---
title: Why do you also need confidential computing for your private datacenter?
description: Discover the importance of confidential computing for private data centers.
  Learn how confidential virtual machines (CVMs) establish a new trust boundary, protect
  against insider attacks, and mitigate vulnerabilities. Explore why data governance
  alone is not enough for security and how confidential computing can safeguard your
  sensitive data. Find out how Ubuntu, with its support for various silicon technologies,
  is an ideal choice for implementing confidential computing in your private data
  center. Learn more about Ubuntu's commitment to security and explore additional
  resources for confidential computing.
url: https://canonical.com/blog/why-do-you-also-need-confidential-computing-for-your-private-datacenter?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi "More about Ijlal Loutfi")

24 July 2023

# Why do you also need confidential computing for your private datacenter?

---

Share the article

As the adoption of confidential computing gains momentum, a question we often get asked is: why would I need confidential computing in my private data center? However, while it is true that confidential computing has often been associated with addressing security concerns [in public cloud environments](https://canonical.com/blog/confidential-computing-in-public-clouds-isolation-and-remote-attestation-explained), its value proposition extends well beyond that.

# Confidential computing threat model

To answer this question, we must first understand the underlying threat model of [confidential computing](https://canonical.com/blog/what-is-confidential-computing-a-high-level-explanation-for-cisos). In the public cloud, confidential virtual machines (CVMs) establish a new trust boundary for workloads by encrypting the workload in main memory. This prevents the host operating system, hypervisor, and DMA-capable devices from accessing the sensitive data. Even if these components were compromised, your CVM’s data would still be protected. Without confidential computing, the millions of lines of code comprising the cloud’s system software would have unrestricted access. Moreover, CVMs also protect workloads from the cloud’s operators.

# Your private data centre is not confidential

Some argue that private data centres have inherent advantages such as data governance, control, and physical security. And that is all true. Whether your data is encrypted or in plaintext, you always have the authority to decide where it resides, how it is backed up and who can access your server room.

Image by [Fabio](https://unsplash.com/@fabioha) from [Unsplash](https://unsplash.com/photos/oyXis2kALVg)

## Governance vs security

However, it is important to distinguish between data governance and security. Maintaining control over data is definitely not synonymous with security. You can control where your data lives and still have it be compromised.

In fact, your on-premises servers are still vulnerable to insiders’ attacks, and they also run the same privileged system software found in the public cloud. Therefore, they are susceptible to the same vulnerabilities and security risks.

To get a better sense of the scale of this issue, look no further than your organisation’s IT system logs, and how many CVEs you have to routinely patch for your datacenter servers. For example, If you are running a Linux host operating system, then you likely had to patch around 400 CVEs in 2022 alone, half of which had either high or critical severity.

Without confidential computing, any one of these CVEs, if exploited, could leak your data and compromise its integrity. With confidential computing  in place, you can take all this system software, which will certainly be found to be vulnerable at some point, and put it outside of your confidential workload’s trust boundary. A host OS exploit, for instance, would have absolutely no security impact on your workload.

This point about the need for confidential computing in the private datacenter is not immediately obvious to many of the customers we talk to. The confusion is also compounded by the public cloud provider’s messaging, which advertises the technology as a way to gain “the same level of security as a private datacenter”, and thus, incentivises more people to move to the public cloud.

Photo by [Dave](https://unsplash.com/@iamthedave) from [Unsplash](https://unsplash.com/photos/3lUtceZtmIs)

# Ubuntu confidential computing

To embark on this transformative security journey of making your private data center confidential, you have several options from different silicon providers to choose from. For example, on the X86 architecture, you can consider Intel SGX, Intel TDX, and AMD SEV. If you’re in the ARM ecosystem, TrustZone and the upcoming ARM CCA are available. Keystone is designed for RISC-V architectures, and Nvidia H100 is a great choice for GPUs.

Whatever your choice of the underlying silicon technology, Ubuntu is a natural choice for you to start this journey, today. Ubuntu has already pioneered supporting technologies like [AMD SEV](https://canonical.com/blog/whats-confidential-generally-available-and-open-source-its-canonical-ubuntu-22-04-on-microsoft-azure) and [Intel TDX](https://canonical.com/blog/ubuntu-confidential-vms-intel-tdx-microsoft-azure-confidential-computing) for confidential virtual machines, and is committed to driving further innovation across all layers of the confidential computing ecosystem. And with Ubuntu confidential VMs being present in all major cloud providers, you can confidently build your hybrid multi-cloud confidential computing  strategy to protect your data wherever it is deployed.

## Learn more about Ubuntu security

If you would like to know more about the Canonical approach to security at large, [contact us](https://ubuntu.com/security/contact-us).

## Additional resources

* [Ubuntu Pro | product page](https://ubuntu.com/pro)
* [Ubuntu Pro 20.04 on Azure Marketplace Microsoft Azure Marketplace](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/canonical.0001-com-ubuntu-pro-focal?tab=Overview)
* [Watch our webinar to learn more about confidential computing](https://www.brighttalk.com/webcast/6793/543562)
* [Read our blog post for “What is confidential computing? A high-level explanation for CISOs”](https://canonical.com/blog/what-is-confidential-computing-a-high-level-explanation-for-cisos)
* [Read our blog post for “Confidential computing in public clouds: isolation and remote attestation explained](https://canonical.com/blog/confidential-computing-in-public-clouds-isolation-and-remote-attestation-explained)”
* [Start creating and using Ubuntu CVMs on Azure](https://docs.microsoft.com/en-us/azure/confidential-computing/quick-create-confidential-vm-portal-amd)
* [Is Linux Secure?](https://ubuntu.com/blog/is-linux-secure)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Arduino® VENTUNO™ Q is available for pre-order with Ubuntu pre-installed](https://canonical.com/blog/arduino-ventuno-q-is-available-for-pre-order-with-ubuntu-pre-installed)

London, UK – August 25, 2026 – Following our initial collaboration announcement in March 2026, Canonical and Arduino (a subsidiary of Qualcomm Technologies, Inc.) are excited...

[Canonical](https://canonical.com/blog/author/canonical)

25 August 2026

[### Advantech AOM-2721 is now Ubuntu Certified](https://canonical.com/blog/advantech-aom-2721-ubuntu-certified)

Canonical announces that the Advantech AOM-2721 is officially joining the list of Ubuntu Certified Hardware.

[Mikhail Khazov](https://canonical.com/blog/author/khazov-m)

13 August 2026

[### Canonical integrates NVIDIA Nemotron 3.5 Lightning with Ubuntu for always-on AI agents](https://canonical.com/blog/nvidia-nemotron-3-5-lightning)

Canonical is pleased to announce that NVIDIA’s newly introduced NVIDIA Nemotron 3.5 Lightning, an open, customizable model built for always-on AI agents, is now available on...

[Canonical](https://canonical.com/blog/author/canonical)

11 August 2026
