If a protocol processes sensitive financial data off chain, what should users require as proof before trusting the workload?

Would love to hear how you'd answer.