is useful, but verification needs to happen in the flow of interaction. When somebody else wants to verify this computer is in the cloud, they need the trust server, because it can add a signature that the machine is known.

This creates an immediate design challenge: who runs that trust server. This presents a possible problem whereby someone could fake attestation.   

The next step, and the one that gives Proof of Cloud its wings, is decentralising the trust server itself. Alex Zaidelson, CEO of Secret Network Labs, describes an approach where the trust server runs across several companies, and validation requires signatures from more than one party. “A signature from multiple companies is required in order to actually prove that this thing is valid, and we are implementing an MPC scheme to allow this” he says, describing it as a decentralised trust server intended to make the system “more product worthy”.

Dimitris Mouris, Head of Cryptography at Nillion, points to the emphasis on simplicity as critical to adoption: “What I like about the tooling we are building is how little it asks of the user. A browser extension that tells you whether you are talking to a real TEE or not makes trust legible. You do not need to understand the internals. You just need to see whether your data is actually protected.” He adds that this simplicity is only possible because the work is being done collaboratively across leaders in the TEE ecosystem.

A user experience layer, not just infrastructure

The second shift is user experience. A browser extension can indicate whether a server you are talking to is running inside a TEE and whether it is valid.

That matters because Proof of Cloud is ultimately a trust signal. In the conversation, the language of verification is translated into something people already understand: a visible indication that the environment is what it claims to be. This can be described as a “blue check mark” for TEE infrastructure, meaning a user can see that “somebody made sure this machine is indeed legitimate”.

This is a subtle but important reframing. Proof of Cloud is not only a registry and a ceremony. It is moving towards being a reusable trust layer, with a mechanism for ongoing verification and a way to surface that verification to non specialists.

Francis Otshudi, CTO at iExec stresses the importance of observable runtime verification. “What matters is not just registering trusted TEE machines, but being able to verify their status at the moment of interaction. Proof of Cloud makes TEE verification simple to consume for both developers and end users, exposing runtime trust as a concrete signal rather than a complex process of obtaining and validating proofs, or an implicit assumption.”

A spokesperson for Aleph Cloud echoes the validation offered by Proof of Cloud: “At Aleph Cloud, where we operate decentralized confidential computing across independent node providers globally, Proof of Cloud solves what brand reputation cannot: cryptographic verification that TEE workloads run on legitimate, untampered hardware, essential for distributed infrastructure where trust must be proven, not assumed.”

Intel enters the story, and the market question becomes adoption

The third new ingredient is Intel’s own response in the form of its recent Platform Ownership Endordement (https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/platform-ownership-endorsements.html)

This initiative allows a cloud provider to install software and generate proof that computers are located inside their data centre. POE is, in a way, a new incarnation of the discontinued Intel Tiber product (https://www.intel.com/content/www/us/en/security/trust-authority.html) that was only deployed by a three Cloud Service Providers: Google Cloud, Microsoft Azure and IBM Cloud. With POE, smaller providers outside the elite club can now offer a proof of ownership.

On paper, this is the clean solution. If cloud providers can attest directly, the need for an external alliance diminishes for those providers. If a machine is on Azure, people do not need verification for the Proof of Cloud Alliance, because Microsoft can sign and say it is their machine.

Then comes the practical constraint. The only problem is that the offering of the big 3 providers that have proof of ownership today, is it too expensive? Also, their choice of bare metal hardware is quite limited, which inherently pushes builders towards tier two and tier three providers.

This is where Proof of Cloud’s positioning sharpens. It is designed to work without requiring cloud providers to do anything. “Proof of Cloud does not require the data centre to do anything,” says Zaidelson. “The verification is done by the alliance”

In other words, Intel’s solution is provider led, and Proof of Cloud is led by the ProofOfCloud community. Intel can solve the problem from inside the cloud. Proof of Cloud solves it from the outside, using a community based process when providers have not implemented a native approach.

The commercial reality is also laid bare. Proof of Cloud can be described as  altruistic in the sense that it does not make the alliance money, while also being essential because without it, anything the alliance is doing with TEEs cannot be trusted.

Cost is a reason why smaller providers may not rush to implement Intel’s approach. 

What the next iteration needs to solve

Another issue is how to maintain trust beyond a one time verification, with periodic checks being suggested. 

Overall, Proof of Cloud lives in the world of operational security rather than cryptographic perfection, which aligns with the alliance’s framing of the initiative as early stage, with standardisation and long term verification layers still being developed.

From here, the direction is clear. Bowman’s public narrative established the need for verifiable hardware as a foundation for trusted confidential computing. The next layer, including decentralised verification services, user facing signals, and a pragmatic story about adoption in an industry, is where the technically correct solution can still lose if it demands too much change from cloud providers.

Proof of Cloud has not changed its purpose. It has started to look like a product. That is what gives it wings.