submit a source tarball; an ephemeral intel tdx vm shadow-builds it inside the tee and returns a signed eat receipt binding the build output to a hardware quote. the build host is not trusted — only the cpu vendor root is.
$ curl -F src=@app.tar.gz https://<service>/v1/attest { "verdict": "verified", "eat": "…", "mrtd": "…" }
dde6f4c1ce11a0a21bb02384e1440189232984eb5b7659d877725ded0c204b87$ ./scripts/verify-source-to-silicon.sh # [1/4] azure sev-snp → amd root · value_x_bound true # [3/4] gh attestation verify · maceip/attestation-service (self-hosted, in-tee) # PASS: source → silicon — github provenance D == hardware value_x