Skip to content

Mero TEE

TEE infrastructure for Calimero. A node proves what code it is running with a hardware attestation; the KMS releases its storage key only when that attestation matches a signed release policy. This site is how it fits together — and how to operate it.

Understand

What Mero TEE is and why it is trustworthy: the system map, the trust model, each component, and the glossary. Start here →

How it works

The runtime flows: how a node attests, how the KMS releases a key, what a verifier checks, and how policies are managed. Follow a flow →

Operate

Run it: every config knob, the release pipeline, operational runbooks, and the error catalog. Operate a deployment →

Mero TEE is built on the Calimero TEE attestation model. For the protocol-level view of how a node’s attestation is admitted into a context, see the Calimero Core TEE reference.