What Is Confidential Computing?

Confidential computing protects data while it is being used, not just stored or transmitted, by running the computation inside a trusted execution environment — a hardware-isolated enclave whose memory even the host operating system cannot read. It lets a party process data it is not allowed to see, and prove to a remote party what code ran, through attestation. For agents, it is one way to handle a counterparty’s data without being trusted with it.

Protects
Data in use, inside a hardware enclave
Mechanism
A trusted execution environment (TEE)
Proof
Remote attestation of the code that ran

The third state of data

Encryption at rest and in transit protect data when it is stored and when it moves; both leave it exposed in memory at the moment it is processed. A TEE closes that gap by isolating the computation in hardware, so the enclave can work on sensitive data while the machine around it, and its operator, cannot observe it.

Attestation is the half that makes it useful across organisations: a remote party can verify which code the enclave is running before sending it data — a hardware root of trust that pairs naturally with the estate’s cryptographic one.

Related standards

Confidential Computing Consortium

Questions

Is confidential computing the same as a zero-knowledge proof?

No — they solve overlapping problems differently. See the comparison: one isolates computation in hardware, the other proves a statement with mathematics.

Does it require trusting the hardware vendor?

Yes — the root of trust is the chip and its attestation, which is the main difference from a purely cryptographic approach.

Keep reading

related
What Is a Zero-Knowledge Proof?
related
TEEs vs Zero-Knowledge Proofs: Two Roads to Privacy
related
What Is Agent Attestation?
related
What Is a Merkle Tree?
referenced by
Custodial vs Non-Custodial: Who Holds the Keys?
referenced by
Symmetric vs Asymmetric Encryption: What’s the Difference?
Trust & the Record
Verify, Don’t Trust: Verification for AI Agents
Trust & the Record
Provenance for Autonomous Actions
Trust & the Record
How Is AI Agent Reputation Earned and Verified?
Trust & the Record
Zero-Trust Architecture for AI Agents
Trust & the Record
What Is a Trust Graph for Agents?
Trust & the Record
What Is a zk-Rollup?
Trust & the Record
What Is a Blockchain Oracle?
Trust & the Record
zk-Rollup vs Optimistic Rollup: What’s the Difference?
Trust & the Record
What Is Public-Key Cryptography?
Trust & the Record
What Is a Digital Signature?
Trust & the Record
What Is a Cryptographic Hash Function?
Trust & the Record
What Is Mutual TLS (mTLS)?
Trust & the Record
What Is a Sybil Attack?
Trust & the Record
What Is Certificate Transparency?
Trust & the Record
Hashing vs Encryption: What’s the Difference?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.