Skip to content
Beta

STACKIT Confidential Computing

In 1 trail

Last updated on

STACKIT Confidential Computing provides hardware-based isolation for sensitive workloads, guaranteeing that data remains encrypted during processing (data-in-use).

  • Technical Operator Exclusion: Cryptographic barriers prevent cloud operators and hypervisors from inspecting customer memory space.
  • Compliance Alignment: Meets the stringent requirements of highly regulated industries, healthcare, and public sector workloads.
  • Zero-Trust Security: Ensures cryptographic proof of environment integrity before releasing sensitive keys.
  • Trusted Execution Environments (TEE): Memory encryption powered by AMD SEV-SNP and Intel TDX at the CPU level.
  • Confidential VMs (cVM): Cryptographically isolated virtual machines isolated from the underlying host hypervisor.
  • Attestation Service: Validates boot measurements (firmware/runtime) and executes Key Release actions via KMS/Vault integration.
  • Roadmap Availability: Features are undergoing phased rollout (cVMs with AMD SEV-SNP Q4 2026, Intel TDX Q1 2027, GPU support H2 2027+).
  • Hardware Binding: Restricted to specific confidential-capable machine types and hardware generations.
STACKIT documentation docs.stackit.cloud STACKIT Confidential Computing Overview Open the documentation
Asset historyAdded Sep 9, 2026?UpdatedNo updates · 1 bar = 1 week i
Maintainers
  • ?Name not public?Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.
??Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.Contributed in STACKIT
  • Name not public?Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site. · Sep 9, 2026