21PacketsContact Us
21Packets Confidential Execution

Protect sensitive processing while it runs.

Run approved workloads in hardware-protected confidential environments using Intel SGX and TDX capabilities where supported, at the edge or in the cloud.

Available in 247+ Countries
450+ POPs

Operational value

A protected execution boundary inside the fabric

Confidential Execution extends the fabric beyond protected transport. Eligible Service Endlets can place sensitive code and data inside hardware-backed trusted execution environments, reducing exposure during processing while preserving network, identity, and lifecycle governance.

Approved workloadCode · keys · data in useMachine-validated stateTrusted Execution EnvironmentService Endlet identity + policyIntel SGX process isolation · Intel TDX VM isolation

Inside the capability

Release authority only to verified execution state.

A confidential Service Endlet uses hardware-backed Trusted Execution Environments to isolate approved code, protected keys, and sensitive data in use. Attestation binds identity, software measurement, feature profile, and cryptographic authority into one admission decision.

Intel SGX

Process-level protected execution for modular, containerized Service Endlets.

Intel TDX

Virtual-machine trust-domain isolation for protected cloud and on-premises VM execution.

Layered protection

Identity, attestation, encryption, monitoring, and policy surround the trusted execution boundary.

The Endlet operating model

Deploy
Validate
Admit
Activate
Connect
Observe

Why it matters

Turn capability into operating advantage.

Reduce runtime exposure

Use supported hardware-backed environments to protect selected code and data during execution.

Place protected services closer

Run approved confidential workloads in eligible cloud and edge environments near operations.

Keep execution governed

Coordinate workload placement with Endlet identity, policy, locality, and lifecycle requirements.

How it operates

A coordinated path from policy to operation.

Identify an eligible workload

Select processing that requires a protected execution boundary and supported hardware.

Apply placement policy

Choose an approved edge or cloud environment based on locality, capacity, and operating requirements.

Run as a governed Endlet

Maintain identity, connectivity, and lifecycle control around the confidential service.

Design your fabric

Start with the operating constraint you cannot compromise.

Bring your current topology, providers, workloads and continuity requirements. We’ll map the 21Packets capabilities that fit.

Book a working session