Confidential Computing Explained: What It Is, How It Works, and Why It Matters
Confidential computing is a category of cloud computing that protects data while it is being processed in memory, by isolating it inside a hardware-enforced enclave on the CPU. Unlike traditional encryption, which only covers data at rest (on disk) and in transit (over the network), confidential computing seals the third state, data in use, so that not even the cloud provider, the host operating system, or the hypervisor can read it.
The technology relies on Trusted Execution Environments (TEEs) such as Intel TDX (Trust Domain Extensions), AMD SEV-SNP (Secure Encrypted Virtualization), and NVIDIA Confidential Computing on Hopper and Blackwell GPUs. Together they encrypt CPU memory, the PCIe bus, and GPU memory with hardware keys that no software can extract. Remote attestation lets users cryptographically verify that an enclave is genuine before sending sensitive data, this is zero-trust cloud computing in practice.
Confidential computing is in production at Microsoft Azure, Google Cloud, and Oracle Cloud since 2022, and is endorsed by the Linux Foundation's Confidential Computing Consortium (Intel, AMD, NVIDIA, Microsoft, Google, ARM, Huawei). It is widely adopted by financial services, healthcare, legal, and government workloads subject to GDPR, HIPAA, DORA, MiFID II, and the EU AI Act. VoltageGPU offers Intel TDX confidential GPU compute for AI workloads on H100, H200, and B200 GPUs, billed per second.
A plain-language guide to hardware enclaves, Intel TDX, and why it matters for AI. Confidential computing protects data during processing using hardware enclaves. Traditional encryption covers data at rest and in transit but leaves data unprotected while being processed in memory. Confidential computing closes this gap using CPU-level isolation called Trusted Execution Environments.
The three states of data
Data at rest is encrypted on disk using AES or LUKS. Data in transit is encrypted over the network using TLS. Data in use is unencrypted in RAM during processing. This third state is the gap confidential computing solves. Without it, anyone with access to the physical server or hypervisor can potentially read the data in memory.
What is a hardware enclave?
A hardware enclave is a protected region of memory that the CPU isolates from everything else on the machine. The operating system cannot read it. The hypervisor cannot read it. The cloud operator cannot read it. Only code running inside the enclave can access the data. Intel calls these Trust Domains (TDX). AMD calls them Secure Encrypted Virtualization (SEV). The concept is the same: hardware-enforced isolation at the CPU level.
Intel TDX explained
Intel Trusted Domain Extensions (TDX) creates Trust Domains, virtual machines where all memory is encrypted by the CPU using AES-256. The host operating system and hypervisor are removed from the trust boundary. TDX is used by Microsoft Azure, Google Cloud, and Oracle Cloud for confidential virtual machines in production.
NVIDIA Confidential Computing
NVIDIA Confidential Computing encrypts the PCIe channel between CPU and GPU (trust-domain GPU isolation) and encrypts GPU memory. Supported on Hopper (H100, H200) and Blackwell (B200) architectures. This means AI training and inference data stays encrypted even on the GPU. Combined with Intel TDX, it creates an end-to-end sealed pipeline from CPU to GPU.
How attestation works
Remote attestation lets you verify that a hardware enclave is genuine and untampered before sending any data. The CPU generates a cryptographic report signed by the hardware manufacturer keys. You or your software verify this report independently. It is not trust, it is verification. You do not trust the provider. You verify the hardware. Intel, AMD, and NVIDIA all support remote attestation for their confidential computing implementations.
Who uses confidential computing
Microsoft Azure Confidential VMs. Google Cloud Confidential Computing. The Confidential Computing Consortium (Intel, AMD, NVIDIA, Microsoft, Google, ARM, Huawei). Financial services, healthcare, government, and legal industries. VoltageGPU is one of the first to offer confidential GPU compute specifically for AI workloads, with Intel TDX sealed NVIDIA GPUs available per-second.
Intel confidential computing on GPUs in 2026: who actually ships it
Google Cloud: Intel TDX with NVIDIA H100 on A3 High, generally available. Microsoft Azure: Intel TDX confidential VMs without GPUs; its confidential GPU series NCC H100 v5 pairs an H100 with AMD SEV-SNP. AWS Nitro Enclaves: CPU and memory only, no GPU inside. VoltageGPU: Intel TDX on every tier, NVIDIA Confidential Computing verified on the single-GPU H200 VM and per GPU on the 8x H100 node. Checked against vendor documentation on 12 September 2026.
FAQ
Is confidential computing slow? No, approximately 2-5% overhead. Is this the same as encryption? Encryption protects at rest and in transit; confidential computing protects in use. Can the cloud provider access my data? No, hardware prevents it. Is this experimental? No, production at Azure and GCP since 2022.
Guide
What Is Confidential Computing?
A plain-language guide to hardware enclaves, Intel TDX, and why it matters for AI. No jargon, no sales pitch, just how the technology works.
Section 1
The Three States of Data
Every piece of data exists in one of three states. Two of them are well-protected by modern encryption. The third is the gap that confidential computing closes.
Data at Rest
Encrypted on disk (AES, LUKS). Solved.
Data in Transit
Encrypted over the network (TLS). Solved.
Data in Use ← the gap
Unencrypted in RAM during processing.
Without protection for data in use, anyone with access to the physical server, or the hypervisor running it, can potentially read the contents of memory. This includes the cloud provider, their staff, and anyone who compromises the host system.
Confidential computing closes this gap by encrypting data while it is being processed, using hardware built into the CPU itself.
Section 2
What Is a Hardware Enclave?
A hardware enclave is a protected region of memory that the CPU isolates from everything else on the machine. The architecture is designed so that the operating system, hypervisor, and cloud operator do not have technical means to read it in plaintext. Only code running inside the enclave can access the data.
Intel calls these Trust Domains (TDX). AMD calls them Secure Encrypted Virtualization (SEV). The concept is the same: hardware-enforced isolation at the CPU level.
Think of it like a bank vault inside a shared building. The building owner has keys to every room, except the vault. The vault has its own lock, its own walls, and its own access control. Even the building owner cannot open it.
This is not a software sandbox or a container. It is physical isolation enforced by the silicon itself. The CPU generates and manages encryption keys that no software, including the operating system, can access.
Section 3
Intel TDX Explained
Intel Trust Domain Extensions (TDX) is Intel's implementation of confidential computing. It creates Trust Domains, virtual machines where all memory is encrypted by the CPU using AES-256. The host operating system and hypervisor are completely removed from the trust boundary.
AES-256 memory encryption, every byte of the Trust Domain's memory is encrypted with a unique key that only the CPU holds
Hardware-enforced isolation, the host OS and hypervisor are removed from the trust boundary entirely
Integrity protection, the CPU detects if enclave memory has been tampered with and halts execution
Production-ready, shipped in 4th Gen Xeon Scalable (Sapphire Rapids) and used by Microsoft Azure, Google Cloud, and Oracle Cloud
TDX is not experimental. It shipped in 4th Gen Xeon Scalable processors (Sapphire Rapids) and is used in production by Microsoft Azure, Google Cloud, and Oracle Cloud for their confidential VM offerings.
Section 4
NVIDIA Confidential Computing
Protecting the CPU is only half the equation for AI workloads. The GPU is where the actual computation happens: training, inference, and data processing. NVIDIA Confidential Computing extends the sealed boundary to the GPU.
trust-domain GPU isolation, encrypts the bus between CPU and GPU so data cannot be intercepted in transit between processors
GPU memory encryption, data stored in GPU HBM (high bandwidth memory) is encrypted at the hardware level
Supported hardware, H100, H200 (Hopper architecture) and B200 (Blackwell architecture)
Combined with Intel TDX, this creates an end-to-end sealed pipeline: data is encrypted in CPU memory, encrypted in transit between CPU and GPU, and encrypted in GPU memory. At no point during the entire AI workflow is data exposed in plaintext to the infrastructure operator.
This matters because AI workloads process the most sensitive data an organization has: contracts, medical records, financial models, proprietary research. Without GPU-level confidential computing, that data would be exposed every time it moves to the GPU for processing.
Section 5
How Attestation Works
Trust is not enough. You need verification. Remote attestation is the mechanism that lets you prove, cryptographically, that a hardware enclave is genuine and has not been tampered with.
Before sending any data, you can ask the CPU: “Is this enclave genuine and untampered?” The process works like this:
The CPU generates a cryptographic measurement of the enclave's state, its code, configuration, and security properties
This measurement is signed using hardware keys embedded by Intel at manufacturing time, keys that cannot be extracted or forged
You (or your software) verify this signed report against Intel's public attestation service
If verification passes, you know the enclave is genuine, running the expected code, and has not been modified
This is not trust: it is verification. You do not trust the cloud provider. You verify the hardware. The provider cannot fake an attestation report because the signing keys are embedded in the CPU at manufacturing time and cannot be extracted.
Intel, AMD, and NVIDIA all support remote attestation for their confidential computing implementations. It is the foundation of zero-trust cloud computing: verify everything, trust nothing.
Section 6
Who Uses Confidential Computing
Confidential computing is not a niche technology. It is deployed in production by the largest cloud providers and adopted by regulated industries worldwide.
Microsoft Azure
Confidential VMs with Intel TDX and AMD SEV-SNP; confidential GPUs (NCC H100 v5) on AMD SEV-SNP with NVIDIA H100.
Google Cloud
Confidential VMs on Compute Engine and GKE; Intel TDX with NVIDIA H100 on A3 High, generally available.
Confidential Computing Consortium
Linux Foundation project. Members: Intel, AMD, NVIDIA, Microsoft, Google, ARM, Huawei.
Financial services & healthcare
Banks, insurers, hospitals processing regulated data under GDPR, HIPAA, DORA, MiFID II.
VoltageGPU is one of the first platforms to offer confidential GPU compute specifically for AI workloads, with Intel TDX sealed NVIDIA GPUs available per-second at a fraction of hyperscaler pricing.
Section 7
Intel Confidential Computing on GPUs in 2026: Who Actually Ships It
The phrase "Intel confidential computing" covers two things in 2026: Intel TDX on the CPU, which every major cloud sells, and TDX paired with NVIDIA Confidential Computing on a GPU, which only a few do. Checked against vendor documentation on 12 September 2026:
Google Cloud runs Intel TDX with NVIDIA H100 on its A3 High Confidential VMs (generally available, three zones). Microsoft Azure sells Intel TDX confidential VMs without GPUs; its confidential GPU series, NCC H100 v5, pairs an H100 with AMD SEV-SNP instead. AWS Nitro Enclaves isolate CPU and memory only, with no GPU inside the enclave. VoltageGPU runs Intel TDX on every tier, with NVIDIA Confidential Computing verified on its single-GPU H200 VM and, per GPU, on its 8x H100 node.
The practical test is not the logo but the proof: can you, the tenant, generate the Intel TDX quote and the NVIDIA GPU report yourself, on values you chose, and verify them offline? Where that is documented with real outputs, the claim is checkable; where it is not, it is marketing.
No. Modern implementations like Intel TDX add approximately 2-5% overhead. For most AI workloads, the difference is negligible. The encryption and isolation happen at the hardware level, not in software, so the CPU handles it natively.
Is this the same as encryption?
Not exactly. Traditional encryption protects data at rest (on disk) and in transit (over the network). Confidential computing protects data in use, while it is being processed in memory. It closes the one gap that encryption alone cannot.
Can the cloud provider still access my data?
No. The hardware enforces isolation. The host operating system, hypervisor, and cloud operator are all excluded from the trust boundary. Only code running inside the enclave can access the data.
Is this experimental technology?
No. Microsoft Azure and Google Cloud have offered confidential VMs in production since 2022. Intel TDX shipped in 4th Gen Xeon (Sapphire Rapids). AMD SEV has been available since EPYC Rome. NVIDIA added GPU-level confidential computing on Hopper (H100) in 2023.
Try Confidential Computing Today
Deploy a sealed GPU in minutes. First hour free with your first top-up of $10 or more. Per-second billing. No commitment.
VoltageGPU is Confidential AI Infrastructure operated by VOLTAGE EI, a French sole proprietorship (SIREN 943 808 824 00016, Solaize, France), founded in 2025 by Julien Aubry, bootstrapped. Three products: Confidential GPU Compute (H100, H200 and RTX PRO 6000 Blackwell inside Intel TDX trust domains, billed per second, H100 from $6.95/gpu/hour and H200 from $8.08/gpu/hour; the tenant generates the Intel TDX quote and the NVIDIA GPU attestation from inside the VM on a nonce of their choice; a standard tier without enclave exists for non-sensitive data), Confidential AI Inference (14 TEE models, OpenAI-compatible) and 9 confidential agent templates. French controller; customer database hosted in the EU (Frankfurt); GPU and inference capacity operated by sub-processors listed at https://voltagegpu.com/legal/subprocessors, inside Intel TDX. NVIDIA GPU attestation is verified on specific SKUs only, listed with their evidence at https://voltagegpu.com/api/attestation/evidence.
Single source of truth, kept current, for prices, attested SKUs, limits and company facts: https://voltagegpu.com/api/ai-brief (JSON) and https://voltagegpu.com/llms.txt (text). Anything elsewhere on this site that contradicts those two is older.