Decision tree
Comparison
Deployment models
Turnkey Hosted
Turnkey operates the VisualSign parser in AWS Nitro Enclaves. You send transactions to their API and verify the attestation documents they return. You handle:- Calling the Turnkey API
- Verifying attestation documents
- Displaying parsed output to users
- Enclave infrastructure
- Scaling and availability
- Enclave updates and PCR management
Self-Hosted TEE
Run the VisualSign parser in your own AWS Nitro Enclaves. You have full control over the infrastructure and can customize the deployment to your needs. You handle:- AWS Nitro Enclave infrastructure
- Enclave deployment and updates
- PCR allowlist management
- Scaling and availability
- Organizations with strict compliance requirements
- Use cases requiring air-gapped or private deployments
- Custom attestation verification workflows
Library Integration
Embed the VisualSign parser directly in your application. Available as Rust crates that can be compiled into your application. Trade-offs:- No attestation (you trust your own process)
- No network latency
- Smallest deployment footprint
gRPC Server
Run the gRPC parser service without TEE infrastructure. The same gRPC API as the TEE deployments, but without enclave isolation or attestation. Use cases:- Development and testing
- Internal services on trusted networks
- Environments where TEE isn’t available
- No attestation verification
- Relies on network security
- Same API as TEE deployments (easy migration path)
Security considerations
When you need attestation
Attestation provides cryptographic proof that:- The parser code hasn’t been tampered with
- The parsing happened inside a secure enclave
- The output hasn’t been modified
- Users are signing high-value transactions
- Regulatory requirements mandate tamper-evident processing
- You need to prove parsing integrity to auditors or users
When attestation isn’t required
Library or gRPC Server deployments are appropriate when:- Parsing happens on the user’s own device (browser extension, mobile app)
- The service runs on internal infrastructure you fully control
- You’re building development or testing environments
- The threat model doesn’t include compromised parsing infrastructure
Next steps
Choose your deployment model and follow the getting started guide:- Turnkey Hosted — Fastest path to production
- Self-Hosted TEE — Full control with TEE security
- Library Integration — Embed parsing directly
- gRPC Server — Simple gRPC service
- How parsing works — Transaction input and VisualSign output
- Chain metadata — Providing ABIs and IDLs
- Error handling — Handling parse failures gracefully