Request a consultation

focus area · protecting data even during processing

Confidential Computing

Today data is stored encrypted and transmitted encrypted. Yet the moment an AI model processes it, it sits in plain text in memory — visible to operators, administrators and attackers with system access. Confidential computing closes this gap: processing takes place in a hardware-protected environment whose state can be proven cryptographically.

The gap between storage and transmission

Classic security architectures protect data “at rest” (disk, database) and “in transit” (network). The third state — “in use”, during computation — long remained unprotected. Whoever controls the infrastructure can in principle read along: the cloud provider, an administrator, a compromised operating system.

For AI this is particularly relevant because models process large amounts of context at once: contracts, patient data, design documents, personnel files. Exactly the data nobody but the company itself should see.

How confidential computing works

Modern processors and increasingly GPUs offer trusted execution environments (TEE). Code and data run in an encrypted memory region that neither the operating system nor the hypervisor nor the operator can inspect. Before data is loaded into such an environment, it proves through attestation that it is running the expected hardware, configuration and software.

Memory encryption

Data and model exist in memory only in encrypted form; decryption happens exclusively inside the processor.

Isolation

Operating system, hypervisor and operator have no access to the content of the protected environment.

Attestation

A cryptographic proof shows which code runs on which hardware before data is handed over.

GPU support

Current accelerators extend protection to AI inference itself, not just pre-processing.

When confidential computing makes sense for AI

Not every use case needs this protection. It becomes worthwhile when data is so sensitive that external processing was previously ruled out — or when several parties want to combine data without disclosing it to each other.

  • Processing sensitive documents in the cloud: Contracts, expert reports, HR or health data with external models, without the provider being able to read along.
  • Joint analyses in supply chains: Quality or demand data from several partners is analysed together; nobody sees the others' raw data.
  • Protecting your own models: Fine-tuned models and prompts stay protected even on third-party infrastructure.
  • Shared Sovereignty: Shared AI infrastructure with hardware-backed tenant separation.

Classification under data protection and compliance

Confidential computing replaces neither a legal basis nor a data processing agreement. It is a technical and organisational measure in the sense of the GDPR that significantly lowers the risk of processing — and can therefore enable processing that would otherwise be rejected. For ISO 27001, TISAX and BSI baseline protection, attestation provides robust evidence. We carry out the assessment together with your data protection officer and your law firm.

A realistic view of limits and costs

Confidential computing protects against access by infrastructure operators and the system level — not against faulty application code, insecure interfaces or misconfiguration. It costs compute, narrows the choice of hardware and providers and requires know-how for attestation and key management. Whether it pays off is calculated per use case with the Sellium TCO model against the alternatives: on-premise operation, conventional cloud with contractual assurances, or forgoing the use case.

privacy first ai

Proving trust instead of promising it

Provider promises are contract clauses. Attestation is cryptographic proof. For companies whose business rests on confidentiality, that is the difference between “not allowed” and “safely possible”.

Verifiable

The state of the execution environment is checked and logged before every data handover.

Vendor-neutral

We evaluate TEE offerings from cloud providers, data centres and on-premise hardware by the same criteria.

Embedded

Confidential computing is a building block of the AI architecture — aligned with data preparation, model choice and governance.

process

How we introduce confidential computing

From protection needs to attested processing.

  1. Step 1: Protection needs & use cases

    Which data, which use cases, which threats: assessment with data protection and IT security.

  2. Step 2: Architecture & provider choice

    Target architecture with TEE components, key management and attestation flow; TCO comparison of variants.

  3. Step 3: Pilot & proof

    Implementation of one use case in the protected environment; attestation, logging and verification of the evidence.

  4. Step 4: Operation & documentation

    Regular operation with monitoring, documentation for audits and data protection, expansion to further use cases.

contact

Let's talk

Happy to help with anything AI. We will get back to you promptly.

AddressCarolastraße 4-6, 09111 Chemnitz

Get in touch