> For the complete documentation index, see [llms.txt](https://docs.ionos.com/cloud/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ionos.com/cloud/compute-services/compute-engine/confidential-computing-vm.md).

# Confidential VM

<code class="expression">space.vars.ionos\_cloud</code> Confidential VM encrypts your VM's memory at the CPU level. Even with full administrative access to the physical host, the hypervisor sees only ciphertext.

It protects **data in use**, the third state of data that standard encryption does not cover. Encryption at rest protects stored data, and encryption in transit protects data moving over a network. Confidential VM closes the remaining gap by protecting data while it's being processed in memory.

Built for regulated industries, including financial services, healthcare, and legal that require cryptographic guarantees over contractual ones, this zero-trust architecture provides:

* **Hardware-Level Isolation:** Workloads run in a runs in a hardware-enforced [<mark style="color:blue;">Trusted Execution Environment (TEE)</mark>](https://docs.ionos.com/cloud/support/general-information/glossary-of-terms#trusted-execution-environment-tee) using [<mark style="color:blue;">AMD Secure Encrypted Virtualization with Secure Nested Paging (AMD SEV-SNP)</mark>](https://docs.ionos.com/cloud/support/general-information/glossary-of-terms#amd-secure-encrypted-virtualization-with-secure-nested-paging-amd-sev-snp) technology ensuring the hypervisor sees only ciphertext. For more information, see [<mark style="color:blue;">Use Cases</mark>](/cloud/compute-services/compute-engine/confidential-computing-vm/use-cases.md).
* **Exclusive Control:** <code class="expression">space.vars.ionos\_cloud</code> provides the physical host, hypervisor, and network. You retain complete control over your operating system, applications, encryption keys, and attestation policies.
* **Immediate Availability:** Directly available to all users in the **Frankfurt-East** `de/fra/2` data center.

{% hint style="warning" %}
**Important:**

* Confidential VMs are currently available in the **Frankfurt-East** `de/fra/2` data center. To deploy, ensure you have an active <code class="expression">space.vars.ionos\_cloud</code> account in this location.
* Because Confidential VMs are designed to completely isolate your data from the underlying infrastructure, <code class="expression">space.vars.ionos\_cloud</code> has zero visibility into your encrypted environment. Consequently, our technical support is strictly limited by the product's design, and we cannot assist with in-guest operating system, application, or key management issues.
  {% endhint %}

## Why IONOS CLOUD Confidential VM

Confidential VM replaces that trust requirement with a cryptographic proof. Using remote attestation, you can verify the TEE's exact state, including the firmware, configuration, and startup measurements, before exposing sensitive data to it. No policy document or audit report is required.

<code class="expression">space.vars.ionos\_cloud</code> provides the infrastructure layer that enables this security:

* **AMD EPYC processors with SEV-SNP:** Runs on AMD EPYC processors with SEV-SNP (a hardware security feature built for confidential workloads), providing memory isolation between VMs and the hypervisor layer.
* **Secure launch infrastructure:** Reads the launch artifacts directly from your image and starts the Confidential VM under hardware-enforced isolation, preventing patching, injection, or inspection during launch.
* **Validated image upload:** Images are verified at upload time to confirm the `LAUNCH_ARTIFACTS` partition is correctly formed before the asset is registered.

## Product Overview

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>Overview</strong></mark></td><td>Understand the architecture, trust model, and end-to-end workflow for Confidential VM.</td><td><a href="/pages/a3hyO7uqcaXjmyWrjV2c">/pages/a3hyO7uqcaXjmyWrjV2c</a></td></tr></tbody></table>

## Quick Links

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>Use Cases</strong></mark></td><td>Real-world scenarios for financial services, healthcare, legal, data marketplaces, and sovereign SaaS.</td><td><a href="/pages/4gmw8UAUdjagOSKNyot3">/pages/4gmw8UAUdjagOSKNyot3</a></td></tr><tr><td><mark style="color:blue;"><strong>API How-Tos</strong></mark></td><td>Step-by-step guides for creating and managing Confidential VMs, images, volumes, and attestation services using the <code class="expression">space.vars.ionos_cloud</code> API.</td><td><a href="/pages/zlPVsFcUJro2hloXYSic">/pages/zlPVsFcUJro2hloXYSic</a></td></tr><tr><td><mark style="color:blue;"><strong>Tutorials</strong></mark></td><td>Deploy an attested Confidential VM on <code class="expression">space.vars.ionos_cloud</code> using the SNPGuard open-source toolchain.</td><td><a href="https://docs.ionos.com/cloud/tutorials/compute-services/confidential-computing-vm/deploy-confidential-vm-with-snpguard">https://docs.ionos.com/cloud/tutorials/compute-services/confidential-computing-vm/deploy-confidential-vm-with-snpguard</a></td></tr></tbody></table>

## Developer Tools

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>IONOS CLOUD API</strong></mark></td><td>Access the CLOUD API documentation for Confidential VM.</td><td><a href="https://api.ionos.com/docs/cloud/v6/">https://api.ionos.com/docs/cloud/v6/</a></td></tr><tr><td><mark style="color:blue;"><strong>SDKs</strong></mark></td><td>Interact with the Confidential VMs using SDKs.</td><td><a href="https://docs.ionos.com/cloud/reference/software-development-kits/sdks/cloud-api-sdks">https://docs.ionos.com/cloud/reference/software-development-kits/sdks/cloud-api-sdks</a></td></tr></tbody></table>

## Frequently Asked Questions (FAQ)

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>FAQ</strong></mark></td><td>Answers to common questions about architecture, provisioning, security, billing, and troubleshooting.</td><td><a href="/pages/Eek73jhsMlyO3M8s4824">/pages/Eek73jhsMlyO3M8s4824</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ionos.com/cloud/compute-services/compute-engine/confidential-computing-vm.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
