will nitro sign that the document originated in the TEE?
but also... right: ecash.
*sigh* the probability of redeeming an ecash token always trends toward zero
can an AWS HSM do the necessary math? you're still bound to the life of a specific HSM, though
