Home Page VMware Cloud Foundation

Securing the Memory Layer: How Broadcom and AMD Are Bringing Confidential Computing to the Enterprise

Security teams have spent years building strong protections around their data. Encryption on disk, encryption over the network, strict access controls, and continuous monitoring are all standard practices. But the moment a workload starts processing data, all of that protection fades away. For organizations handling regulated data, running AI models on sensitive inputs, or operating in multi-tenant environments, that exposure is becoming harder to justify to auditors and regulators.

VMware Cloud Foundation 9.1 closes that gap with confidential computing, and AMD’s hardware technology is central to that story. Broadcom and AMD have been working together to bring AMD Secure Encrypted Virtualization (SEV) with Secure Nested Paging into VCF as a production-ready capability, managed through the same operational model customers already use.

The Threat Landscape Has Shifted

The attack surface that matters most has moved. Network perimeters and disk encryption address external threats well, but the threats that are hardest to detect operate from inside the infrastructure stack. A compromised hypervisor, or even a privileged insider with host access can expose data in memory without triggering traditional security controls.

The growth of AI inference and agentic AI has amplified this exposure significantly. A model running inference on patient records, financial transactions, or proprietary training data sits in memory for the full duration of the job. Multi-tenant environments compound the risk because workloads from different business units or customers share physical hosts, and software-only isolation has a larger attack surface than isolation enforced by the CPU.

Regulatory frameworks like DORA, GDPTR and NIST include data-in-use protection requirements. Financial services, healthcare, and government compliance frameworks are starting to ask specific questions about how data is protected while it’s being processed, not just while it’s stored or transmitted. The answer that satisfies those questions is hardware-enforced memory isolation, which is exactly what AMD SEV provides.

What Broadcom and AMD Have Built Together

AMD’s role begins at the foundation of the stack, inside the AMD EPYCTM processor architecture itself. AMD SEV with Secure Nested Paging, available on AMD EPYCTM processors, creates hardware-isolated virtual machines where each VM’s memory is encrypted with keys that the hypervisor cannot access. The host operating system, the hypervisor, and anyone with administrative access to the physical server are structurally blocked from reading that memory. The protection is enforced by the CPU itself, not by software policy.

Broadcom provides the platform layer that makes SEV-SNP operationally usable inside VCF. VCF 9.0 introduced support for AMD SEV with Secure Nested Paging alongside existing AMD SEV with Encrypted State capabilities, bringing the same workload functionality to the newer technology.  Confidential computing supporting AMD SEV-SNP with Quickboot support became generally available with VMware Cloud Foundation 9.1, delivered as part of VMware Advanced Cyber Compliance

While SEV in an AMD EPYCTM processor is a silicon capability, Secure Nested Paging working correctly inside VCF’s virtualization layer, surfaced through VMware APIs without custom driver work, is a platform feature that customers can deploy to production. Broadcom and AMD did that integration and validation jointly, so customers don’t have to debug the interaction between the hardware and the hypervisor themselves.

AMD designed Secure Nested Paging to address operational concerns that earlier confidential computing technologies couldn’t solve. When a hypervisor loses visibility into a workload’s memory, it also loses the ability to migrate that workload with vMotion, take snapshots of the VM’s memory, or manage it through standard lifecycle operations. SEV’s architecture reduces those limitations, and VCF’s integration preserves as much operational functionality as possible while maintaining the security boundary.

What Customers Get

Workloads protected by SEV  are managed through VCF’s standard lifecycle, compliance, and operations workflows without requiring a parallel toolchain. No additional hardware, no dedicated staff, and no parallel management stack are required. Organizations already running VCF on AMD EPYCTM processors can enable confidential computing on hardware they already own.

AI inference jobs handling sensitive data execute within hardware-isolated memory enclaves where data remains inaccessible to neighboring workloads and platform administrators alike. For security teams, hardware attestation from AMD SEV is a stronger regulatory claim than software access controls because the guarantee is structural rather than policy-based. Infrastructure teams continue using the same tools and processes they already know.

In VCF 9.1, Live Patching lets TPM-equipped ESX hosts receive security updates for roughly 80% of CVEs without disrupting running virtual machines. With Continuous Compliance Enforcement, the platform maintains an always-current view of compliance status, eliminating the need to pull evidence together at audit time. On-premises Ransomware Recovery provides an air-gapped, immutable recovery layer native to the platform. Together with SEV’s memory isolation, these capabilities form a security architecture that covers data across its entire lifecycle.

Looking Ahead / Next Steps

Confidential computing is moving from a specialist capability to a baseline expectation, following the same path disk encryption took. The engineering Broadcom and AMD have done together puts that baseline within reach for any organization running VCF on AMD EPYCTM  processors today.

For teams operating in regulated environments or running AI on sensitive data atop AMD EPYCTM processors,  VCF 9.1 delivers confidential computing ready for production today. Contact your Broadcom representative for guidance on upgrading, selecting pilot workloads, and obtaining the AMD and Broadcom reference architecture.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.