---
title: "Fortanix Confidential Computing Manager (ccm.fortanix.com)"
slug: "fortanix-confidential-computing-manager-standalone"
updated: 2026-06-06T05:21:34Z
published: 2026-06-26T16:34:26Z
canonical: "support.fortanix.com/fortanix-confidential-computing-manager-standalone"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix Confidential Computing Manager (ccm.fortanix.com)

## 1.0 Introduction

Fortanix Confidential Computing Manager (CCM) is a centralized control plane for deploying and managing applications in Trusted Execution Environments (TEEs). CCM enables organizations to protect sensitive applications and data during execution (data-in-use) using platform-based isolation technologies such as Intel® SGX, Intel® TDX, AMD SEV-SNP, AWS Nitro Enclaves, and Microsoft Azure confidential computing offerings.

Fortanix CCM verifies platform integrity through hardware-based remote attestation and enforces policy-driven release of secrets, certificates, and cryptographic material. Sensitive assets are provisioned to workloads only after successful validation of platform and workload measurements, ensuring that they execute in an approved and trusted environment.

## 2.0 Why Use Fortanix CCM

Fortanix CCM enables organizations to enforce Zero Trust principles for sensitive workloads by ensuring that secrets are released only to verified and attested execution environments. CCM allows applications to run within TEEs without requiring application code modifications in most deployment models.

Key benefits include:

- **Hardware-Based Runtime Isolation**: Fortanix CCM supports deployment of workloads into hardware-backed TEEs, ensuring that application memory and execution state are isolated from the host system.
- **Remote Attestation and Policy Enforcement**: Fortanix CCM performs remote attestation to validate the integrity of the compute platform and workload measurements. Policies bind approved measurements to workload identities, preventing unauthorized or modified workloads from accessing protected secrets.
- **Secure Secret and Certificate Provisioning**: Through integration with Fortanix Fortanix-Data-Security-Manager (DSM) ,Fortanix CCM enables secure key release, ensuring that keys, certificates, and other sensitive material are released only to verified and attested workloads.
- **Multi-Platform Support**: Fortanix CCM supports confidential computing technologies across major cloud providers and hardware vendors, providing a consistent security model across heterogeneous environments.

## 3.0 Supported Platforms and Technologies

Fortanix Confidential Computing Manager (CCM) supports deployment and management of workloads across multiple hardware-backed confidential computing technologies and cloud environments.

| Platform / Vendor | Technology or Capability Supported |
| --- | --- |
| Intel | Software Guard Extensions (SGX), Trust Domain Extensions (TDX) |
| Amazon Web Services (AWS) | Nitro Enclaves |
| Microsoft Azure | Confidential Virtual Machines (CVMs), Azure Container Instances (ACI) |
| Advanced Micro Devices (AMD) | Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) |

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.
