The answer to my question seems to be something called "enclaves".
https://blog.opensecret.cloud/opensecret-technicals/
Enclaves seem to be something like a Virtual Machine that has its memory and resources protected from prying eyes at the hardware level, even from the hypervisor running the VM.
However, even if you offer reproducible builds of these enclaves, how can anyone be certain that the current running enclave really is that same build?