Confidential Computing With AMD SEV-SNP

Privacy by design, not by policy. Hardware-level isolation and encryption of your server's memory, boot integrity and storage that you can verify.

What is Confidential Computing?

Confidential Computing protects data while it's being processed, ensuring that it stays encrypted and isolated via hardware-located Trusted Execution Environments (TEEs) where data processing executions can be done securely without risking unwanted interference.

Learn More

Your virtual machine remains isolated from all other hosted VMs as well as the hypervisor, meaning that if they were to be compromised, your data cannot be exposed and remains safe.

How to Activate Confidential Computing

Learn how to enable AMD SEV-SNP for new and existing servers to ensure maximum security at all times.

New Server

If you wish to get a fresh new server with AMD SEV-SNP, you can do so through our server configurator. Simply click the toggle button and SEV-SNP will be automatically enabled for your server once it's deployed. It's that simple!

Deploy Server

Existing Server

If you already have a VPSBG cloud server without SEV, you can always activate it through the settings tab of your server management page. Please note that SEV-SNP is still experimental and some additional configuration actions might be required.

Log in

Verify System On Launch With Measured Boot

Verify that nothing has been modified between system starts and ensure system integrity with Measured Boot. Hardware-signed attestation report, generated with AMD SEV-SNP that you can verify for maximum security.

FEATURES
Feature · 01 of 07

Verified Firmware & UKI

Measured boot allows the exact UEFI firmware and Unified Kernel Image (UKI) that are used during startup to be cryptographically verified, meaning that every boot measurement is recorded and signed. This enables you to confirm that each time the system loads, it does so with the expected firmware and components.

How It Works

Measured boot creates a secure chain of trust starting from the moment your system powers on and continuing seamlessly until your virtual machine is fully operational, ensuring enhanced protection and reliability throughout the entire startup process.

  1. Deployment

    Launch a VM from the VPSBG Console

  2. Initialization

    Firmware + UKI loaded into RAM

  3. Launch Measured

    AMD PSP computes start measurements

  4. Boot

    UEFI hands off to the kernel in the UKI

  5. Disk Verification

    Check dm-verity root hash (Optional)

  6. Disk Verified

    OS starts if check passes (Optional)

  7. Attestation

    Report retrieved & compared

Useful Resources

Guides, tutorials and documentation to learn more and help you get started with cloud hosting.

Documentation

Memory Encryption Fundamentals

Learn more about Secure Memory Encryption (SME) and Secure Encrypted Virtualization (SEV) using AMD's official white paper.

View AMD Documentation(opens in new tab)
Documentation

Introduction to SEV-SNP

Take a deep dive into the technology behind AMD's SEV-SNP and take a closer look at the concept enabling confidential computing.

View AMD Documentation(opens in new tab)
Tutorial

How to perform cryptographic attestation

Learn how to perform AMD SEV-SNP attestation inside of your virtual machine to verify encryption and security.

View Tutorial

Frequently Asked Questions

Find answers to the most frequently asked questions for all VPSBG inquiries and our services.

Deploy Confidential VM With SEV-SNP

Protect your privacy and ensure maximum security for your cloud server with AMD SEV-SNP. True confidential computing with memory and disk encryption with measured boot for complete service encapsulation!