Skip to main content
Cloud / Google Cloud / Products / Confidential Computing - Encrypted Memory

Confidential Computing - Encrypted Memory

Encrypt data during processing with AMD SEV/SEV-SNP or Intel TDX. Protect sensitive workloads from hypervisor and physical access.

Compute
Pricing Model Premium on top of the underlying Compute Engine pricing
Availability Global with EU regions
Data Sovereignty EU regions available
Reliability SLA as published by the provider, same as Compute Engine SLA

Confidential Computing extends encryption to data in use, protecting sensitive workloads from hypervisor-level and certain physical access scenarios.

What is Confidential Computing?

Traditional cloud security encrypts data at rest (storage) and in transit (network), but data must typically be decrypted for processing. Confidential Computing closes that gap: it encrypts data in use, while it sits in memory during processing.

Depending on the machine series, Confidential VMs use different hardware technologies for memory encryption: AMD SEV or the enhanced SEV-SNP on N2D instances, Intel TDX on C3 instances, and AMD SEV on C4D instances (currently in preview). Encryption keys are managed directly within the CPU.

Core Features

  • Hardware-based encryption: AMD SEV/SEV-SNP or Intel TDX encrypt VM memory at the CPU level
  • Multiple supported machine series: N2D, C3, and C4D (preview)
  • Remote attestation: Cryptographically verify the security configuration of a workload
  • Low overhead: Google states the overhead for AMD SEV ranges from negligible to minimal
  • Confidential GKE Nodes: Run Kubernetes workloads on confidential nodes
  • Confidential Space: A trusted environment for multi-party computation without exposing raw data

Typical Use Cases

Financial Services Data Processing

Banks and financial institutions process sensitive customer data, trading algorithms, and risk models. Confidential Computing adds protection for this data even during computation.

Healthcare Analytics

Healthcare organizations analyze patient data for research and clinical decision support. Confidential Computing allows processing of protected health information with an additional layer of protection against unauthorized access.

Multi-Party Data Collaboration

Multiple organizations can jointly analyze combined datasets without exposing their raw data to each other. Confidential Space provides a trusted, attested execution environment for this kind of computation.

Confidential VMs vs. Shielded VMs

FeatureShielded VMsConfidential VMs
Secure BootYesYes
vTPMYesYes
Integrity MonitoringYesYes
Memory encryptionNoYes
Supported machine seriesBroad rangeN2D, C3, C4D (preview)

Benefits

  • Additional security layer: Protection against hypervisor-level access and certain physical attack scenarios
  • No code changes: Confidential VMs work with existing applications
  • Hardware-based: AMD SEV/SEV-SNP or Intel TDX handle encryption in the CPU
  • Attestation: Cryptographic proof of the security configuration is available

Integration with innFactory

As a certified Google Cloud Partner, innFactory helps you implement Confidential Computing for sensitive workloads. We assess which applications benefit most from confidential environments, design architectures that leverage Confidential VMs and GKE, and help you demonstrate compliance with regulatory requirements.

Available Tiers & Options

Confidential GKE Nodes

Strengths
  • Kubernetes-native integration
  • Node-level encryption
  • Works with existing workloads
Considerations
  • Limited to supported node types

Confidential Space

Strengths
  • Multi-party computation
  • Attestation-based trust
  • Data clean rooms
Considerations
  • Requires workload redesign

Typical Use Cases

Processing sensitive financial data
Healthcare and patient data analytics
Multi-party data collaboration
Regulatory compliance workloads

Technical Specifications

Attestation Remote attestation
Encryption tech AMD SEV, AMD SEV-SNP, Intel TDX
Machine types N2D (SEV/SEV-SNP), C3 (Intel TDX), C4D (SEV, preview)

Frequently Asked Questions

What is Confidential Computing?

Confidential Computing encrypts data while it is being processed in memory, not just at rest or in transit. Encryption happens at the hardware level, for example via AMD SEV/SEV-SNP or Intel TDX, so that data is protected even from access at the hypervisor level or certain physical attack scenarios.

How much performance overhead does Confidential Computing add?

According to Google, the performance difference between an AMD SEV Confidential VM and a standard Compute Engine VM ranges from negligible to minimal. The exact impact depends on the workload and the chosen technology.

Do I need to modify my applications?

No. Confidential VMs are transparent to applications. You select a supported machine type and configuration, and memory encryption happens automatically at the hardware level. Existing applications run without code changes.

Which machine types support Confidential Computing?

Confidential VMs are available across several machine series, including N2D with AMD SEV or SEV-SNP, C3 with Intel TDX, and C4D with AMD SEV currently in preview. The full, current list of supported configurations is maintained in Google's documentation.

How does Confidential Computing differ from encryption at rest?

Encryption at rest protects stored data, and encryption in transit protects network data. Confidential Computing protects data during processing, in the memory where your application runs. Together, they cover the full data lifecycle.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

STACKIT

STACKIT Compute Engine - Virtual Machines

STACKIT Compute Engine: scalable VMs from German and Austrian data centers. GDPR-compliant, OpenStack-based.

Pricing Pay-as-you-go (hourly billing)
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Compute Engine GPU - GPU Instances

STACKIT Compute Engine GPU: NVIDIA H100, A100, and L40S from German data centers for AI training and inference, …

Pricing Pay-per-use (hourly billing)
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Linux Server - Managed Linux VMs

STACKIT Linux Server: VMs with Ubuntu, Debian, RHEL, Rocky Linux, AlmaLinux and openSUSE, operated in German and …

Pricing Compute Engine hourly price per vCPU/RAM …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Red Hat Enterprise Linux - RHEL VMs

STACKIT RHEL: Red Hat Enterprise Linux images from German data centers, SAP-certified. GDPR compliant.

Pricing Pay-per-use for VM and RHEL license …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Run Command - Scripts Without SSH

STACKIT Run Command enables secure remote execution of scripts on Compute Engine instances without a direct SSH …

Pricing Included in Compute Engine
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Server Agent - Manage and Monitor Servers

STACKIT Server Agent: lightweight agent for monitoring and managing STACKIT servers, the basis for Run Command and …

Pricing Pricing as published in the STACKIT …
SLA SLA as published by the provider
Compare →

60 comparable products found across other clouds.

Ready to start with Confidential Computing - Encrypted Memory?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation