engine · web uistatic preview

The engine, in your browser.

The engine ships with a local web UI: submit an attestation quote, verify a bundle, browse the attack database. What you see below is that interface, as a static preview. No compute happens on this page. The forms become real when you run the engine on your machine.

runs locally real verdict shown Apache-2.0
static preview engine web UI · submit

Submit an attestation quote

Run evaluation

Result

Confidior 6 attacks F · 33/100
33/100 grade F L2
  • platformIntel TDX
  • measurementmatch
  • attacks6 unmitigated
  • freshnessFRESH
  • debugOFF
  • provenanceabsent

The badge above is a real verdict: RedPill's production TDX gateway, verified by the engine and anchored to Rekor (bundle-20260814131745). Run the engine on the same quote and the web UI renders this badge.

static preview engine web UI · verify-badge

Verify a badge

bundle-20260814131745.bundle badge SVG + signature + bundle
Verify

Verdict

  • signature valid
  • bundle intact
  • grade F · 33/100

The badge checks out as genuine output of the engine. It is still an honest F. Verifying authenticity and trusting the result are different steps.

static preview engine web UI · measure · archaeology

Runtime measurement

Run measurement
measure ✓ match passed

Attack archaeology

AttackCostCategoryMitigation
BadRAM<$10rogue memory modulefirmware patch
Battering RAM<$50memory bus interpositionhardware redesign
TEE.fail~$1,000memory bus interpositionhardware redesign
RMPocalypsen/aarchitecturalmicrocode update
VMScapen/aarchitecturalsoftware fix

Run it yourself.

The screens above are previews. The engine is real, local, and open source. Clone it, run the web UI, and submit your own quote.

No compute happens on this page. The verdict shown is real: RedPill's production TDX gateway, verified by the engine and anchored to Rekor (bundle-20260814131745).