points
> even if you don't have the keys you may still control the implementation
The sorts of places that care about remote attestation also care about insider risk.