Protect data while it is being processed through isolated execution environments and memory encryption. Evaluate secure boot, attestation, trusted execution environments, secure enclaves, and the limits of confidential computing.