- $50 billion: Projected market size for confidential computing by 2028.
- Independent attestation: Cryptographic proof of workload integrity in cloud environments.
- PKI framework: Extends trusted internet security principles to confidential computing.
Experts would likely conclude that this collaboration represents a significant advancement in cloud security, offering cryptographically verifiable trust that addresses critical gaps in confidential computing.
A New Layer of Trust: How Independent Verification Changes Cloud Security
LEHI, UT – June 23, 2026 – In a move that signals a significant maturation of cloud infrastructure, digital trust leader DigiCert has announced a collaboration with Google Cloud to bring independent, third-party validation to the world of confidential computing. By applying the time-tested principles of Public Key Infrastructure (PKI) to the cloud’s most secure environments, the initiative promises to provide cryptographic proof that an organization's systems and AI workloads are running exactly as intended, free from tampering. This partnership tackles a fundamental question in the digital age: in a world built on shared infrastructure, how do you truly verify trust?
For years, the industry has relied on a model of implicit trust, where cloud providers offer assurances about the integrity of their platforms. Now, this collaboration introduces a new paradigm—verifiable trust. Acting as a neutral arbiter, DigiCert will independently attest to the authenticity of workloads hosted in Google Cloud, offering a layer of assurance that complements the provider’s own guarantees. It’s a development that could unlock the next wave of cloud adoption for the world’s most sensitive operations.
The Trust Gap in the Cloud’s Inner Sanctum
At the heart of this announcement is a technology called confidential computing. Its purpose is to protect “data in use”—the moment when information is most vulnerable as it is actively being processed. This is achieved by isolating data and applications within a hardware-based Trusted Execution Environment (TEE), a secure enclave on a server's processor. The contents of this enclave are encrypted and inaccessible, even to the cloud provider that owns the hardware, its administrators, or the system’s own operating system.
While TEEs provide powerful isolation, a subtle but critical trust gap has remained. The process of “attestation”—cryptographically verifying that the enclave is genuine and that the correct code is running inside it—has typically been managed by the cloud provider itself. For many organizations, particularly those in highly regulated sectors like finance and healthcare, this presents a challenge. It requires them to place their full faith in the provider’s systems and personnel, creating a single point of trust. Migrating mission-critical applications or training AI on proprietary data under these conditions has remained a calculated risk.
Independent validation addresses this gap directly. By introducing a neutral third party rooted in cryptographic certainty, organizations gain an external, objective mechanism to confirm the integrity of their cloud environments. This is less about mistrusting cloud providers and more about establishing the multi-layered, verifiable assurance that modern compliance and risk management demand.
Extending a Proven Model: How PKI Secures the Cloud Core
The technology underpinning this new layer of security is Public Key Infrastructure, the same framework that has secured internet communications for decades. PKI is the reason a padlock icon appears in your browser, providing the identity validation and encryption that enables secure online banking, e-commerce, and communications. It establishes a “root of trust” that allows billions of devices to interact securely without prior arrangement.
“For decades, PKI has enabled trusted interactions across the internet,” said Amit Sinha, CEO of DigiCert, in the announcement. “We are now extending those same trust principles to confidential computing and cloud infrastructure.”
Developed over a year-long collaboration, the service positions DigiCert to issue cryptographic certificates that attest to the integrity of Google Cloud’s confidential computing environments. When a workload starts, it can now be verified not only by Google’s internal mechanisms but also by an independent certificate from a globally trusted authority. This provides a common root of trust that can span across distributed and even multi-cloud environments, simplifying security and compliance.
This external verification strengthens the entire model. “Confidential computing is built on the principle that customers should be able to verify the integrity of their workloads,” noted Nelly Porter, Director of Product Management for Google Cloud Confidential Computing and Encryption. “By collaborating with DigiCert on independent attestation, we're extending that principle and providing customers with an additional layer of assurance for sensitive cloud workloads."
Unlocking New Frontiers for Sensitive Data and AI
The practical implications of verifiable trust are profound, especially for industries where data sensitivity and regulatory oversight are paramount. With independent attestation, the scope of what can be safely moved to the cloud expands dramatically.
In financial services, for instance, competing banks could securely pool transaction data within a confidential environment to train a shared anti-money laundering AI model. Independent validation would give each institution cryptographic proof that its sensitive customer data remains private and that the shared environment is untampered. In healthcare, researchers from different hospitals could collaborate on drug discovery by analyzing patient data without ever exposing personally identifiable information, all while maintaining strict HIPAA compliance.
The burgeoning field of artificial intelligence stands to benefit significantly. As organizations increasingly rely on AI, protecting the intellectual property of the models themselves and the vast, often sensitive, datasets used to train them has become a critical concern. With this new trust layer, a company can run its proprietary AI model in the cloud with cryptographic assurance that it remains confidential and has not been altered.
This capability directly addresses a major inhibitor to cloud adoption for the most critical business functions. It transforms the security conversation from a matter of policy and contractual obligation to one of mathematical proof, giving CISOs and compliance officers the concrete evidence they need to approve cloud migrations for previously off-limits workloads.
A Paradigm Shift Towards Verifiable Architectures
The DigiCert-Google Cloud partnership is more than a new product feature; it reflects a broader industry shift toward verifiable trust architectures. The market for confidential computing is projected to grow exponentially, with some estimates suggesting it could exceed $50 billion by 2028 as data privacy regulations intensify and cyber threats become more sophisticated. In this landscape, simply trusting a provider’s word is no longer sufficient.
The move toward cryptographically validated security claims represents the next stage in the evolution of digital infrastructure. Just as HTTPS became the default standard for the web, independent attestation may become a baseline expectation for any organization handling sensitive data in the cloud. This establishes a clear, auditable, and universal standard for trust, paving the way for a future where complex, multi-party collaborations and sensitive AI applications can operate securely at scale.
