The confinement controller is trusted infrastructure
Strict-local execution requires a qualified Linux host. The controller runs as the same user and remains part of the trusted infrastructure. A signed result is not proof that the entire host is outside an attacker’s reach.
