> Markdown version of [/videos/1565-safeguarding-sensitive-data-access-at-scale-with-privacy-enhancing-technologies?t=1101](https://www.wearedevelopers.com/videos/1565-safeguarding-sensitive-data-access-at-scale-with-privacy-enhancing-technologies?t=1101). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Safeguarding Sensitive Data Access At Scale with Privacy-Enhancing Technologies Are sprawling microservices exposing your sensitive data? Discover how combining end-to-end pseudonymization with Trusted Execution Environments lets you mathematically prove your security posture at scale. - **Speakers:** [Mingshen Sun](https://www.wearedevelopers.com/@mingshen-sun) - **Event:** World Congress 2025 - **Published:** August 20, 2025 - **Duration:** 23:52 - **URL:** https://www.wearedevelopers.com/videos/1565-safeguarding-sensitive-data-access-at-scale-with-privacy-enhancing-technologies ## Summary Modern microservice architectures offer exceptional agility and scalability, but they also allow data to flow freely across loosely coupled backend systems. This dynamic sprawl creates significant challenges for enforcing purpose limitation and safeguarding sensitive data at scale. To address these vulnerabilities without compromising system flexibility, organizations are increasingly adopting Privacy-Enhancing Technologies (PETs), with a primary focus on Confidential Computing and Trusted Execution Environments (TEEs) designed to protect data while it is actively in use. An innovative architectural approach to this challenge combines serverless computing with end-to-end pseudonymization. By isolating the specific logic that processes sensitive data within serverless compute engines protected by TEEs, engineering teams can dramatically minimize the code surface area that requires rigorous security review. Simultaneously, implementing system-wide pseudonymization ensures that non-relevant microservices only handle anonymized data, strictly enforcing the principle that services should only access the data required for their designated purpose. The cornerstone of this secure architecture is its capacity for "verifiable transparency." By integrating Key Management Systems (KMS) with a hardware-backed remote attestation service, the system effectively acts as a highly secure, hardware-endorsed IAM layer. Decryption keys are only granted to workloads that can provide cryptographic, hardware-generated proof of their identity and integrity. This capability empowers organizations to mathematically prove to third-party auditors that strict data protection protocols and access controls are actively enforced across complex, large-scale backend environments. **Keywords:** privacy-enhancing technologies, confidential computing, trusted execution environments, microservice data protection, verifiable software transparency, fine-grained purpose limitation, hardware-backed remote attestation, serverless environment isolation, sensitive data processing, data pseudonymization techniques, cryptographic workload identity, KMS integration, third-party security auditing, data in use protection, hardware attestation reports ## Chapters 1. **Data exposure risks in flexible microservice architectures** (00:00) — Free-flowing microservice data creates significant challenges for limiting sensitive information exposure to irrelevant services. 1. **Hardware isolation through privacy enhancing technologies** (04:58) — Trusted execution environments and secure enclaves provide hardware-level protection for sensitive data during active processing. 1. **Scaling confidential computing across complex deployments** (10:00) — Enforcing fine-grained purpose limitation and providing verifiable privacy proofs become highly difficult within distributed backend systems. 1. **Isolating sensitive processing using serverless architectures** (13:46) — Moving specific code that handles sensitive data into hardware-protected serverless engines drastically reduces the necessary review scope. 1. **Securing data pipelines via pseudonymization and hardware attestation** (16:00) — Combining end-to-end encryption with hardware-attested reports ensures non-relevant microservices only access pseudonymized payloads. 1. **Integrating key management and identity attestation services** (18:21) — Replacing traditional identity access management with hardware-backed attestation allows for verifiable third-party management of encrypted data keys. 1. **Summarizing verifiable data protection in distributed systems** (21:26) — Combining serverless isolation, secure enclaves, and cryptographic proofs creates adaptable yet secure architectures for handling sensitive data. ## Related Moments - [Securing data in use with confidential cloud computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) (from "Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing") - [Utilizing trusted execution environments for data protection](https://www.wearedevelopers.com/videos/100013-building-trust-through-private-and-verifiable-ai) (from "Building Trust Through Private and Verifiable AI") - [Advancing confidential computing with open source multi-way collaboration](https://www.wearedevelopers.com/videos/1036-tiktok-s-privacy-innovation) (from "TikTok's Privacy Innovation") - [Protecting infrastructure with the shared responsibility model](https://www.wearedevelopers.com/videos/691-building-well-architected-applications) (from "Building Well-Architected applications") - [Blending trusted hardware with future security strategies](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) (from "This Machine Ends Data Breaches") - [Hardware-based trusted execution environments for confidential computing](https://www.wearedevelopers.com/videos/100129-building-securing-and-governing-ai-infrastructure-in-the-era-of-agentic-ai) (from "Building, securing and governing AI infrastructure in the Era of Agentic AI") ## Related Articles - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) ## Related Jobs - [Identity, Defense & Resilience - Network Security - Manager](https://www.wearedevelopers.com/jobs/ext/2470336-identity-defense-resilience-network-security-manager) at **PwC** - [Principal Solutions Architect, Professional Services](https://www.wearedevelopers.com/jobs/ext/2948701-principal-solutions-architect-professional-services) at **Docker, Inc.** - [Identity, Defense & Resilience - Network Security - Manager](https://www.wearedevelopers.com/jobs/ext/2467836-identity-defense-resilience-network-security-manager) at **PwC** - [Principal Solutions Architect, Professional Services](https://www.wearedevelopers.com/jobs/ext/2759779-principal-solutions-architect-professional-services) at **Docker, Inc.** - [Principal Solutions Architect, Professional Services](https://www.wearedevelopers.com/jobs/ext/2747554-principal-solutions-architect-professional-services) at **Docker, Inc.** - [Identity, Defense & Resilience - Network Security - Manager](https://www.wearedevelopers.com/jobs/ext/2567532-identity-defense-resilience-network-security-manager) at **PwC**