---
title: "STACKIT Confidential Computing"
description: "Hardware-based data-in-use protection providing strict memory isolation (TEE) and zero-knowledge cloud architectures."
scfAsset:
  category: "blueprint"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Confidential Compute", "Security", "AMD SEV-SNP", "Zero-Trust", "Encryption"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-confidential-computing/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-confidential-computing.mdx"
---

STACKIT Confidential Computing provides hardware-based isolation for sensitive workloads, guaranteeing that data remains encrypted during processing (data-in-use).

## Service Overview
- **Technical Operator Exclusion**: Cryptographic barriers prevent cloud operators and hypervisors from inspecting customer memory space.
- **Compliance Alignment**: Meets the stringent requirements of highly regulated industries, healthcare, and public sector workloads.
- **Zero-Trust Security**: Ensures cryptographic proof of environment integrity before releasing sensitive keys.

## Technical Details
- **Trusted Execution Environments (TEE)**: Memory encryption powered by AMD SEV-SNP and Intel TDX at the CPU level.
- **Confidential VMs (cVM)**: Cryptographically isolated virtual machines isolated from the underlying host hypervisor.
- **Attestation Service**: Validates boot measurements (firmware/runtime) and executes Key Release actions via KMS/Vault integration.

## Limitations & Constraints
- **Roadmap Availability**: Features are undergoing phased rollout (cVMs with AMD SEV-SNP Q4 2026, Intel TDX Q1 2027, GPU support H2 2027+).
- **Hardware Binding**: Restricted to specific confidential-capable machine types and hardware generations.

<LinkCard title="STACKIT Confidential Computing Overview" href="https://docs.stackit.cloud" />
