DigiCert has announced a collaboration with Google Cloud to bring independent trust validation to confidential computing environments.
By leveraging the principles of Public Key Infrastructure (PKI), DigiCert aims to offer cryptographic verification that ensures cloud-hosted systems and workloads are authentic and trustworthy. This initiative becomes crucial as more organisations shift sensitive applications, AI workloads, and critical operations to the cloud, with a growing need for a secure underlying infrastructure.
Enhanced trust verification
As a neutral third-party root of trust, DigiCert introduces an additional layer of trust by using cryptographic signatures, certificates, and identity validation. This independent trust verification service, developed over a year in collaboration with Google Cloud, creates a novel trust model for the confidential computing ecosystem. It brings an extra level of security by allowing organisations to independently verify the integrity of their workloads and computing environments hosted on Google Cloud.
DigiCert introduces an additional layer of trust by using cryptographic signatures
"As organisations handle increasingly sensitive data, the demand for multi-layered infrastructure assurance has grown," stated Amit Sinha, CEO of DigiCert. "For decades, PKI has enabled trusted interactions across the internet. We are now extending those same trust principles to confidential computing and cloud infrastructure." The initiative coincides with the rising adoption of confidential computing, where secure environments protect data that is being processed.
Strengthening cloud security
Through this partnership, DigiCert’s independent attestation capabilities enhance confidential computing by empowering organisations to verify infrastructure integrity and authenticity. By integrating Google Cloud's capabilities with DigiCert's expertise in PKI and digital trust, organisations benefit from:
- Independent cryptographic verification of workloads and infrastructure
- Stronger assurance against modification or tampering
- A unified root of trust across distributed cloud environments
- Increased transparency and confidence for regulated and security-sensitive workloads
Nelly Porter, Director of Product Management for Google Cloud Confidential Computing and Encryption, stated, "Confidential computing is built on the principle that customers should be able to verify the integrity of their workloads. By collaborating with DigiCert on independent attestation, we're extending that principle and providing customers with an additional layer of assurance for sensitive cloud workloads."
Future of verifiable trust architectures
This collaboration signifies a broader industry movement towards verifiable trust architectures, where security claims are validated through cryptographic methods rather than assumed. DigiCert's strategy extends the existing trust framework, which secures numerous internet connections, to advance the security of cloud and AI infrastructures, aligning with modern requirements for verifiable trust.
DigiCert, a global pioneer in intelligent trust, announces it is bringing independent trust validation to confidential computing environments, in collaboration with Google Cloud. By applying the proven principles of Public Key Infrastructure (PKI) to cloud infrastructure, DigiCert will provide cryptographic verification that cloud-hosted systems and workloads are authentic, trusted, and untampered.
As organisations move more sensitive applications, AI workloads, and critical operations to the cloud, trust in the underlying infrastructure has become a foundational requirement. Particularly in regulated industries, organisations are increasingly seeking independent attestation to validate infrastructure integrity and complement cloud provider assurances.
Increasingly sensitive data
DigiCert’s role introduces this independent layer of trust verification. Acting as a neutral third-party root of trust, DigiCert uses cryptographic signatures, certificates, and identity validation to independently attest that workloads and computing environments hosted in Google Cloud are operating even more transparently. Developed through a year-long collaboration between DigiCert and Google Cloud, the service establishes a new trust model for the confidential computing ecosystem that enables independent verification of cloud infrastructure complementing provider attestation.
“As organisations handle increasingly sensitive data, the demand for multi-layered infrastructure assurance has grown,” said Amit Sinha, CEO of DigiCert. “For decades, PKI has enabled trusted interactions across the internet. We are now extending those same trust principles to confidential computing and cloud infrastructure.”
Adoption of confidential computing
The initiative builds on the growing adoption of confidential computing, which protects data while it is actively being processed by isolating workloads in secure hardware-based environments. DigiCert’s independent attestation capabilities strengthen this model by enabling organisations to verify the integrity and authenticity of the infrastructure itself.
By combining Google Cloud’s confidential computing capabilities with DigiCert’s expertise in PKI and digital trust, organisations gain:
- Independent cryptographic verification of workloads and infrastructure
- Stronger assurance that systems have not been modified or tampered with
- A common root of trust across distributed cloud environments
- Greater transparency and confidence for regulated and security-sensitive workloads
Verifiable trust architectures
“Confidential computing is built on the principle that customers should be able to verify the integrity of their workloads,” said Nelly Porter, Director of Product Management, Google Cloud Confidential Computing and Encryption. “By collaborating with DigiCert on independent attestation, we're extending that principle and providing customers with an additional layer of assurance for sensitive cloud workloads."
The announcement reflects a broader industry shift toward verifiable trust architectures, where security claims are validated cryptographically rather than assumed implicitly. DigiCert’s approach extends the trust framework that secures billions of internet connections today into the next era of cloud and AI infrastructure.