News
Encryption

Future-Proof Encryption: enclaive Delivers Quantum-Resistant Confidential Computing

Sebastian Gajek
July 29, 2026
Future-Proof Encryption: enclaive Delivers Quantum-Resistant Confidential Computing

Rhine-Main, 29 July 2026 – enclaive, a leading provider of innovative confidential computing solutions, offers confidential execution environments with crypto-agile, post-quantum encryption. This enables companies and public-sector organisations to protect their applications, databases and AI models against both current and future threats – and to respond to new developments in cryptography and cybersecurity.

“Security officers are currently facing not one but two cryptographic ‘revolutions’: first confidential computing, and now post-quantum encryption,” explains Professor Sebastian Gajek, CTO and co-founder of enclaive. “A one-dimensional security strategy inevitably leaves gaps. If data is not encrypted while being processed, the question of quantum-resistant cryptography is largely irrelevant. Conversely, confidential computing can only be truly confidential if the encrypted execution environments themselves are protected against post-quantum threats. At enclaive, we therefore combine both approaches to provide our customers with future-proof infrastructure.”

Focus on Post-Quantum Cryptography and Encrypted Data Processing

Quantum computing is currently receiving considerable attention. One of the most critical concerns in cybersecurity is the so-called “Q-Day” – the point at which quantum computers become capable of breaking conventional encryption methods such as RSA, ECC and Diffie–Hellman. These concerns are further intensified by the growing prevalence of “harvest now, decrypt later” attacks targeting sensitive data today. The US National Institute of Standards and Technology (NIST) has already published post-quantum standards, while Europe’s NIS Cooperation Group has issued a post-quantum roadmap. Germany’s Federal Office for Information Security (BSI) also recommends introducing post-quantum cryptography for highly sensitive applications by the end of 2030 at the latest. In addition, the planned deprecation of the DSA signature algorithm from 2029 suggests that an earlier migration to post-quantum cryptography may be advisable.

At the same time, security officers are only just beginning to eliminate another cryptographic attack vector: the protection of data in use. For decades, data being processed remained accessible through privileged access by administrators, cloud providers or compromised systems. Confidential computing now provides a solution to this vulnerability and has already been incorporated into regulatory frameworks and standards, including the current BSI C5 criteria catalogue. By encrypting data during processing within isolated, hardware-based execution environments, applications, databases and AI workloads can now be operated through cloud providers without requiring trust in the underlying infrastructure. Sovereign key management is central to this approach: control over encryption keys means control over data.

Long-Term Data Security with enclaive

enclaive combines easy-to-integrate confidential computing with post-quantum-secure encryption. This enables customers to modernise their encryption mechanisms without significant implementation effort.

Two solutions play a central role:

  • eMCP: Post-Quantum Migration at the Touch of a Button
    The enclaive Multi-Cloud Platform (eMCP) simplifies the transition to confidential computing and post-quantum security. Through a central user interface, confidential execution environments – either as virtual machines using enclaive Buckypaper or as Kubernetes clusters using enclaive Dyneemes – can be deployed and managed with post-quantum encryption across multiple cloud providers. The platform abstracts the security technologies used by hardware manufacturers and cloud providers, allowing customers to avoid lengthy implementation processes and become operational with just a few clicks through a plug-and-play approach.
  • vHSM: Future-Proof Through Post-Quantum Algorithms and Crypto-Agility
    Through its virtual Hardware Security Module (vHSM), enclaive provides a cloud-native cryptographic engine that delivers post-quantum-level encryption while allowing customers to retain full control over their encryption keys. The strength of enclaive’s encryption always reflects the latest NIST and BSI recommendations because the vHSM is crypto-agile: Both algorithms and key lengths can be updated and modified dynamically without interrupting customer operations.

Gajek adds: “Crypto-agility is one of the major strengths of our confidential computing architecture. It is the only way for companies and public-sector organisations to ensure that their encryption remains state of the art. This is particularly important in the field of post-quantum cryptography, where the final technological landscape has yet to fully emerge. The ability to adapt is therefore absolutely critical to long-term data security.”

Regarding the current state of technology, customers also benefit from the dual role of enclaive’s CTO. As a professor of IT security and cryptography at Flensburg University of Applied Sciences, Gajek remains closely involved with the latest advances in research and incorporates these developments into the company’s technical innovation.

PQC Standards Used by enclaive

In addition to conventional encryption algorithms, enclaive currently uses the NIST-finalised standards FIPS 203 (ML-KEM) for secure key establishment and FIPS 204 (ML-DSA) for digital signatures. FIPS 205 (SLH-DSA), as well as the standards currently under development – FIPS 206 (FN-DSA) and FIPS 207 (HQC-KEM) – are also being progressively integrated into the vHSM and, consequently, into enclaive’s encryption architecture.

Further information about enclaive is available at www.enclaive.io.

Download this ebook

To keep up with the latest innovations in Confidential Computing, follow enclaive on LinkedIn or subscribe to our newsletter.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.