Sumber Solusi Optimal
ID
Confidential Computing: Data In-Use Security for Cloud and Enterprise AI
Insights

Confidential Computing: Data In-Use Security for Cloud and Enterprise AI

08 July 2026 ·Achmad Basjarah

Indonesia's Personal Data Protection Law and financial sector regulations are increasingly explicit: sensitive data must not be processed in uncontrolled environments — including plaintext memory in cloud shared tenancy. Data is encrypted at rest and in transit — but when processed in CPU memory, it is in plaintext and vulnerable to insider threats, hypervisor attacks, and compelled disclosure — risks that encryption at rest does not cover. Confidential Computing closes this final gap with Trusted Execution Environment (TEE) — hardware enclaves that process encrypted data even from cloud administrators. In 2026, confidential computing matures from niche to production-ready for AI, analytics, and multi-party computation in regulated sectors worldwide including Indonesia and ASEAN markets. This article covers TEE technology, enterprise use cases, vendor landscape, and confidential computing adoption roadmaps for regulated organizations in Indonesia and ASEAN. This guide helps CIOs, CISOs, and compliance officers understand when and how to deploy confidential computing practically in Indonesian cloud and on-premise environments with data protection compliance.

1. What Is Confidential Computing and TEE?

Confidential Computing is a security paradigm protecting data in use — during computation — using hardware isolation. The first most mature use cases are financial services fraud detection collaboration and healthcare research — sectors with highest regulatory pressure and adequate security budgets.

TEE (Trusted Execution Environment) is an isolated memory region in CPU/GPU accessible only to authorized code; hypervisor, host OS, and cloud provider cannot read enclave contents.

Key 2026 technologies: Intel TDX/SGX, AMD SEV-SNP, ARM CCA, and NVIDIA Confidential Computing for GPU AI workloads. Confidential Containers and Confidential VMs make adoption easier without full application rewrites.

The Confidential Computing Consortium (Linux Foundation) and standards like Remote Attestation let verifiers confirm enclaves run expected code integrity before data is sent.

2. Why Enterprises Need Confidential Computing

Adoption drivers:

  • Regulated data on public cloud — banking, healthcare, government want cloud elasticity without blind trust in providers.
  • Multi-tenant risk — SaaS shared infrastructure; TEE isolates tenant data during processing.
  • AI & sensitive inference — proprietary models and prompts; PII training data must not be visible to cloud admins.
  • Multi-party analytics — Bank A + Bank B analyze fraud patterns without exposing each other's raw data.
  • Supply chain integrity — attestation verifies runtime environment before workload starts.

Encrypt at rest + in transit is standard — confidential computing completes the triad: data protection in use.

3. Confidential Computing Use Cases in Enterprise

Confidential AI training & inference: Train LLMs or fraud models on confidential GPU VMs — datasets and weights protected from cloud operator.

Secure key management: HSM-like functionality in TEE for crypto key operations without dedicated hardware appliances.

Healthcare analytics: Aggregated multi-hospital medical record analysis with privacy preservation — HIPAA/data protection compliance.

Financial risk modeling: Portfolio data and proprietary algorithms in enclave — attestation audit for regulators.

Blockchain & digital identity: Confidential smart contract execution and verifiable credential processing.

Edge confidential computing: IoT data processed in edge TEE before uplink — minimize exposure window.

Indonesia's central bank pilots federated learning for suspicious transaction pattern detection across banks using confidential compute — enabling collaboration without raw data sharing that violates customer confidentiality.

4. Vendor and Platform Landscape in 2026

Mature ecosystem:

  • Hyperscalers — Azure Confidential Computing, AWS Nitro Enclaves, Google Confidential VMs, IBM Z Secure Execution.
  • Software frameworks — Gramine, Occlum, Enarx for porting apps to TEE; Fortanix, Anjuna for runtime abstraction.
  • Hardware — Intel 4th/5th gen Xeon with TDX, AMD EPYC SEV-SNP, NVIDIA H100 confidential mode.
  • OrchestrationKubernetes confidential node pools, confidential containers (Kata + TEE).

Vendor evaluation: attestation support, performance overhead (typically 5–15%), ecosystem tooling, regional availability (Jakarta region support), and compliance certification.

5. Architecture and Enterprise Stack Integration

Reference architecture:

  • Attestation service — verify enclave measurement before key release from KMS.
  • Confidential workload layer — VM/container on TEE-enabled nodes.
  • Key management — integration with cloud KMS, HashiCorp Vault, or HSM with key sealing to enclave.
  • Network — encrypted enclave-to-enclave channels; no plaintext egress.
  • Observability — metrics from enclave boundary; logs without exposing sensitive payload.
  • IAM & SSO — access control to deploy and manage confidential workloads via enterprise identity.

Common hybrid pattern: sensitive data in confidential enclave on-premise or sovereign cloud; non-sensitive on standard public cloud — unified management plane. Regulators increasingly ask for attestation evidence during audits — confidential computing provides cryptographic proof of execution environment integrity that traditional audit logs cannot offer.

6. Adoption Challenges and Performance Considerations

Challenges:

  • Performance overhead — enclave memory limits, encryption overhead; mitigation: workload profiling, batch processing.
  • Complexity — attestation, key ceremony, enclave debugging difficult; mitigation: managed confidential services.
  • Porting legacy apps — not all apps TEE-ready; mitigation: confidential VM lift-and-shift vs rewrite.
  • Skill gap — rare expertise; mitigation: partners, training, start with managed PaaS.
  • Cost — confidential instance premium pricing; ROI from compliance enablement and breach risk reduction.

POC must measure latency and throughput vs non-confidential baseline before production commit.

7. Adoption Roadmap and Confidential Computing Conclusion

12-month roadmap:

  1. Identify sensitive workloads (months 1–2) — data classification, regulatory mapping.
  2. Confidential VM POC (months 3–5) — one workload, attestation flow, performance benchmark.
  3. Integrate KMS & IAM (months 5–7) — key lifecycle, SSO for ops team.
  4. Production pilot (months 7–10) — one regulated use case with monitoring.
  5. Scale & multi-party (months 10–12) — expand portfolio, explore federated analytics.

Confidential computing in 2026 is a trust enabler for cloud adoption in sectors previously blocked by data sovereignty concerns. Early investors build competitive moats in regulated AI and analytics.

Bank Indonesia and ASEAN peers explore confidential computing for anti-fraud model collaboration — sharing patterns without sharing customer PII. Healthcare consortiums for epidemiology analytics with privacy preservation are emerging use cases across the region worth piloting now.

Confidential computing protects data in use in the cloud and AI era — completing encryption at rest and in transit for full triad protection. Early adopters in regulated sectors build trust advantages and enable cloud migration previously blocked by compliance concerns. POC with performance benchmarks is mandatory before production commitment. Evaluate sensitive workloads and start a confidential VM pilot for regulated use cases as the first step toward compliant hybrid cloud. PT. Sumber Solusi Optimal helps with workload assessment, TEE architecture design, and enterprise security integration. Consult our security and cloud services Contact our team for a confidential computing workshop, sensitive workload regulatory mapping, and TEE architecture consultation tailored to your regulated industry requirements today.

Related resources

Share

Services & Next Steps

Need consultation for your project?

The Sumber Solusi Optimal team is ready to help with audits, planning, and IT implementation.

Related Articles

Explore other topics relevant to your business needs.