The computer’s hypervisor, which runs below the VM running the untrusted OS and apps, decrypts the data and associates hardware tags with every memory word of the mem-ory allocated to hold the decrypted data—called a secure data compart-ment within the memory.