Fortanix Confidential Computing Manager

Prev Next

1.0 Introduction

Fortanix Confidential Computing Manager (CCM) is a centralized control plane for deploying and managing applications in Trusted Execution Environments (TEEs). CCM enables organizations to protect sensitive applications and data during execution (data-in-use) using platform-based isolation technologies such as Intel® SGX, Intel® TDX, AMD SEV-SNP, AWS Nitro Enclaves, and Microsoft Azure confidential computing offerings.

Fortanix CCM verifies platform integrity through hardware-based remote attestation and enforces policy-driven release of secrets, certificates, and cryptographic material. Sensitive assets are provisioned to workloads only after successful validation of platform and workload measurements, ensuring that they execute in an approved and trusted environment.

2.0 Why Use Fortanix CCM

Fortanix CCM enables organizations to enforce Zero Trust principles for sensitive workloads by ensuring that secrets are released only to verified and attested execution environments. CCM allows applications to run within TEEs without requiring application code modifications in most deployment models.

Key benefits include:

  • Hardware-Based Runtime Isolation: Fortanix CCM supports deployment of workloads into hardware-backed TEEs, ensuring that application memory and execution state are isolated from the host system.

  • Remote Attestation and Policy Enforcement: Fortanix CCM performs remote attestation to validate the integrity of the compute platform and workload measurements. Policies bind approved measurements to workload identities, preventing unauthorized or modified workloads from accessing protected secrets.

  • Secure Secret and Certificate Provisioning: Through integration with Fortanix Fortanix-Data-Security-Manager (DSM) ,Fortanix CCM enables secure key release, ensuring that keys, certificates, and other sensitive material are released only to verified and attested workloads.

  • Multi-Platform Support: Fortanix CCM supports confidential computing technologies across major cloud providers and hardware vendors, providing a consistent security model across heterogeneous environments.

3.0 Supported Platforms and Technologies

Fortanix Confidential Computing Manager (CCM) supports deployment and management of workloads across multiple hardware-backed confidential computing technologies and cloud environments.

Platform / Vendor

Technology or Capability Supported

Intel

Software Guard Extensions (SGX), Trust Domain Extensions (TDX - coming soon)

Amazon Web Services (AWS)

Nitro Enclaves

Microsoft Azure

Confidential Virtual Machines (CVMs), Azure Container Instances (ACI)

Advanced Micro Devices (AMD)

Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP)

Fortanix-logo

4.6

star-ratings

As of August 2025