Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Data & AI 3 min read8 December 2025

Confidential Computing: Protecting Cloud Data in Use

Confidential computing protects cloud data in use, closing the gap left by encryption at rest and in transit. Here's how enclaves, DSPM and AI DLP fit.

Z

Ziv

YouCC Technologies

Confidential Computing: Protecting Cloud Data While It's in Use

Most data protection strategies cover two states well: data at rest and data in transit. But confidential computing addresses the gap everyone forgets, protecting data in use, while it is actually being processed in the server's memory. To work on encrypted data, a system has to decrypt it, and that moment of exposure is the weak point this technology is built to close.

What's on offer

Confidential computing. Using hardware features such as Intel SGX or AMD SEV, confidential computing creates encrypted enclaves inside the server, a kind of digital vault. Data is processed only inside the enclave, which is fully isolated from the rest of the operating system and even from the cloud provider itself. No external party, neither an attacker nor a system administrator, can access the data while it is being processed.

Homomorphic encryption. A complementary but distinct technique, homomorphic encryption lets a user or service perform mathematical operations (such as addition or subtraction) directly on encrypted data and receive an encrypted result that decrypts to the correct value. This makes it possible to share sensitive data, for example medical records, between organizations or process it in a public cloud while preserving maximum privacy.

These two technologies solve different problems at different points in the data lifecycle, so they complement rather than replace each other.

Why it matters

Encryption alone is not enough. You also have to ensure the security around the data is configured correctly and continuously controlled. That is where DSPM (Data Security Posture Management) comes in: an automated tool that maps, discovers, and classifies every data store across the cloud, databases, and files. It identifies sensitive information, assesses the current risk to each store, and flags misconfigurations, such as a database holding PII that is exposed to the public.

Layered on top of that is a new generation of DLP that uses AI to understand the context of data, not just exact keywords. These tools recognize when sensitive information relates to something meaningful to the organization, for example an internal "Project X" mentioned in a document.

What to do

  • Evaluate confidential computing (Intel SGX / AMD SEV enclaves) for sensitive workloads that must be processed in shared or public cloud.
  • Consider homomorphic encryption for cross-organization analytics on sensitive data that should never be decrypted.
  • Deploy DSPM to continuously discover and classify sensitive data and catch risky misconfigurations.
  • Adopt AI-driven DLP to detect contextual data exposure that keyword-based tools miss.

Shared from the CSC - Cloud Security Community community, by Ziv.

Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community