Runs inside a dedicated confidential compute enclave. No outbound egress required after setup. Every answer cited. Full audit trail.