But without the source being available you still need to trust vp.net to be providing the correct hash to compare to, right?
https://www.intel.com/content/www/us/en/developer/tools/soft...
So you can verify locally and Intel's API also does the verification.
When an SGX Encalve is created, the private key to it goes within it, it can't be accessed. That's the security.
It's a good read if you look in to the tech on Intel's website.