A sealed vault, not a spy
A Trusted Platform Module is a small cryptoprocessor with one job: holding keys in a place software cannot read. Inside it live a storage root key that wraps everything else, and an endorsement key, burned in at manufacture, that identifies the chip itself. Applications hand the TPM encrypted material and ask it to lock or unlock data — the private material never leaves the chip, not for Windows, not for the apps, not for a debugger.
The second half of its job is measuring. At every boot, the firmware, bootloader and early drivers get cryptographically hashed into registers called PCRs, forming a tamper-evident log of exactly which chain of code started the machine. That log is why BitLocker can tell a healthy boot from a tampered one — and why changing a firmware setting can suddenly demand your 48-digit recovery key.
What it actually stores about you
The inventory is shorter and more boring than the rumors suggest. A TPM never sees your browsing, your documents or your keystrokes — it has no storage for them and no way to read RAM. What it does hold is a short list of cryptographic secrets tied to your machine's identity and its boot history.
- BitLocker's volume encryption keys, sealed so the disk unlocks only after a verified boot
- Windows Hello biometric templates and PIN material — the keys behind face and fingerprint login
- PCR measurements — running hashes of your firmware settings, bootloader and boot drivers, never their contents
- Attestation identity keys, used to prove to a server that a genuine, verified machine is asking for something
- Optional application keys — VPN certificates and corporate secrets sealed by IT software
Who can read it — and why Windows 11 demands it
The TPM does not phone home; it cannot — it has no network stack and no way to send anything anywhere. Disclosure happens when software asks it to attest: a health check proves to a server that the machine booted verified code, without revealing your keys. If you sign in with a Microsoft account, your BitLocker recovery key also gets escrowed there — that is a Windows policy decision, not the chip's doing, and you can review it at aka.ms/myrecoverykey.
Windows 11 requires TPM 2.0 because its whole security stack — measured boot, Credential Guard, Windows Hello, BitLocker by default — is built on keys that must live somewhere software cannot touch. Whether yours is a discrete chip on the board or firmware inside an Intel (PTT) or AMD (fTPM) CPU changes nothing about your privacy: both refuse to spill their secrets to the operating system. Clearing or disabling the TPM from firmware settings is possible, but on an encrypted machine you will need that recovery key first.
Questions and Answers
Does a TPM chip record what I do on my computer?
No. It stores keys and boot measurements only — it has no access to your files, browsing history or keystrokes, and no connection to send them anywhere.
Can I disable or remove the TPM on my PC?
You can clear or disable it in firmware settings, but if the disk is BitLocker-encrypted, Windows will demand the 48-digit recovery key on the next boot. Save that key to your Microsoft account first.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]