Skip to content

Architecture-first platforms for startups and growing organisations

Estimate a programme

Cybersecurity · 10 July 2026 · 6 min

Confidential computing: protecting data while it is being used

Encryption at rest and in transit is table stakes. The open question is what happens during processing.

Most security programmes still stop at the two easy states of data: stored, and moving. The third state — data in use, in memory, in a query, in a model — is where a growing class of programmes now live, especially once analytics and AI enter a startup or a bank.

Confidential computing is the set of techniques that keep that third state inside a hardware-backed enclave, so that even a privileged operator of the host cannot casually read the working set. It is not magic, and it is not always the right tool. It is the right question to ask when the workload is sensitive and the platform is not entirely yours.

When it is worth the complexity

Joint analytics across organisations, model training on regulated records, and processing in a cloud you do not administer are the obvious candidates. A four-person internal app on a locked-down server is not. We will say so.

More notes

Next step

Bring us the hard programme.

If the work needs architecture, security, and a team that will still be there at go-live, we should talk. Discovery conversations are with a senior architect — not a queue.