Every security professional knows the uncomfortable truth: your most sensitive data is most vulnerable precisely when you need to use it.
For decades, the playbook has been straightforward enough. Encrypt databases at rest. Encrypt network traffic in transit. But then comes the moment of reckoning—when an algorithm needs to crunch those numbers, when an AI model needs to analyze patient records, when a fraud detection system needs to scan transactions. At that instant, everything gets decrypted. Exposed. Sitting in server memory where anyone with the right access could theoretically see it all: cloud providers, rogue administrators with privileged credentials, even nation-state actors who've gained physical access to data center hardware.
It's the reason major banks still run their core trading systems in on-premises data centers. Why healthcare institutions balk at using cloud-based AI for diagnostics, no matter how good the algorithms. Why defense contractors demand air-gapped deployments that make IT directors quietly weep. The third pillar of encryption—protecting data during processing, not just when it's stored or transmitted—has existed mostly in the realm of academic papers and proof-of-concept demos.
Maybe not for much longer.
On February 3, 2026, Berlin-based Enclaive closed a €4.1 million seed round, co-led by Join Capital and Amadeus APEX Technology Fund with participation from Auriga Cyber Ventures. The funding itself is modest by today's venture standards—barely a rounding error compared to the billion-dollar rounds flowing into generative AI startups. But the timing tells a different story. Enclaive is betting that a technology called confidential computing is finally ready to move from early adopter curiosity to enterprise necessity.
"We're addressing a fundamental trust gap in multi-cloud and AI deployments," CEO Andreas Walbrodt said when announcing the round. The company's platform—dubbed eMCP, short for Enclaive Multi Cloud Platform—promises something that sounds almost too good: securing data at rest, in transit, and during processing, what they're calling "3D encryption." The kicker? They claim enterprises don't need to rewrite their applications.
Which would be remarkable if it works at scale. The question hovering over confidential computing has never been whether the concept makes sense—it does—but whether it can escape the gravitational pull that keeps so many elegant security technologies trapped in niche deployments.
How We Got Here (Faster Than Expected)
The journey from research labs to production systems has been surprisingly swift, at least by enterprise security standards.
The core idea behind confidential computing is elegant: isolate sensitive workloads inside hardware-based Trusted Execution Environments, or TEEs. These create secure enclaves that even the host operating system can't access. Think of them as sealed black boxes enforced by the processor itself. Before any processing begins, the enclave uses cryptographic attestation to prove both the code running inside and the hardware state are legitimate. No attestation, no decryption.
All three hyperscale cloud providers now offer versions of this technology, though the implementations diverge in ways that make cross-cloud deployments... interesting.
Google Cloud made its Confidential Space generally available in 2024, then expanded it throughout 2025 with Intel TDX support. The company launched confidential Google Kubernetes Engine nodes on C3D instances using AMD SEV on January 27, 2025. Ubuntu confidential VMs on A3 instances with NVIDIA H100 GPUs appeared March 27, 2025. AWS has woven confidential computing into the Nitro system and Nitro Enclaves from the ground up; at re:Invent 2025, the company showcased EC2 instance attestation and what they call the Nitro Isolation Engine with formal verification methods. Microsoft Azure offers confidential VMs powered by AMD SEV-SNP across DCasv5 and ECasv5 instance families, Intel SGX application enclaves, and preview versions of AKS confidential containers.
Market projections vary wildly depending on which analyst you ask, but the directional trend is unambiguous. Mordor Intelligence pegs the confidential computing market at $9.31 billion in 2025, growing to $172.95 billion by 2031—a compound annual growth rate of 62.7%. Future Market Insights is notably more conservative at $8.9 billion for 2025 expanding to $83.1 billion by 2035 (25% CAGR). Market Research Future splits the difference: $6.09 billion in 2024 expanding to $166.9 billion by 2035, which works out to 35.1% annually.
The exact numbers matter less than what Gartner said last October: by 2029, more than 75% of operations processed in untrusted infrastructure will be secured in-use through confidential computing. The firm listed it among its top strategic technology trends for 2026. When Gartner calls something a strategic trend, CIOs start paying attention, whether they want to or not.
Three Forces Converging
What's pushing confidential computing from specialized security feature to board-level priority? Three forces, really, each feeding the others.
First: AI workloads that demand processing sensitive data without exposing it.
NVIDIA announced confidential computing support for its H100 GPUs with multiple modes—CC-Off, CC-On, and DevTools—complete with attestation tooling. The company's upcoming Rubin platform, unveiled at CES 2026, promises what NVIDIA is marketing as "3rd-generation confidential computing" at rack scale. When Apple launched Private Cloud Compute with hardware-enforced TEEs and transparency logs for AI processing, and Google followed with its own "Private AI Compute" announcements, the subtext became text: if you're running AI inference on sensitive data, you need confidential computing. Period.
"Confidential computing is laying the foundation for trusted AI," Google Cloud's leadership wrote in an earlier 2025 blog post explaining the company's TDX and SEV expansions. It reads like corporate boilerplate until you consider what they're actually saying—that without hardware-enforced privacy guarantees, enterprises won't trust cloud AI with their most valuable data. Which would be a problem for cloud providers who've bet their futures on AI workloads.
Second: regulatory requirements that are shifting from aspirational to mandatory, with actual penalties attached.
The EU's NIS2 directive had an October 17, 2024 transposition deadline, though many member states missed it and the European Commission started issuing infringement notices in November 2024 and May 2025. The directive affects essential and important entities across critical sectors. EU DORA regulations for the financial sector became applicable January 17, 2025. The EU AI Act's timeline runs through 2027, with high-risk AI enforcement starting August 2, 2026.
In the United States, SEC cybersecurity disclosure rules now require incident 8-Ks within four business days of materiality determination. The scrutiny continued through 2024 and 2025, and it's not getting more lenient.
A December 2025 study from the Confidential Computing Consortium and IDC found that 75% of organizations are adopting confidential computing, with AI and compliance as the primary drivers. Same report identified interoperability, attestation standards, and skills gaps as the remaining bottlenecks—which is consultant-speak for "the technology works but implementing it is still a pain."
Third: the economics and reality of multi-cloud architectures.
Enterprises increasingly spread workloads across AWS, Azure, and Google Cloud—for resilience, cost optimization, avoiding vendor lock-in, or all three. But managing encryption keys and maintaining consistent security policies across clouds quickly becomes a nightmare. Different attestation mechanisms. Different key management systems. Different monitoring tools. Enclaive's pitch—a unified abstraction layer with virtual HSM capabilities and sovereign key management across providers—addresses a real operational headache.
Whether they can deliver on that pitch at scale remains to be seen. But the pain point is genuine.
Where It's Actually Working

The most revealing insights come from early adopters who've moved past pilots into production.
UCSF's BeeKeeperAI project used Azure with Intel SGX and Fortanix's platform to validate AI models on protected clinical data. The setup allowed researchers to train and test algorithms on sensitive patient information without ever exposing the underlying data to the model developers or cloud provider. That's not a theoretical use case—it's how you enable medical AI research without violating HIPAA or patient trust.
Data clean rooms represent another application that's gaining traction. Decentriq built its platform on Azure Confidential Computing to enable cross-organizational analytics without revealing raw data. Financial crime analysis often requires sharing transaction patterns across banks, something that's legally and practically complicated. Confidential computing makes it possible without compromising customer privacy. In theory, anyway.
Then there's the civil society angle, which perhaps matters more than people realize. The Organized Crime and Corruption Reporting Project—OCCRP—uses Edgeless Systems' Constellation, a confidential Kubernetes distribution, to protect investigations running on Google Cloud. For journalists working on stories that might attract government surveillance or worse, hardware-enforced guarantees matter more than traditional software security ever could. When your adversary controls physical infrastructure, software protections aren't enough.
NATO's late 2025 deal with Google Cloud for sovereign and air-gapped Google Distributed Cloud deployments signals that defense and government sectors increasingly view confidential computing as table stakes for cloud adoption. That's a sentence that would have sounded absurd five years ago.
The Technical Reality (Warts and All)
The confidential computing landscape has gotten crowded quickly: hyperscale cloud platforms, chip vendors providing TEE hardware, and specialized software companies trying to simplify adoption.
Intel offers TDX (Trust Domain Extensions) on 4th and 5th generation Xeon processors alongside Trust Authority for attestation. AMD's SEV-SNP runs across EPYC Milan, Genoa, and Turin processor lines. Arm's CCA (Confidential Compute Architecture) introduces what they call realms and RME. NVIDIA's confidential computing spans Hopper, Blackwell, and Rubin GPUs with GPU and switch attestation SDKs.
Software vendors have emerged to abstract complexity away. Fortanix provides Confidential Computing Manager and Data Security Manager supporting AWS Nitro Enclaves, Azure confidential VMs, and its own confidential OS. Edgeless Systems offers Constellation as a CNCF-certified confidential Kubernetes distribution. Anjuna Security supports Azure confidential VMs. Opaque Systems focuses on multi-party confidential AI and analytics, tracing its lineage back to the academic MC2 project.
Enclaive positions itself as the no-code-change option—enterprises wanting confidential computing without application rewrites. The company's eMCP supports confidential VMs (called "buckypapers" in their documentation, which is certainly a choice), confidential Kubernetes clusters ("dyneemes"), virtual HSM, and bring-your-own-sovereignty key management across AWS, Azure, and soon Google Cloud. The platform has attracted customers including Skill In-Depth, Atlas IoT, Meedio, Bare.ID, and Mitigant, according to company materials.
Open-source options like SCONE and Gramine enable container and application lift-and-shift into TEEs, though they require considerably more hands-on technical work than commercial platforms.
Here's the part that vendor marketing materials tend to gloss over: the technology isn't bulletproof.
AMD SEV-SNP faced multiple vulnerability disclosures in 2025, including "RMPocalypse" (CVE-2025-0033) and "StackWarp" (CVE-2025-29943). AMD released mitigations in security bulletins, but the vulnerabilities existed. Intel SGX had historical issues with Foreshadow/L1TF and Plundervolt side-channel attacks. Academic researchers continue finding ways to refine confidential containers and VMs, which is a polite way of saying they keep discovering new attack vectors.
The reality is that confidential computing materially raises the security bar, but it doesn't eliminate hardware and side-channel risks. Attestation rigor, patch hygiene, and careful architecture choices remain critical. Performance overheads for GPU AI workloads are measurable compared to non-confidential modes. They're improving, but they exist.
What Comes Next (And What Doesn't)

Two trajectories will likely define confidential computing's next phase: standardization efforts and the post-quantum cryptography transition.
The "zero-code-change" confidential VMs using AMD SEV-SNP and Intel TDX have dramatically broadened potential adoption compared to earlier Intel SGX models that required enclave-specific development. As attestation services mature—Intel Trust Authority, AWS KMS integrations, NVIDIA GPU attestation—the friction continues dropping, at least in theory.
Interoperability remains messy. Moving workloads between clouds while maintaining consistent confidential computing guarantees requires careful planning and, often, vendor-specific expertise. Standards bodies and industry consortiums are working on this. Enterprises today often pick one cloud's confidential computing stack and commit to it, which is exactly what cloud providers want and exactly what enterprises claim they're trying to avoid.
The post-quantum cryptography transition adds another variable that most people aren't thinking about yet. NIST finalized ML-KEM, ML-DSA, and SLH-DSA standards on August 13, 2024, and selected HQC as a backup KEM on March 11, 2025. Virtual HSM and bring-your-own-key solutions like those Enclaive offers will need post-quantum algorithm support across all major clouds to maintain long-term security guarantees. That's not a 2026 problem, but it's coming.
Sovereignty concerns are reshaping cloud architecture in Europe particularly. The EU's Cloud Services Cybersecurity Certification Scheme (EUCS) remains politically contested, with the "High+" sovereignty level debate causing delays well into 2025. Confidential computing offers a technical path to data sovereignty even when using U.S.-based cloud infrastructure—you can run workloads on AWS while keeping encryption keys in a German-controlled HSM, with cryptographic attestation proving AWS never sees the data unencrypted. Whether that satisfies regulators is a different question.
The Verdict (Such As It Is)
For CTOs and CISOs evaluating confidential computing, the question has shifted from "do we need this?" to "when and how do we deploy it?"
Regulated industries have little choice with NIS2, DORA, and AI Act requirements stacking up. AI workloads on sensitive data essentially mandate it for any serious enterprise deployment. Multi-cloud strategies benefit from unified confidential computing abstractions, assuming those abstractions actually work as advertised.
The €4.1 million Enclaive raised isn't transformative capital by venture standards. But it signals something else: investor confidence that confidential computing is moving from early adopter phase to mainstream enterprise adoption. The technology still requires expertise to deploy well. Performance trade-offs need careful consideration. Skills gaps are real—finding people who understand both cloud architecture and TEE implementation details isn't easy.
But the fundamental capability—processing sensitive data without exposing it, even to infrastructure operators—is becoming non-negotiable for an expanding set of workloads.
Perhaps the clearest sign of maturity is that hyperscale cloud providers now compete on confidential computing features rather than just price and availability zones. When Google, AWS, and Azure all race to support the latest Intel, AMD, and NVIDIA confidential hardware, and when Apple makes hardware-enforced privacy a headline feature for its AI cloud, the message is unmistakable.
The third pillar of encryption has arrived. Whether it stands up under the weight enterprises are about to put on it—that's the next chapter.
