The coverage is calculated into a PCR from the Confidential VM's vTPM (that's matched in The main element release plan on the KMS Using the expected plan hash for the deployment) and enforced by a hardened container https://abeluqtl112232.blogmazing.com/29788472/a-review-of-safe-ai-chatbot