Confidential VM

Eviden Confidential VM protects data-in-use by isolating computations inside hardware-backed secure enclaves, ensuring that even infrastructure providers cannot access sensitive data during processing.

Overview

Secure data while it is being processed

Traditional encryption protects data at rest and in transit, but sensitive information remains exposed while it is being processed. This “data-in-use” gap represents one of the most critical security challenges in modern cloud and distributed infrastructures.
Eviden Confidential VM addresses this challenge by enabling secure execution of workloads inside confidential computing environments. Data and applications run within hardware-isolated trusted execution environments (TEEs), ensuring complete confidentiality even from cloud providers, hypervisors, and system administrators.
This approach enables organizations to securely process highly sensitive data in cloud, hybrid, and distributed environments without compromising control, privacy, or sovereignty.

Data encryption - shield

Key features

What sets Confidential VM apart

Defense Digital Superiority icon

Hardware-isolated confidential computing

Execute workloads in secure, hardware-protected environments. 

  • Trusted Execution Environments (TEE) support
  • Hardware-based memory encryption
  • Isolation from host OS, hypervisor, and infrastructure
  • Protection of data-in-use during processing
  • Secure execution of sensitive applications
     
Communication Security icon

End-to-end data protection

Extend security beyond storage and transmission.

  • Protect data at rest, in transit, and in use
  • Secure full lifecycle of sensitive workloads
  • Prevent exposure during computation
  • Reduce attack surface in cloud environments
  • Consistent encryption integration
     
IS icon Trust Domain Protection

Secure cloud execution model

Run sensitive workloads in untrusted environments safely.

  • Secure execution in public and hybrid cloud
  • Cloud-provider visibility elimination on sensitive data
  • Isolation of sensitive workloads from shared infrastructure
  • Support for multi-tenant environments
  • Enables confidential cloud adoption
     
pqc implementation icon

Simplify secure operations

Operate confidential workloads without changing existing processes.

  • Use familiar Linux-based environments
  • Avoid training or workflow disruption
  • Reduce operational complexity
  • Enable fast adoption of confidential computing

     

Benefits

Compliance and security for your data in motion

E

Eliminate data-in-use exposure

Protect the most vulnerable phase of data lifecycle, processing.    

  • Secure sensitive computations in isolated environments
  • Prevent access by cloud providers or system operators
  • Reduce risk of memory-level data leakage
  • Close the data-in-use security gap
E

Enable secure cloud adoption

Move sensitive workloads to the cloud without sacrificing control.

  • Run confidential workloads in public cloud safely
  • Reduce dependency on trusted infrastructure assumptions
  • Enable secure digital transformation
  • Maintain sovereignty over sensitive data
I

Improve security without performance trade-offs

Balance strong protection with operational efficiency.

  • Hardware-accelerated isolation mechanisms
  • Optimized execution in secure environments
  • Minimal impact on workload performance
  • Suitable for high-scale processing systems 
E

Enable broad cloud and hardware flexibility

Deploy securely across modern infrastructure platforms.

  • Support for AMD, Intel, and TPM-based architectures
  • Works across multiple cloud environments
  • Future-ready with confidential GPU support
  • Ensures portability of secure workloads

Why Eviden

Why choose Confidential VM

Sovereign-grade confidential computing expertise

Eviden delivers advanced confidential computing solutions designed for environments where trust, sovereignty, and control are non-negotiable. Built for sensitive industries and regulated sectors, Confidential VM reflects deep expertise in securing data beyond traditional encryption boundaries, especially at the data-in-use layer.

 

Hardware-enforced trust without infrastructure dependency

Confidential VM relies on trusted execution technologies such as AMD SEV-SNP, Intel TDX, and TPM to enforce security directly in hardware. This eliminates the need to trust cloud providers or system operators, ensuring that sensitive workloads remain fully isolated throughout their execution lifecycle.

Seamless adoption for existing linux workloads

Unlike complex secure execution platforms that require application redesign, Eviden Confidential VM is based on a hardened Linux environment. This allows organizations to run existing applications and tools without modification, significantly reducing deployment friction and accelerating adoption of confidential computing.

 

Integrated security across the eviden ecosystem

Confidential VM is not an isolated technology, it is part of a broader Eviden Data Protection portfolio. It complements encryption, key management, and advanced cryptographic solutions, enabling end-to-end protection from data creation to storage, transmission, and execution.

FAQ

Frequently asked questions

Eviden Confidential VM is a secure execution environment that protects sensitive workloads by isolating them inside hardware-backed trusted execution environments. It ensures that data remains protected not only at rest and in transit, but also while it is being processed.

It addresses the “data-in-use” security gap, where sensitive information is exposed during computation. By isolating workloads in secure hardware environments, it prevents cloud providers, administrators, or malicious actors from accessing data while it is being processed.

Integrity is ensured through snapshot-based verification and continuous monitoring. Snapshots capture system state, boot sequence, and software configuration, while runtime checks detect unauthorized changes to maintain a trusted execution environment over time.

Eviden Confidential VM is designed to work natively with Eviden Key Management solutions (KMS). This integration enables secure handling of encryption keys within trusted execution environments, ensuring that cryptographic operations and sensitive workloads remain protected end-to-end, even in untrusted infrastructure. It strengthens overall data protection by combining secure key management with isolated execution.

Solution

Data protection for governments, companies and critical infrastructuresؘ

A secure, high-performance and verifiable virtualized environment. 

  • Familiar environment: Eviden Confidential VM is a Linux distribution, so it integrates seamlessly with your existing tools and workflows, requiring no additional learning curve.
  • Effortless cloud migration: Ideal for those moving to the cloud, it simplifies deployment without sacrificing confidentiality. You get the ease of cloud deployment with on-premises security.
  • Time savings: Automates verification processes, saving you time and reducing manual intervention.
  • Enhance security: Strengthens your security posture by ensuring that your cloud provider maintains the integrity and security of your VM. Continuous monitoring and snapshot verification guarantee that no unauthorized changes have occurred.
Eviden Confidential VM - factsheet

Discover

Other Data Protection products

Our team

Corentin Cordier

Corentin Cordier

Cybersecurity Product Owner

charles

Charles Piron

Global Sales Director

How can Eviden support you?

Speak with an expert

Our experts are here to discuss your challenges and design solutions tailored to your organization’s specific needs.