Confidential Computing Hosted Cloud Infrastructure

Dedicated bare metal servers with Intel TDX and SGX for workloads that require hardware-based isolation, memory encryption, and attestation capabilities.

Schedule Consultation

OpenMetal Hosted Private Cloud Core

Why OpenMetal for Confidential Computing?

Hardware Requirements Public Cloud Abstracts

Intel TDX and SGX require all DIMM channels fully populated (8 DIMMs per CPU socket) to enable hardware encryption. Partial configurations disable these features at the BIOS level. Production workloads need 1TB+ memory to run comfortably: TDX reserves per-page metadata (PAMT) before any Trust Domain launches, roughly 1/256 of total RAM, and SGX separately reserves Enclave Page Cache (up to 512 MB per socket). At lower total RAM, this overhead consumes a larger share before workloads even start.

On bare metal, you verify hardware configuration like processor model, memory layout, and NVMe storage before deploying workloads. Shared infrastructure abstracts these details, leaving uncertainty about whether configurations meet Intel’s requirements.

Learn More >>

Consistent Performance Without Resource Contention

Confidential computing adds overhead: memory encryption on every access, context switches for Trust Domain boundaries, attestation protocol latency. On shared infrastructure, this compounds with hypervisor delays and resource contention.

Dedicated processors eliminate noisy neighbor effects. Every core, memory channel, and I/O path belongs to your workloads. Performance remains stable for benchmarking and SLA compliance.

Learn More >>

Economics That Scale with Capacity, Not Instance Count

Fixed monthly cost per server versus premium per-instance pricing. Run multiple Trust Domains on the same hardware without additional licensing fees. Unmetered internal bandwidth prevents unexpected charges when transferring encrypted datasets between isolated workloads.


For a detailed discussion and assessment of your confidential computing needs, schedule a complimentary cloud consultation.

Request a Cloud Trial        Schedule Meeting

Built for Confidential Workloads

  • 5th and 6th Gen Intel Xeon Processors: Native TDX and SGX support with hardware-based memory encryption and Trust Domain isolation operating independently of the hypervisor, available on Emerald Rapids (v4) and Granite Rapids (v5) platforms.
  • 8 DIMMs per CPU Socket: Intel requires fully populated memory channels to enable TDX/SGX. Partial configurations leave these features disabled in BIOS.
  • 1TB+ System Memory: Sufficient capacity after accounting for TDX’s per-page metadata reserve (PAMT, roughly 1/256 of total RAM) and SGX’s Enclave Page Cache reserve (up to 512 MB per socket).
  • NVMe Storage: Low-latency I/O for loading encrypted data into Trust Domains without cloud storage tier performance variability.
  • Dual 10 Gbps Network: High bandwidth for encrypted dataset transfers between Trust Domains. Unmetered internal traffic. LACP bonding for fault tolerance.
  • Bare Metal API Access: API-driven provisioning of dedicated TDX/SGX-capable servers through OpenMetal Central.

Comparing Confidential Computing Infrastructure Options

When thinking about where to host your confidential computing workloads, it’s wise to compare the major options out there and see which offer the features and benefits you need.

Hardware Access


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Virtualized TEE instances, limited visibility into processor features and memory configuration.Complete control over hardware selection and configuration. Long procurement and setup times.Full control but requires building and maintaining infrastructure. Long procurement lead times.Direct access to Intel TDX/SGX on dedicated bare metal processors, with full BIOS control. TDX and SGX require bare metal; they are not available through OpenStack Nova or hosted private cloud deployments.

Performance


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Varies with noisy neighbor effects. Hypervisor adds latency to every memory access.Maximum performance with dedicated resources. Requires expertise to optimize configurations.Predictable within private environment. Requires capacity planning to avoid oversubscription.Consistent latency without tenant contention. Dedicated bare metal hardware eliminates multi-tenant performance impacts for TDX and SGX workloads.

Security Isolation


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Trust Domains isolated from other tenants but share physical infrastructure. Provider controls firmware.Complete physical control. All security decisions managed internally. Requires dedicated security team.Single-tenant environment. Full control over security policies. Requires expertise to configure.Dedicated hardware with no multi-tenant sharing. Hardware attestation verifies platform integrity. Available on individual bare metal servers.

Cost Structure


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Premium per-instance pricing plus licensing and egress charges. Costs spike unpredictably.High capital expenditure for hardware, datacenter space, power, cooling. Ongoing maintenance costs.Large capital investment upfront. Fixed costs regardless of utilization.Fixed monthly cost per server or Cloud Core. No per-VM licensing fees. Unmetered internal bandwidth. Egress included in allocation.

Scaling Model


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Scale by requesting more instances (availability dependent). Costs scale linearly with VMs.Scale by purchasing and installing hardware. Requires datacenter capacity planning and rack space.Scale by purchasing more hardware. Long lead times for capacity additions.Run multiple Trust Domains on the same bare metal hardware. Add capacity without procurement delays.

Management


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Managed by cloud provider. Limited customization of confidential computing features.Complete operational responsibility. Requires facilities management, hardware maintenance, and security teams.Full operational responsibility. Requires dedicated infrastructure team.Physical infrastructure managed by OpenMetal. You manage workloads and security policies on bare metal. Optional assisted management available.

Best For


Public CloudOn-PremisesTraditional Private CloudOpenMetal
Development, testing, or workloads with flexible performance requirements.Organizations with strict data sovereignty requirements, existing datacenter facilities, and large IT teams.Organizations with existing infrastructure teams and long-term capacity requirements.Production confidential workloads requiring dedicated bare metal hardware for TDX/SGX isolation and attestation.

OpenMetal Server Options for Confidential Computing

 Large v4 (Upgraded)XL v4XXL v4XL v5
ProcessorsDual Intel Xeon Gold 6526Y

32C/64T

2.8/3.9Ghz

Dual Intel Xeon Gold 6530

64C/128T

2.1/4.0Ghz

Dual Intel Xeon Gold 6530

64C/128T

2.1/4.0Ghz

Dual Intel Xeon 6530P

64C/128T

2.3/4.1Ghz

Standard Memory512GB DDR5 5200MHz1024GB DDR5 4800MHz2048GB DDR5 4800MHz1024GB DDR5 6400MHz
TDX/SGX Memory ConfigUpgrade to 1TB required (8 DIMMs per CPU)Standard 1TB config (8 DIMMs per CPU)Standard 2TB config (16 DIMMs per CPU)Standard 1TB config (8 DIMMs per CPU)
SGX/TDX ReadyWith memory upgradeOut-of-the-boxOut-of-the-boxOut-of-the-box
Storage2x 6.4TB NVMe

2x 960GB Boot Disk

4x 6.4TB NVMe

2x 960GB Boot Disk

6x 6.4TB NVMe

2x 960GB Boot Disk

4x 6.4TB NVMe

2x 960GB Boot Disk

Network20Gbps Private

4Gbps Public

20Gbps Private

6Gbps Public

20Gbps Private

10Gbps Public

20Gbps Private

6Gbps Public

Monthly Cost (2-Year)$1,009.30

(Before upgrade)

$1,708.99$2,390.11$3,318.91
Best ForProduction workloads with moderate confidential computing requirementsProduction confidential computing with multiple Trust DomainsLarge-scale deployments with memory-intensive confidential workloadsProduction confidential computing on current-generation hardware, including confidential AI inference, regulated data processing, and validator key protection workloads that benefit from higher memory bandwidth and multiple Trust Domains.

Pricing and specs are per bare metal server. Prices may change at any time and vary based on data center. For hosted private cloud options with a three-server Cloud Core running OpenStack and Ceph, review our cloud deployment calculator. Our v4 and v5 XL and XXL servers are TDX- and SGX-enabled out-of-the-box. Contact us to see which is the best option for you.