---
title: Data Sovereignty with Confidential Computing and Networking
description: Explore how confidential computing and networking support data sovereignty while protecting sensitive workloads in public cloud environments.
image: https://arqitgroup.com/hubfs/intel%20arqit.jpg
---

[Skip to content](https://arqitgroup.com/resources/data-sovereignty-with-confidential-computing-and-networking#main-content)

[ Close ](https://arqitgroup.com/resources/data-sovereignty-with-confidential-computing-and-networking#)

- Solutions 
    - [PQC Migration](https://arqitgroup.com/products/encryption-intelligence)
    - [Key Sovereignty ](https://arqitgroup.com/products/ska-platform) 
          - [SKA Edge Controller](https://arqitgroup.com/products/ska-ec)
          - [SKA Central Controller](https://arqitgroup.com/products/ska-cc)
    - [Network Security](https://arqitgroup.com/products/networksecure)
- Sectors 
    - [Telecoms](https://arqitgroup.com/sectors/telecoms)
    - [Defense](https://arqitgroup.com/sectors/defense)
    - [Govt & CNI](https://arqitgroup.com/sectors/govt-cni)
    - [U.S Markets](https://arqitgroup.com/mission-readiness)
- [Resources](https://arqitgroup.com/resource) 
    - [Case Studies](https://arqitgroup.com/resources/tag/case-studies)
    - [Product sheets](https://arqitgroup.com/resources/tag/product-sheets)
    - [White Papers](https://arqitgroup.com/resources/tag/white-papers)
    - [Arqit Terms](https://arqitgroup.com/resources/tag/legal)
    - [Blog](https://arqitgroup.com/resources/blog)
- About 
    - [Our Approach](https://arqitgroup.com/company/our-approach) 
          - [Strong](https://arqitgroup.com/company/our-approach#strong)
          - [Simple](https://arqitgroup.com/company/our-approach#simple)
          - [Scalable](https://arqitgroup.com/company/our-approach#scalable)
          - [Standards-based](https://arqitgroup.com/company/our-approach#standards-based)
    - Our Technology 
          - [Simplicity](https://arqitgroup.com/company/simplicity)
          - [Agility](https://arqitgroup.com/company/agility)
          - [Trust](https://arqitgroup.com/company/trust)
          - [Compliance](https://arqitgroup.com/company/compliance)
    - [Company](https://arqitgroup.com/who-we-are) 
          - [Leadership](https://arqitgroup.com/who-we-are#leadership)
          - [Awards](https://arqitgroup.com/who-we-are#awards)
    - [Partners](https://arqitgroup.com/partners/partners)
    - [Press](https://arqitgroup.com/resources/tag/press-releases)
    - [Careers](https://arqitgroup.com/careers)
    - [Investors](https://ir.arqit.uk/)
- [Book a demo](https://arqitgroup.com/demo/demo-hub)

[![Arqit_Logo_Midnight_Citrus_Horizontal](https://arqitgroup.com/hubfs/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_Midnight_Citrus_Horizontal.svg)](https://arqitgroup.com/)[![Arqit_Logo_Midnight_Citrus_Horizontal](https://arqitgroup.com/hubfs/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_Midnight_Citrus_Horizontal.svg)](https://arqitgroup.com/)

- Solutions 
    - [PQC Migration](https://arqitgroup.com/products/encryption-intelligence)
    - [Key Sovereignty ](https://arqitgroup.com/products/ska-platform) 
          - [SKA Edge Controller](https://arqitgroup.com/products/ska-ec)
          - [SKA Central Controller](https://arqitgroup.com/products/ska-cc)
    - [Network Security](https://arqitgroup.com/products/networksecure)
- Sectors 
    - [Telecoms](https://arqitgroup.com/sectors/telecoms)
    - [Defense](https://arqitgroup.com/sectors/defense)
    - [Govt & CNI](https://arqitgroup.com/sectors/govt-cni)
    - [U.S Markets](https://arqitgroup.com/mission-readiness)
- [Resources](https://arqitgroup.com/resource) 
    - [Case Studies](https://arqitgroup.com/resources/tag/case-studies)
    - [Product sheets](https://arqitgroup.com/resources/tag/product-sheets)
    - [White Papers](https://arqitgroup.com/resources/tag/white-papers)
    - [Arqit Terms](https://arqitgroup.com/resources/tag/legal)
    - [Blog](https://arqitgroup.com/resources/blog)
- About 
    - [Our Approach](https://arqitgroup.com/company/our-approach) 
          - [Strong](https://arqitgroup.com/company/our-approach#strong)
          - [Simple](https://arqitgroup.com/company/our-approach#simple)
          - [Scalable](https://arqitgroup.com/company/our-approach#scalable)
          - [Standards-based](https://arqitgroup.com/company/our-approach#standards-based)
    - Our Technology 
          - [Simplicity](https://arqitgroup.com/company/simplicity)
          - [Agility](https://arqitgroup.com/company/agility)
          - [Trust](https://arqitgroup.com/company/trust)
          - [Compliance](https://arqitgroup.com/company/compliance)
    - [Company](https://arqitgroup.com/who-we-are) 
          - [Leadership](https://arqitgroup.com/who-we-are#leadership)
          - [Awards](https://arqitgroup.com/who-we-are#awards)
    - [Partners](https://arqitgroup.com/partners/partners)
    - [Press](https://arqitgroup.com/resources/tag/press-releases)
    - [Careers](https://arqitgroup.com/careers)
    - [Investors](https://ir.arqit.uk/)
- [Book a demo](https://arqitgroup.com/demo/demo-hub)

<https://arqitgroup.com/resources/data-sovereignty-with-confidential-computing-and-networking#>

![](https://arqitgroup.com/hs-fs/hubfs/intel%20arqit.jpg?width=300&name=intel%20arqit.jpg)

[Arqit](https://arqitgroup.com/resources/author/arqit)Apr 28, 2025 12:17:44 PM1 min read

# Data Sovereignty with Confidential Computing and Networking

#### Arqit NetworkSecure™ uses Intel® Trust Domain Extensions (Intel® TDX) to help increase confidentiality of both data in use and data in transit for sensitive workloads deployed across hosted environments.

Highly sensitive workloads require greater security controls, particularly when running on shared or managed infrastructure. Intel TDX creates a Trust Domain (TD), designed to encrypt and isolate Virtual Machines (VMs) from the underlying physical hardware, operating system, hypervisor, and other VMs. This robust security boundary increases VM security, even when attackers compromise the physical host. However, data entering or leaving the TD may still be at risk as it passes through a network interface or system bus. Arqit’s quantum-safe Symmetric Key Agreement Platform (SKA-Platform™) allows services running within a TD to create symmetric encryption keys that are considered safe to attack, even from quantum computers. This ensures data is encrypted securely before it leaves the TD boundary. The data can be shared with other TDs running on the same or different hosts with full end-to-end encryption. Encryption keys are ephemeral and never shared outside of the TD.

Together, Arqit and Intel provide a holistic solution designed to protect sensitive workloads and their data from external attacks. It’s especially well-suited for shared or managed infrastructure outside of the customer’s direct control, like the public cloud, and highly sensitive applications such as AI or user data processing. Not only does this protect the customer’s data, but it also benefits the hosting service provider as they can process and transmit data without any visibility, granting full sovereignty and reducing liability.

[Download](https://arqitgroup.com/hubfs/Website/Resource%20Library/TDX%20Data%20Sovereignty%20with%20Confidential%20Computing%20and%20Networking.pdf)

## RELATED RESOURCES

[![Arqit_Logo_White_Citrus_Horizontal](https://7543877.fs1.hubspotusercontent-na1.net/hubfs/7543877/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_White_Citrus_Horizontal.svg) ](https://arqitgroup.com/)

<https://www.linkedin.com/company/arqit>

- [Get in Touch](https://arqitgroup.com/contact-us)

![NQA_ISO27001_CMYK_UKAS (1)](https://arqitgroup.com/hubfs/NQA_ISO27001_CMYK_UKAS%20(1).webp)

![FIPS 140-3 validated product logo image in color (1)](https://arqitgroup.com/hubfs/FIPS%20140-3%20validated%20product%20logo%20image%20in%20color%20(1).webp)

[![Consultancy_Post-Quantum Cryptography (Discovery and Migration Planning) (1)](https://arqitgroup.com/hubfs/Consultancy_Post-Quantum%20Cryptography%20(Discovery%20and%20Migration%20Planning)%20(1).webp) ](https://www.ncsc.gov.uk/schemes/assured-cyber-security-consultancy/pqc-pilot)

[![Cyber Essentials Badge (1)](https://arqitgroup.com/hubfs/Cyber%20Essentials%20Badge%20(1).webp) ](https://www.ncsc.gov.uk/cyberessentials/overview)

[![IDC-Innovator-2024-badge-blue-withlabel (1)](https://arqitgroup.com/hubfs/IDC-Innovator-2024-badge-blue-withlabel%20(1).webp) ](https://arqitgroup.com/who-we-are?hsLang=en#awards)

[![GLOMO (1)](https://arqitgroup.com/hubfs/GLOMO%20(1).webp) ](https://www.mwcbarcelona.com/articles/2024-glomo-award-winners-unveiled-at-mwc-barcelona)

[![e_sig_the_cyber_defence_product_of_the_year_33 (1)](https://arqitgroup.com/hubfs/e_sig_the_cyber_defence_product_of_the_year_33%20(1).webp) ](https://thenationalcyberawards.org/2024-winners/)

[![CTGSEA25-Winner+Cat_Endpoint Security Solution Award (1)](https://arqitgroup.com/hubfs/CTGSEA25-Winner+Cat_Endpoint%20Security%20Solution%20Award%20(1).webp) ](https://arqitgroup.com/who-we-are?hsLang=en#awards)

[![NaaS Innovation 1080x1080 (1) (1)](https://arqitgroup.com/hubfs/NaaS%20Innovation%201080x1080%20(1)%20(1).webp) ](https://www.mplify.net/news/mplify-names-winners-of-the-2025-naas-excellence-awards/)

All rights reserved

- [Terms of Use](https://arqitgroup.com/resources/arqit-terms)
- [Privacy Policy](https://arqitgroup.com/privacy-policy)
- [Visit the Arqit website](https://arqitgroup.com)

<https://arqitgroup.com/resources/data-sovereignty-with-confidential-computing-and-networking#>

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "",
    "addressLocality" : "London",
    "addressRegion" : "United Kingdom",
    "postalCode" : "SW1H 0BF",
    "streetAddress" : "1st Floor, 3 Orchard Place"
  },
  "knowsLanguage" : "en",
  "name" : "Arqit Quantum Inc",
  "url" : "https://arqitgroup.com/resources/data-sovereignty-with-confidential-computing-and-networking"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Arqit",
    "url" : "https://arqitgroup.com/resources/author/arqit"
  },
  "dateModified" : "2026-07-24T14:38:17.226Z",
  "datePublished" : "2025-04-28T11:17:44.000Z",
  "headline" : "Data Sovereignty with Confidential Computing and Networking",
  "image" : [ "https://arqitgroup.com/hubfs/intel%20arqit.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://arqitgroup.com/resources/data-sovereignty-with-confidential-computing-and-networking",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://arqitgroup.com/hubfs/Arqit_Logo_Horizontal_Night.png"
    },
    "name" : "Arqit"
  }
}
```

```json
{
      "@context": "https://schema.org",
      "@type": "BlogPosting",
      "headline": "Blog: Changing the rules of trust in cloud computing",
      "image": [
        "https://arqitgroup.com/hs-fs/hubfs/NetworkSecure%20TDX%20architecture.png?width=3350&height=1342&name=NetworkSecure%20TDX%20architecture.png",
"https://7543877.fs1.hubspotusercontent-na1.net/hub/7543877/hubfs/TDX.png?width=2000&name=TDX.png"
     ],
      "datePublished": "2025-05-01T12:56:37.000Z",
      "dateModified": "2025-06-13T12:56:37.000Z",
      "text": "In this blog, our Deputy CTO, Michael Murphy explains how the joint solution between Intel Corporation Trust Domain Extensions (Intel TDX) and Arqit NetworkSecure™  is helping organisations overcome long-standing cloud security challenges. These challenges include: gaining full control over encryption keys, securing data in transit, enabling trusted collaboration, and reducing the cost and complexity of additional hardware.
Figure 1: Example of Arqit NetworkSecure running inside a Trust Domain (enclave) provides quantum-safe symmetric keys to a strongSwan VPN client. The keys are ingested by the client and used to secure the IPsec tunnel between the clients. Data is protected from the physical host both in use inside the TD and while in transit between environments.

For customers, this means sensitive data in workloads like AI or financial systems is not only protected in use on the host, but also in transit as it’s distributed to other services. This is particularly relevant for industries like finance, healthcare, or government that handle regulated customer data but who want the flexibility and power of public cloud. It also reduces the liability of the cloud provider itself by removing liability associated with data exfiltration or host misconfiguration.

Beyond data-in-use encryption, Intel TDX also provides remote attestation capabilities, meaning workloads can prove they are running within an enclave and confirm other hosts are also using Intel TDX. This reduces the chance of man-in-the-middle attacks or data poisoning by rogue endpoints and ensures that workloads never share data with environments without Confidential Computing. Arqit’s own symmetric- based active authentication service augments the PKC-based approach offered by attestation services, providing quantum-secure authentication in addition to data security.

Attestation can also be used to verify that NetworkSecure is running unmodified by a third party, and that information could be shared with other TDs through the quantum-safe data link. This removes the risk of tampering and ensures the integrity of Arqit’s software running inside the enclave.

Key benefits for customers:

Data-in-use and data-in-transit protection for highly sensitive workloads, especially on shared infrastructure.
Simple to use and deploy
Independent attestation provided by Intel Tiber Trust Authority
Encryption keys are never visible to the users outside the enclave, maintaining full data confidentiality and ownership
For hosting providers, prevent inadvertent data leaks, reduce liability, and offer your customers quantum-safe data security with minimal customer configuration.

We believe the combination of quantum-safe data-in-transit security offered by Arqit combined with the confidential computing capabilities of Intel TDX provides a powerful, holistic solution to data security.

Read more about the solution here.
 
Highly sensitive workloads require greater security controls, particularly when running on shared or managed infrastructure. One solution is confidential computing where workloads run inside an encrypted enclave virtual machine (VM) isolated from the underlying physical hardware, operating system, hypervisor, and other VMs using technology such as Intel TDX. This robust security boundary increases VM security, protecting sensitive data even if attackers compromise the physical host.

However, data entering or leaving the enclave may still be at risk as it passes through a network interface or system bus to other services. Arqit’s quantum-safe Symmetric Key Agreement Platform (SKA-Platform™) allows services running within an enclave to create symmetric encryption keys that cannot be cracked, even by a quantum computer. This ensures data is encrypted securely before it leaves the enclave boundary. The data can be shared with other enclaves running on the same or different hosts with full end-to-end encryption. Encryption keys are ephemeral and never shared outside of the enclave.
Michael Murphy, Deputy CTO
Dr Michael Murphy is a seasoned product and technology expert with over a decade of experience in tech startups. As Deputy CTO at Arqit he leads the technology strategy for its range of post-quantum security solutions. He holds a PhD in quantum computing and has driven innovation in cybersecurity, AI, and financial services.",
      "author": {
         "@type": "Person",
         "name": "Arqit",
         "sameAs": "http://arqitgroup.com/"
     }
    }
```