https://store-images.s-microsoft.com/image/apps.19761.f8f748ce-d619-47d9-9f03-a02efb95f2cb.ec0a8464-2a05-4614-ad4a-ded34f2f041b.8430a6b2-3a1d-4e10-b35e-7090a4ae01b9

Polaris Pro

Fr0ntierX Inc.

Polaris Pro

Fr0ntierX Inc.

Secure existing Docker workloads within a Trusted Execution Environment with encrypted data storage.

Securely encrypt data with a permanent key stored in a TEE.

Polaris Pro enables the secure deployment of stateful applications within a Trusted Execution Environment (TEE), encrypting all data in transit, and isolating sensitive information from the underlying infrastructure. With Polaris Pro, users can securely store encrypted data across cloud, disk, or database storage, accessible only within the TEE.


Encrypts data across disks, cloud storage, and databases

Fr0ntierX’s Polaris Pro Secure Container utilizes Confidential Virtual Machines (CVM) to isolate Docker workloads within a fully encrypted environment – CVMs offer full memory encryption with minimal overhead, shielding data from both the cloud provider and internal IT resources. With Polaris, sensitive information remains encrypted at all stages: at rest, in transit, and when in use.

Polaris Pro encrypts HTTP requests to protect against exposure risks. Our encryption process uses a public key provisioned on the client’s infrastructure and managed within the TEE by the Polaris secure proxy. With encryption handled transparently within the TEE, no workload changes are necessary.

All responses are automatically encrypted with the public key provided by the user’s request, and Polaris SDK securely and easily decrypts the information. Polaris SDK can perform the encryption and decryption inside either a server or browser environment.

Polaris Pro securely encrypts data across disks, cloud storage, databases, and more using a permanent key stored within the TEE. Access is restricted through an attestation policy, verifying workload integrity and can block SSH access or limit usage to pre-approved software versions. The Polaris SDK handles both encryption and decryption for seamless data protection.


Secure by Design

  • Data Encryption: Security at all stages – at rest, in transit, and in use

  • Complete Isolation: Workloads shielded from cloud providers and internal IT resources

  • Transparent Encryption: All requests and responses are automatically encrypted and decrypted

  • No Modifications Required: No workload changes necessary

  • Encrypted Data Storage: Securely store encrypted information

  • TEE-Based Decryption: Secure data decryption within a Trusted Execution Environment

  • Optional Software Version Pinning: Only allow pre-approved software versions to decrypt data



Key Benefits

● Memory encryption (in use)

● Optional input and Output encryption

● Permanent TEE key stored within an HSM

● Attestation policy and key protection

● Permanent storage for workloads



Why Polaris Pro?

Polaris Pro provides continuous encryption, securing data throughout its lifecycle by isolating existing stateful Docker workloads within a TEE, shielding information from cloud providers with an option to enhance input and output encryption for increased security. Polaris Pro also encrypts stored data using a permanent key stored in an HSM that can only be used with a TEE, and also allows permission-specific software version access and decryption.


https://store-images.s-microsoft.com/image/apps.58246.f8f748ce-d619-47d9-9f03-a02efb95f2cb.f1af544b-2e4b-45d8-809c-be70b1508f25.e2bb8cd3-0924-4140-9362-c696eb1e89b2
/staticstorage/71131a1/assets/videoOverlay_7299e00c2e43a32cf9fa.png
https://store-images.s-microsoft.com/image/apps.58246.f8f748ce-d619-47d9-9f03-a02efb95f2cb.f1af544b-2e4b-45d8-809c-be70b1508f25.e2bb8cd3-0924-4140-9362-c696eb1e89b2
/staticstorage/71131a1/assets/videoOverlay_7299e00c2e43a32cf9fa.png
https://store-images.s-microsoft.com/image/apps.9513.f8f748ce-d619-47d9-9f03-a02efb95f2cb.a541ce5a-763d-4470-8555-1bfbb98b4019.a1218ceb-20ae-46e4-b14c-c9c6c385063a
https://store-images.s-microsoft.com/image/apps.37645.f8f748ce-d619-47d9-9f03-a02efb95f2cb.d76ea789-c91a-4222-b8b1-f9bec88bac44.3824c882-01ab-4487-a105-63a8f5d8f0af