
About URE
Data is not a fungible asset. When an operator holds your data inside their infrastructure, you did not buy a service. You acquired a business partner, one you never vetted and cannot fire without a migration project. Most of what the market sells as cloud security is the paperwork that makes that arrangement feel normal.
URE Sentinel is the platform for taking that ownership back: a trust plane you own instead of rent. Attestation, access, and audit evidence rooted in a cryptographic authority the customer controls, on any provider’s silicon or on your own metal, with the trust chain anchored in hardware you can verify rather than a console you can only read.
Verified infrastructure is now the floor
AI industrialized the attack chain. Compromise is generated at machine speed, and the noise is permanent, it accumulates and never recedes. The only operational standard that survives that world assumes every host and every network is already hostile. You stop defending a perimeter you no longer believe in, and you start verifying.
Think about how money moved online. Nobody would type a card number into an http:// page today, and that reflex is recent. One conversion, TLS everywhere, is what made money safe to move across the open Internet. Attested compute is the same conversion happening one layer down, and verified infrastructure is sliding from a wish-list line item to a condition of staying in business.
Running that posture across several clouds and your own metal is brutally complex, which is exactly why most teams never finish the job. URE abstracts the complexity without taking your keys. Think of being handed the key to your own car while someone else manages the footprint, across every kind of compute you run. The root of your authority stays offline, in a physical vault you hold, and everything the fleet does chains up to a key no provider ever holds.
Every regulator question has an evidence answer
Compliance comes down to a few questions about who controls what. URE answers each with evidence you can hold, emitted as a by-product of normal operation, not as a report assembled for the audit.
Who holds the keys
You do. Every identity and attestation traces back to a cryptographic authority the customer holds, on any provider's silicon or your own metal.
Who verified the platform
The hardware did. Trust is rooted in silicon attestation at every layer, not in a control document or a vendor's word.
Who accessed what, and when
The record shows it. Every privileged action lands in a tamper-resistant log bound to an attested identity, so access answers for itself.
SOC 2 Type II and FedRAMP sample this evidence continuously across the examination period, not on audit day.
In NIST SP 800-53 terms, the controls implemented directly rather than documented around: AC-3, AC-6, IA-2, IA-3, IA-9, AU-9, AU-10, SC-8, SR-4.
One trust plane, the whole compute stack
URE Sentinel ships one trust plane that runs from the out-of-band controller on a bare box all the way up to confidential GPUs, on a SPIFFE/SPIRE root you hold, beside the BMC, Kubernetes, and cloud accounts you already operate. Six substrates, one identity chain, one set of enforcement, one body of evidence, and a root of authority that never leaves your vault. One solution across the whole stack, not six products: four of the six substrates are live today, on AWS, GCP, and Azure and on your own metal, and two are next release.
Operate boxes that expose nothing inbound
Ground truth starts at the BMC, the out-of-band controller, with physical TPM 2.0 on hardware you own and nothing exposed inbound. Sealed-environment access reaches a persistent shell through a proxy with no SSH and no standing credentials, patent pending.
What this means: you can run machines that are invisible from the network and still prove exactly who touched them.
Physical TPM 2.0 · BMC out-of-band · proxy access, no SSH · SPIFFE assurance · per-session risk analysis · tamper-resistant access log
Your identity, even when the building is not
Physical servers in someone else's facility still carry hardware identity that belongs to you. TPM 2.0 with TPM DevID roots that identity in the silicon, not the site.
What this means: your servers can sit in someone else's building and still answer only to you.
TPM 2.0 · TPM DevID hardware identity
Rented GPU metal, identity you still own
Bare-metal-as-a-service instances from the neoclouds join the same chain as hardware in your own rack. Rented GPU bare metal carries the same hardware-rooted identity as metal you own, so whoever provisions the box never becomes whoever controls it.
What this means: when this ships, you can rent someone else's machines by the hour and they still belong to your chain of trust, not theirs.
Neocloud BMaaS · TPM 2.0 · TPM DevID · same hardware root as owned metal
The hardware tier on all three clouds
Cloud instances attest to the same hardware-rooted identity as your own metal, directly on AWS, GCP, and Azure. No cloud is a soft spot in the chain.
What this means: the same proof of identity holds whether you run on Amazon, Google, or Microsoft, with no weak cloud in the mix.
AWS NitroTPM (aws_iid) · GCP Shielded VM vTPM (gcp_iit) · Azure Trusted Launch vTPM bound to MAA (azure_msi)
Fleets that deny what they can't attest
Unattested pods do not get to talk. Projected token attestation scopes identity per namespace and service account, network policy provably denies the rest, with packet capture behind every denial in end-to-end validation on real clusters, under Cilium multi-region ClusterMesh and Calico on hardware-bound nodes. The projected token is software evidence until it anchors to an attested node, and we say so.
What this means: a workload that cannot prove what it is gets no network at all, and you have the recording that shows it was blocked.
SPIRE k8s_psat · per-namespace NetworkPolicy · packet-capture proof per denial · nodes via aws_iid · Cilium ClusterMesh, Calico via SPIFFE mTLS
End-to-end encrypted compute, GPU included
Confidential containers extend the same chain into the accelerator: a vTPM inside the enclave, NVIDIA MIG and TEE attestation, verified through NVIDIA Remote Attestation Service. End-to-end encrypted computing across the whole stack, the GPU included.
What this means: when this ships, even the work running on the GPU stays sealed and verified, so no one, not even the host, can see inside.
CoCo confidential containers · vTPM inside · NVIDIA MIG + TEE attestation · NVIDIA Remote Attestation Service (NRAS)
These three controls do not change as you move up the stack. The identity model, the operator rules, and the evidence are identical on bare metal and inside a confidential container.
Workload identity rooted in your authority
Every workload earns its identity in three graded tiers, from gated quarantine enrollment through rotating software identity to hardware-attested identity, all on a SPIFFE/SPIRE root you hold.
SPIFFE/SPIRE root you hold · SPA-gated quarantine · rotating SVIDs · TPM DevID · aws_iid · gcp_iit · azure_msi
Privileged access without standing keys
Operators prove who they are on every privileged action, not once at login. No standing SSH, no shared keys, a hardware step-up in front of anything that matters.
FIDO2/WebAuthn step-up · no standing SSH · no shared keys
Every action leaves proof, not a promise
Attestation, access, and privileged actions land in tamper-resistant records bound to an attested identity, rooted in an authority you hold, so your evidence never depends on a provider's word.
Customer-held authority · identity-bound records · tamper-resistant log
Not consulting. Not advising. Building.
Engineered and shipped, not declared. What follows is the record of the operator who built the trust plane above.
20+ years in security, from the data center floor to the silicon trust boundary.
Physics doesn’t negotiate. Neither does cryptography.
I am Stefano Schotten, founder of URE. CISSP, 20+ years in security, most of them spent accountable for other people’s most critical workloads.
The record, compressed: I built and ran a data center and managed-security operation that sustained 99.99% availability for multiple years in a row for healthcare, banking, and pharma workloads, the kind of targets organized and state-aligned actors probe continuously and red teams were paid to break. I designed a Tier III facility to ISO 27001, NIST CSF, SOC 2, TIA-942, GDPR, and LGPD, and the United States granted me an EB-2 National Interest Waiver on the strength of that record in cyber resilience. The company was acquired at the end of 2023. The operational war stories live in the articles; what matters here is what the work proved: safe environments are engineered, not declared, and evidence beats promises every time someone else is holding your workloads.
I started deploying TPMs, and arguing that they mattered, in 2017, when most of the industry treated the module as a disk-encryption accessory. That position has not changed; the market caught up to it. Today the same argument is the bedrock of confidential computing. A company’s intellectual property and market strategy now run on hardware it does not own. I work at the edge of that shift: provenance, attestation, evidence, and registered access for sovereign and GPU computing in environments that cannot afford to take anyone’s word for anything.
One conviction runs through all of it. You cannot fight wildfires day in and day out. Security has to live in the primitives, and the safe way has to be the easy way. We don’t cage the river, we shape the riverbed.
The current work is workload identity at the metal. Cryptographic identity born inside the TPM, attestation as the precondition for every privilege, and permeability gates at every seam from the PCIe connector to the Kubernetes fleet. Access is never a standing power. It is minted per session, scoped to a capability, recorded, and revocable.
Contact
- Email: s@ure.us
- LinkedIn: linkedin.com/in/schotten
- GitHub: github.com/sch0tten
- ORCID: 0009-0000-2131-5448