Comparison · RedactSure Research
Secure VM, Confidential VM, or Render Layer: Which One Decides What the AI Sees?
Only the render layer. A secure VM decides where the agent runs and what may leave it. A confidential VM decides who besides the agent can see what is inside. The render layer is the only one of the three that decides what the agent itself receives, because it is the only one that operates on the page before the model reads it. The three are not rivals; they answer three different questions, and an enterprise agent program needs all three answered. Least Exposure is the principle behind the third: for each piece of work, the agent receives exactly the data the task requires and nothing more, enforced before any model reads the screen. This page maps the three designs, the trust architectures the largest AI providers built on the first two, and the question each leaves for the next. The environment that enforces this is built by RedactSure, an AI agent controls, governance and data protection company.
Key findings
- Three questions, three layers. Where does the agent run and what leaves: the secure VM. Who besides the agent can see the data: the confidential VM. What does the agent see: the render layer. Each answers its own question fully and the others not at all.
- The 2026 consumer trust architectures are built on the first two questions. Apple’s Private Cloud Compute answers the provider question with statelessness and published software images; Meta’s Muse answers it with a per-user Secure VM today and user-held keys in the Confidential VM to come. In both, the model reads the user’s data in full.
- The six-layer stack in The Two Gaps AI Agents Opened in Your Security Stack places enclaves at layer 01 and the render at layer 05. Everything between governs where data may go. Only the render governs what the AI can see.
- A vault inside a secure VM protects what the user deposits, credentials and payment cards. It has no entry for the records already on the screen when the agent arrives.
- RedactSure runs on all three: a governed environment, on hardware-encrypted enclaves with customer-held keys, with render-layer tokenization inside it. The first two are the floor. The third is the difference.
The three designs side by side
| Secure VM | Confidential VM | Render layer | |
|---|---|---|---|
| The question it answers | Where does the agent run, and what may leave? | Who besides the agent can see the data? | What does the agent see? |
| Mechanism | Dedicated machine per user or tenant; credentials held outside the agent; a gate on every egress; a person who can watch and take over | Hardware enclave (AMD SEV-SNP, Intel TDX, AWS Nitro); memory encrypted with keys the operator does not hold; attested code | The page is read as fields, not a picture; identifiers replaced with consistent tokens before any model reads it; real values resolve only at approved destinations |
| Who it protects against | Other tenants, the open internet, a hijacked agent acting freely | The cloud provider, its staff, a compromised host, a subpoena on the operator | The model itself, and anyone who gets what the model held |
| What the model receives | Everything the browser shows | Everything the browser shows | The fields the task needs, with identifiers as tokens |
| What a successful injection collects | The context, identifiers included; credentials excepted | The context, identifiers included; credentials excepted, and nobody at the provider watching | Tokens, from a narrower surface; the consequential action stops for a named person |
| Layer in the six-layer stack | 01 to 02 (hardware, control) | 01 (hardware) | 05 (render) |
| Who ships it | Meta (Muse Secure VM), OpenAI and Anthropic (cloud browser and sandboxed agents), RedactSure | Meta (Muse Confidential VM, planned), Apple (Private Cloud Compute, by a different route), the cloud providers, RedactSure | RedactSure |
Read across the row for what the model receives. The first two columns say the same thing, because neither design touches the page. That is not a flaw in either; it is their scope. The secure VM was built so the agent could act safely. The confidential VM was built so the provider could not look. The render layer was built so the model would not hold what the task did not need.
Where the consumer trust architectures sit
Three large providers built three different answers to the provider question in 2026, and it is worth placing each on the map from its own documentation.
Apple: stateless and verifiable. Private Cloud Compute states that user data must not be retained, including via logging or for debugging, after the response is returned; that the nodes intentionally include no remote shell or interactive debugging; that software images of every production build are published for security research; and that personal data must never be available to anyone other than the user, not even to Apple staff, not even during active processing. The design excludes the provider by making the machine forgetful and inspectable.
Meta: isolated now, cryptographic next. Muse gives each user a Secure VM with its own browser, a separate Sentinel that must approve every egress, and credentials the agent uses through surrogate tokens without seeing. Meta states that this version restricts personnel access through operational policies and does not prevent Meta from accessing data to support, secure or operate the service; the Confidential VM, planned for later in the year, is intended to cryptographically and verifiably prevent that access. The design excludes the provider by handing the user the keys.
The credential integrations. 1Password for Claude fills passwords and one-time codes into the page through a channel the model never sees, scoped to the task. The design excludes the model from the secret, and only from the secret.
Each of the three is a serious piece of engineering aimed at a real question. None of them changes the second-to-last row of the table. The model reads the page.
Why only the render can decide what the AI sees
The reason is mechanical. A control can only govern what passes through it. Isolation passes the agent’s process. Encryption passes the machine’s memory. Egress gates pass the outbound request. The page passes through none of those on its way to the model; it is rendered by the application inside the environment and read there. The one control that can change what the model receives is the one that sits between the render and the read.
That is why the render layer can only exist inside an environment that owns the render. A browser extension cannot intercept every path a page takes to the screen; an API vault only covers the applications a developer integrated. A governed workspace in which the organization’s applications render under the environment’s control can do two things nothing else in the table can: replace the values the task does not need with consistent tokens (USER_001, SSN_001, ACCT_001) before any model reads them, and hand the model the fields the work needs rather than the picture. What Does an AI Agent See When It Takes a Screenshot? walks the second of those.
The secure VM and the confidential VM are the preconditions for that layer, not alternatives to it. RedactSure’s environment is a governed workspace; it runs on AMD SEV-SNP hardware-encrypted enclaves on HIPAA-eligible AWS infrastructure with the customer holding the keys; and the render layer runs inside both. Everyone else controls where data can go. RedactSure controls what the AI can see.
What each design leaves for the next
An enterprise evaluating agent platforms can use the three questions as a checklist, in order.
Does the agent have its own environment, with credentials outside its reach, a gate on egress and a person who can intervene? If not, stop; that is the floor. Does an AI Agent Need Its Own Virtual Machine? covers it.
Is that environment protected from its host, and who holds the keys? A vendor-held key means the vendor is inside the trust equation; a customer-held key means it is out. Does a Confidential VM Keep Sensitive Data Away From the AI? covers it.
What did the model receive for one screen of our workflow? If the answer is the page, the visibility question is still open, whatever the first two answers were. If the answer is the task’s fields with tokens where the identifiers were, it is closed, and the AI Control Record holds the proof.
One further question sits underneath all three, and it is about ownership rather than mechanism: whether the environment belongs to the model vendor or to the customer. Should the AI Agent’s Secure Environment Belong to the Model Vendor? takes it up.
What the record shows
Three designs, three questions. The secure VM decides where the agent runs and what leaves it, and the 2026 platforms agree it is necessary. The confidential VM decides who besides the agent can see the data, and Apple and Meta built their trust architectures to answer exactly that, each in its own words excluding the provider. The render layer decides what the agent sees, and it is the only one of the three that can, because it is the only one that operates on the page before the model reads it. In the first two designs the model receives everything the browser shows; in the third it receives the fields the task needs with identifiers as tokens. An enterprise needs all three answers on file. RedactSure runs on the first two and supplies the third.
Frequently asked questions
Are these alternatives, or do we need all three?
All three. They answer different questions and none substitutes for another. RedactSure’s environment is a secure VM, runs on enclaves with customer-held keys, and carries the render layer inside; the first two are the floor.
Where does an enterprise browser fit on this map?
Between the secure VM and the render layer, governing where data may go: copy, paste, upload, download. It does not change what an AI reading the screen receives. Enterprise Browser vs. Render-Layer Tokenization draws the line.
Where does a data privacy vault fit?
At the data layer, tokenizing what flows through integrated pipelines. It protects the applications a developer wired in; the render layer protects whatever renders. Data Privacy Vault vs. Screen-Level Tokenization compares them.
Does Muse’s Sentinel do what the render layer does?
No. The Sentinel is the egress gate of a secure VM: it decides whether an action may leave the machine. It does not inspect or change what the agent read. That is the secure VM column of the table, done well.
Is the render layer a form of confidential computing?
No. Confidential computing protects the workload from the host. The render layer protects the data from the workload. RedactSure uses the first to hold the vault and the second to decide what the model is handed.
What is the one question to ask any vendor?
Show me what the model received for one screen of my workflow. The answer places the platform in a column of the table.
Related reading
Does an AI Agent Need Its Own Virtual Machine? · Does a Confidential VM Keep Sensitive Data Away From the AI? · Should the AI Agent’s Secure Environment Belong to the Model Vendor? · AI Gateway, DLP, or Tokenization: Which Layer Decides What the AI Sees? · On the RedactSure blog: The Two Gaps AI Agents Opened in Your Security Stack
Sources
Vendor documentation
- Apple Security Engineering and Architecture, “Private Cloud Compute: A new frontier for AI privacy in the cloud.” https://security.apple.com/blog/private-cloud-compute/
- Meta AI Research, “How We Built Safety Into Muse: Security and Safety for AI Agents” (September 2026). https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse
- 1Password, “1Password and Anthropic Bring Secure Credential Access to Claude” (July 16, 2026). https://1password.com/press/2026/july/1password-for-claude
Standards
- OWASP, LLM01:2025 Prompt Injection, Top 10 for LLM Applications 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
RedactSure documents
- RedactSure, “The Two Gaps AI Agents Opened in Your Security Stack” (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
- Product behavior described on this page (governed environment, enclave deployment with customer-held keys, render-layer tokenization, structured reading of the page, supervised approval) reflects RedactSure’s current design.
Bring your hardest questions.
A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.
Book a security review Book a demo · Something elseAbout the author
Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.