For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features and Benefits

IONOS CLOUD Confidential VMs provide hardware-enforced memory encryption, cryptographic attestation, and EU data sovereignty, without requiring trust in the cloud provider.

Features

  • Hardware-enforced memory encryption: AMD SEV-SNP CPU encrypts all VM memory with Advanced Encryption Standard (AES) using unique encryption keys that never leave the CPU or reach the hypervisor or administrators.

  • Cryptographic attestation: Verify firmware, kernel, and configuration measurements with signed attestation reports before releasing secrets or encryption keys to VMs.

  • Secure memory protection: AMD Secure Nested Paging detects and blocks hypervisor attempts to replay, remap, or modify VM memory pages.

  • Data sovereignty: Runs exclusively in IONOS CLOUD EU data centers; IONOS CLOUD holds no encryption keys, technically excluding the provider from key management.

  • Firmware transparency: SLSA Level 2 provenance on OVMF firmware builds proves binaries were produced by public CI pipeline with immutable Sigstore Rekor records.

Benefits

  • No provider trust required: Security does not depend on IONOS CLOUD policies, contracts, or audits. The CPU enforces the boundary, removing the provider as a point of failure in your trust model.

  • Verifiable compliance posture: Hardware isolation and cryptographic attestation produce verifiable technical evidence for regulatory audits, replacing policy assertions with cryptographic proof.

  • Runtime tamper detection: Any modification to your software stack, whether from a misconfiguration or supply chain compromise, results in attestation failure before secrets are released, ensuring you know exactly what is running in your environment.

  • Independent platform verification: Firmware provenance is publicly logged and verifiable by anyone. You can verify IONOS CLOUD's claims about the platform using any attestation service. For more information, see SNPGuard.

Last updated

Was this helpful?