Keys are generated inside the enclave and sealed to the hardware. Even the operator can't access them.
Keys can be generated within the enclave to cryptographically prove nobody, not even you or Enclavia, has a backup of those secrets. Enclave memory is always fully encrypted, protecting keys from attacks even if the cloud provider is compromised. Using a strict networking policy you can also stop a potential compromise of the enclave from easily leaking secrets to an attacker.
Data is processed where no operator can read it. Not you, not us. Your users get proof, not promises.
Prove to your customers that you can't see their sensitive data. Provide better services such as server-side transaction monitoring, alerting, push notifications of inbound and outbound payments without possessing privacy-sensitive addresses and public keys. Offer inheritance or recovery services, without knowing your user's balances.
Data you can't read is data you can't leak or be compelled to hand over. The liability surface shrinks.
Any data you don't have, can't be leaked. Even in case of a compromised or rogue employee. Keys generated within the enclave are cryptographically provably unknown to you. You can't be compelled to release any data, or sign a bitcoin transaction because you don't know the secrets.
HTTPS took over the internet. Enclaves will take over compute.