It isn't "trust me bro" though. If you take the time to learn how it all works you can prove all of these things that I am talking about. It's a matter of learning.
We offer the PCR0 hashes of the reproducible code and the what the enclave is attesting and so when they match it confirms that the code matches the code inside the enclave. But it is your user's job to go and read the code itself to make sure no logging or such is happening.