> Markdown version of [/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing?t=187](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing?t=187). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # An alternative approach to digital sovereignty: Confidential Computing Who can access your data while it processes in RAM? Discover how confidential computing leverages hardware-based isolation to physically block hypervisor-level extraction and secure your digital sovereignty. - **Speakers:** [Mike Bursell](https://www.wearedevelopers.com/@mike-bursell) - **Event:** World Congress 2026 Europe - **Published:** July 9, 2026 - **Duration:** 26:53 - **URL:** https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing ## Summary Achieving true digital sovereignty requires moving beyond traditional legal contracts and checkbox compliance to guarantee that sensitive information is systematically protected from unauthorized access. While modern organizations routinely encrypt data at rest and in transit, data "in use" remains fundamentally exposed to the host operating system, hypervisors, and cloud administrators during active processing. This systemic vulnerability undermines the zero-trust architecture needed to safeguard national, organizational, and personal boundaries against both external breaches and insider infrastructure read-access risks. Confidential computing addresses this security gap by utilizing hardware-based Trusted Execution Environments (TEEs) to cryptographically isolate applications and data while they are actively mapped in RAM. By shifting the root of trust away from the cloud vendor and host OS directly to the silicon layer—natively supported by modern AMD, Intel, Arm, and Nvidia processors—organizations can physically block hypervisor-level data extraction. A defining feature of this methodology is "remote attestation," a process allowing engineers and auditors to verify hardware-backed cryptographic signatures, definitively proving that uncompromised code and intact data sets are running securely out of sight from infrastructure operators. This silicon-level trusted isolation unlocks highly sought-after enterprise capabilities previously deemed too risky for the public cloud. Businesses can spin up "confidential clean rooms" to collaborate on sensitive data models across independent banking or healthcare entities without exposing raw information to counterparties. Furthermore, it enables verifiable digital supply chain provenance—ensuring SBOMs are constructed in pristine conditions—and secures decentralized compute architectures where users retain total custody of their encryption keys globally. Now operating with single-digit performance variance thanks to advanced GPU integration, hardware-backed confidential computing has transitioned from an experimental safeguard to an enterprise necessity. **Keywords:** digital sovereignty, confidential computing, trusted execution environments, data in use encryption, remote attestation, hardware-based isolation, zero-trust architecture, confidential clean rooms, hardware root of trust, cryptographic proofs, decentralized compute, SBOM provenance, cloud data security, hypervisor vulnerabilities, regulatory compliance, multi-party data collaboration ## Chapters 1. **Understanding national, organizational, and personal digital sovereignty** (00:03) — Defining digital sovereignty across national, corporate, and individual levels highlights the complexities of modern data protection. 1. **Moving from legal contracts to technical hardware guarantees** (01:37) — Replacing paper agreements with hardware-backed cryptography prevents external entities from accessing highly controlled environments. 1. **Proving regulatory compliance to auditors and chief officers** (03:07) — Demonstrating technical protections against fast-moving cyber threats meets the strict requirements of regulatory bodies. 1. **Protecting data in use to prevent administrative exposure** (04:06) — Encrypting data directly in system RAM mitigates risks posed by privileged users traversing virtualized cloud environments. 1. **Creating trusted execution environments using specialized computing hardware** (05:40) — Utilizing widely available CPUs and GPUs to build trusted execution environments isolates memory pages from hypervisor oversight. 1. **Isolating agentic artificial intelligence workloads from unauthorized access** (07:30) — Securing sensitive model data and prompts guards against internal administrators and unexpected external breaches. 1. **Providing confidentiality, integrity, and remote attestation validation** (08:50) — Cryptographic signatures verify software integrity before execution to ensure remote environments contain exactly the correct application. 1. **Transitioning trust from software policies to central processors** (12:15) — Moving the root of trust away from cloud providers and host operating systems establishes stronger isolation controls. 1. **Utilizing third-party services for unbiased attestation verification** (14:11) — Employing independent attestation checks eliminates the conflict of interest of relying on internal cloud service reports. 1. **Meeting national sovereignty requirements using remote execution environments** (15:18) — Using isolated instances in foreign jurisdictions enables the safe processing of region-locked sovereign data. 1. **Facilitating safe data collaboration via confidential clean rooms** (16:51) — Clean environments permit cross-institutional data analysis without exposing unencrypted raw datasets to competing parties. 1. **Securing digital supply chains using isolated build environments** (17:59) — Generating provenance proofs natively inside secure hardware guarantees the integrity of continuous software bills of materials. 1. **Enabling decentralized computing operations with hardware-level trust** (19:15) — Cryptographically assured deployments empower organizations to distribute computing workloads without exposing private administration keys. 1. **Fostering open-source collaboration for secure computational frameworks** (20:19) — Promoting open-source integration standardizes the implementation of secure computational frameworks across multiple diverse industries. 1. **Addressing availability, latency overheads, and hardware trust concerns** (21:35) — Exploring infrastructure uptime risks, single-digit processing trade-offs, and strategies to secure native encryption keys. ## Related Moments - [Hardware-based trusted execution environments for confidential computing](https://www.wearedevelopers.com/videos/100129-building-securing-and-governing-ai-infrastructure-in-the-era-of-agentic-ai) (from "Building, securing and governing AI infrastructure in the Era of Agentic AI") - [Advancing confidential computing with open source multi-way collaboration](https://www.wearedevelopers.com/videos/1036-tiktok-s-privacy-innovation) (from "TikTok's Privacy Innovation") - [Securing data in use with confidential cloud computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) (from "Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing") - [Utilizing trusted execution environments for data protection](https://www.wearedevelopers.com/videos/100013-building-trust-through-private-and-verifiable-ai) (from "Building Trust Through Private and Verifiable AI") - [Defining trusted execution environments and confidential computing](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) (from "This Machine Ends Data Breaches") - [Defining digital sovereignty and a four-part solution framework](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) (from "Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing") ## Related Articles - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [How we Build The Software of Tomorrow](https://www.wearedevelopers.com/magazine/120-how-we-build-the-software-of-tomorrow) ## Related Jobs - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Cloud Foundations Team](https://www.wearedevelopers.com/jobs/ext/1483289-cloud-foundations-team) at **GitHub** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Senior Software Engineer, Enterprise Products](https://www.wearedevelopers.com/jobs/ext/1841248-senior-software-engineer-enterprise-products) at **GitHub** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub**