Product · Decent Edge
DE:SH · Secured Hypervisor
A hypervisor that audits itself.
DE:SH is a KVM hypervisor that verifies every component from boot to runtime — hardware-rooted, signed, and measurable from the outside. The host is no longer a thing you trust on faith.
- Posture
- Hardware-rooted
- Part of
- Decent Edge product family
What it includes
- Hardware-rooted boot and runtime integrity
- Cryptographic verification of kernel, hypervisor, and guest manifests
- Templates for Kubernetes, containers, and VMs
- Pairs with DE:FENDER for continuous integrity monitoring
Pairs with
How it compares
Confidential compute and hardened virtualization
- AMD SEV-SNP / Intel TDX
- Vendor-specific confidential VMs. Hardware feature sets, not products.
- Anjuna, Fortanix CCM
- Enterprise confidential-compute platforms with strong policy tooling.
- Edgeless Constellation
- Confidential Kubernetes, focused on cluster-level attestation.
Where we focus
Those products excel at confidential-compute enclaves for sensitive workloads. DE:SH is the simpler general-purpose host underneath — a hypervisor you can audit from the outside, designed to host the rest of the Decent Edge family without needing an enclave deployment first.