DigiCert has partnered with Google Cloud to bring independent trust validation to confidential computing environments by leveraging Public Key Infrastructure (PKI). This collaboration aims to ensure cloud-hosted systems and workloads are authentic, trusted, and tamper-proof by applying cryptographic verification.
As more organizations move sensitive applications, artificial intelligence workloads, and critical operations to cloud environments, the need for trust in the underlying infrastructure becomes essential. This is particularly crucial for regulated industries that require external validation to verify infrastructure integrity alongside assurances from cloud providers.
Introduction of an Independent Trust Layer
Through this initiative, DigiCert positions itself as a neutral third-party root of trust. It employs cryptographic signatures, certificates, and identity validation to attest that workloads and environments hosted on Google Cloud operate with enhanced transparency. This offering, developed after a year-long collaboration with Google Cloud, introduces a new trust model for the confidential computing ecosystem, enabling independent verification of cloud infrastructure.
Through this initiative, DigiCert positions itself as a neutral third-party root of trust
"As organizations handle increasingly sensitive data, the demand for multi-layered infrastructure assurance has grown," stated Amit Sinha, CEO of DigiCert. "For decades, PKI has enabled trusted interactions across the internet. We are now extending those same trust principles to confidential computing and cloud infrastructure."
Rise of Confidential Computing
The initiative supports the growing trend of confidential computing, which aims to protect data during active processing by isolating workloads within secure hardware-based environments. DigiCert’s capabilities in independent attestation strengthen this model by ensuring organizations can verify the integrity and authenticity of the infrastructure.
In collaboration with Google Cloud’s confidential computing features, DigiCert provides organizations with:
- Independent cryptographic verification of workloads and infrastructure
- Enhanced assurance that systems have not been altered or tampered with
- A unified root of trust for distributed cloud environments
- Increased transparency and confidence for workloads with regulatory and security concerns
Emergence of Verifiable Trust Architectures
"Confidential computing is built on the principle that customers should be able to verify the integrity of their workloads," commented Nelly Porter, Director of Product Management, Google Cloud Confidential Computing and Encryption. "By collaborating with DigiCert on independent attestation, we're extending that principle and providing customers with an additional layer of assurance for sensitive cloud workloads."
This collaboration underscores a broader industry trend toward verifiable trust architectures. In this model, security claims are validated cryptographically rather than being taken as given. DigiCert's strategy extends the current trust framework used for securing billions of internet connections into the evolving realm of cloud and AI infrastructures.
DigiCert, a global pioneer in intelligent trust, announces it is bringing independent trust validation to confidential computing environments, in collaboration with Google Cloud. By applying the proven principles of Public Key Infrastructure (PKI) to cloud infrastructure, DigiCert will provide cryptographic verification that cloud-hosted systems and workloads are authentic, trusted, and untampered.
As organizations move more sensitive applications, AI workloads, and critical operations to the cloud, trust in the underlying infrastructure has become a foundational requirement. Particularly in regulated industries, organizations are increasingly seeking independent attestation to validate infrastructure integrity and complement cloud provider assurances.
Increasingly sensitive data
DigiCert’s role introduces this independent layer of trust verification. Acting as a neutral third-party root of trust, DigiCert uses cryptographic signatures, certificates, and identity validation to independently attest that workloads and computing environments hosted in Google Cloud are operating even more transparently. Developed through a year-long collaboration between DigiCert and Google Cloud, the service establishes a new trust model for the confidential computing ecosystem that enables independent verification of cloud infrastructure complementing provider attestation.
“As organizations handle increasingly sensitive data, the demand for multi-layered infrastructure assurance has grown,” said Amit Sinha, CEO of DigiCert. “For decades, PKI has enabled trusted interactions across the internet. We are now extending those same trust principles to confidential computing and cloud infrastructure.”
Adoption of confidential computing
The initiative builds on the growing adoption of confidential computing, which protects data while it is actively being processed by isolating workloads in secure hardware-based environments. DigiCert’s independent attestation capabilities strengthen this model by enabling organizations to verify the integrity and authenticity of the infrastructure itself.
By combining Google Cloud’s confidential computing capabilities with DigiCert’s expertise in PKI and digital trust, organizations gain:
- Independent cryptographic verification of workloads and infrastructure
- Stronger assurance that systems have not been modified or tampered with
- A common root of trust across distributed cloud environments
- Greater transparency and confidence for regulated and security-sensitive workloads
Verifiable trust architectures
“Confidential computing is built on the principle that customers should be able to verify the integrity of their workloads,” said Nelly Porter, Director of Product Management, Google Cloud Confidential Computing and Encryption. “By collaborating with DigiCert on independent attestation, we're extending that principle and providing customers with an additional layer of assurance for sensitive cloud workloads."
The announcement reflects a broader industry shift toward verifiable trust architectures, where security claims are validated cryptographically rather than assumed implicitly. DigiCert’s approach extends the trust framework that secures billions of internet connections today into the next era of cloud and AI infrastructure.