Privacy

CRE has two features designed to keep part of a workflow confidential from Workflow DON node operators during execution. Both run inside a secure enclave, a running instance of a Trusted Execution Environment (TEE), and fetch secrets from the Vault DON instead of the regular Workflow DON runtime.

Privacy features

  • Confidential Workflows (private beta): Runs a handler's full callback logic inside a TEE, for workflows where more than a single request is intended to remain confidential: risk thresholds, proprietary scoring, multi-step reasoning over sensitive inputs.
  • Confidential HTTP: Executes a single outbound HTTP request inside a TEE, with secrets injected via templates and an optional encrypted response.

Guides

Learn more

Get the latest Chainlink content straight to your inbox.