Testing (probabilistically, of course) that the code you're running is the code that was certified without your having any visibility into the code itself. The ZKP bits have to have been added by the certification authority to enable you to do this. Think smart cards.