Most security programmes still stop at the two easy states of data: stored, and moving. The third state — data in use, in memory, in a query, in a model — is where a growing class of programmes now live, especially once analytics and AI enter a startup or a bank.
Confidential computing is the set of techniques that keep that third state inside a hardware-backed enclave, so that even a privileged operator of the host cannot casually read the working set. It is not magic, and it is not always the right tool. It is the right question to ask when the workload is sensitive and the platform is not entirely yours.
When it is worth the complexity
Joint analytics across organisations, model training on regulated records, and processing in a cloud you do not administer are the obvious candidates. A four-person internal app on a locked-down server is not. We will say so.
Related practices
