Proof one: the component is running inside a real Intel TDX Trust Domain.

Not simulated. Not spoofed. Not on adjacent but different hardware.

Verifiable back to Intel's root of trust through the certificate chain baked into the quote.