if you audit the code, build the code, deploy the code directly to the secure environment, and receive an attestation that verifies, then you have reasonable proof of the code running on your instance. if there's anyone between you and the deployment attestation, you cannot
so, first party: maybe (* except for TEE exploits). third party: no. if i run routstrd, there is no way to prove im not reading your messages
