Why AWS Nitro Enclaves?
AWS Nitro Enclaves enables customers to create isolated compute environments to further protect and securely process highly sensitive data such as personally identifiable information (PII), healthcare, financial, and intellectual property data within their Amazon EC2 instances. Nitro Enclaves uses the same Nitro Hypervisor technology that provides CPU and memory isolation for EC2 instances.
Nitro Enclaves helps customers reduce the attack surface area for their most sensitive data processing applications. Enclaves offers an isolated, hardened, and highly constrained environment to host security-critical applications. Nitro Enclaves includes cryptographic attestation for your software, so that you can be sure that only authorized code is running, as well as integration with the AWS Key Management Service, so that only your enclaves can access sensitive material.
There are no additional charges for using AWS Nitro Enclaves other than the use of Amazon EC2 instances and any other AWS services that are used with Nitro Enclaves.
Benefits
Use cases
Resources
Customer Stories
"ACINQ is one of the main developers and operators of the Lightning Network, an open, high-performance payment network based on Bitcoin. By running our payment nodes inside AWS Nitro Enclaves, we were able to achieve the high level of protection we need for the private keys that control our funds with nearly no code modifications. The ability to run complex, cryptographically attested applications inside AWS Nitro Enclaves is a game changer from a security point of view and enables us to implement extra security measures such as the use of hardware wallets to administer our systems. Using AWS Nitro Enclaves, we operate one of the most secure payment nodes on the network, and plan to move more services to AWS Nitro Enclaves to reduce the attack surface of our overall system."
Fabrice Drouin, Co-Founder and CTO, ACINQ
“Anjuna innovated an enterprise-ready way to protect high-value assets leveraging AWS Nitro Enclaves. Now our customers can set up and manage isolated compute environments in EC2 to process and harden cloud workloads in minutes without recoding or refactoring applications. Anjuna Confidential Computing software, built on Nitro Enclaves, reduces the attack surface for confidential and sensitive data processing applications: personally identifiable information (PII), proprietary algorithms, multiparty computation (MPC) applications, databases, and key/secrets management. AWS Nitro Enclaves allows Anjuna’s software to better serve customers in highly regulated industries such as financial services, fintech, crypto, government, healthcare, and SaaS providers.”
Ayal Yogev, CEO and Co-founder, Anjuna Security
"Cape Privacy is focused on data security and privacy for AI that leverages the cloud. Companies can use Cape API to leverage the power of Large Language Models against a customized knowledge base that can include sensitive or confidential data. Cape API is designed to provide privacy for customer data without compromising the value of using a Large Language Model. Customers using Cape models on Amazon EC2 can be confident in Cape Privacy's approach to protect their sensitive data because they use AWS Nitro Enclaves on top of the AWS Nitro System with various privacy-preserving data processing techniques to ensure that nobody can ever see your data."
Ché Wijesinghe, CEO, Cape Privacy
"Highly available and secure validator infrastructure is critical for sustainable cryptocurrency networks (such as the Crypto.org Chain). Specifically, one key aspect that needs to be secured and hardened is the signing of consensus protocol messages. Within our cloud infrastructure, AWS Nitro Enclaves and AWS KMS make it easy for Crypto.com and our external partners to scale, deploy and manage these signing processes. AWS Nitro Enclaves provide cost-effective hardening and isolation for secure key management.”
Tomas Tauber, Chain Lead, Crypto.com
"As a Password Manager, Dashlane is responsible for securing some of the most sensitive data for organizations. Using AWS Nitro Enclaves, our customers are able to cut their integration setup time in half, while ensuring the highest level of security. AWS Nitro Enclaves offer an innovative way to fully isolate the encryption keys, allowing organizations to be confident that their data is private and protected, and that no unauthorized parties, including Dashlane, can see or access keys."
Frederic Rivain, Chief Technology Officer, Dashlane
"Protecting and processing highly sensitive information such as financial, healthcare, identity, and proprietary data is one of the main use cases for Evervault’s encryption infrastructure. At the core of Evervault is our Evervault Encryption Engine (E3), which performs all cryptographic operations and handles encryption keys for our customers. E3 is built on AWS Nitro Enclaves which provides an isolated, hardened, and highly constrained compute environment for processing sensitive data. Building E3 on Nitro Enclaves means that we can provide both security through cryptographic attestation, and a robust foundation for all other Evervault products and services. At no additional cost, Nitro Enclaves enable us to provide a highly secure, cost effective, and scalable service to our customers; a service that is capable of handling thousands of cryptographic operations per second.”
Shane Curran, Founder & CEO, Evervault
"Fireblocks powers companies of all sizes to confidently build, run, and grow their business on the blockchain. Security is foundational to our and our customers' operations, and AWS Nitro Enclaves are an important component of our multi-layered security architecture. By leveraging Nitro Enclaves, we've enhanced our multi-party computation (MPC) wallet solution, allowing for secure transaction signing with Nitro System based isolation and reducing the risk involved in these critical operations. This integration enables our clients to maintain control over their assets while benefiting from the scalability and flexibility of cloud deployment. The attestation features of Nitro Enclaves also provide cryptographic assurance that only authorized code is running in these secure environments. By offering Nitro Enclaves as part of our comprehensive security toolkit, we're able to meet the diverse needs of our global client base, ensuring that they can confidently manage and transact digital assets with state-of-the-art security, regardless of their preferred infrastructure."
Pavel Berengoltz, Chief Technology Officer and Co-Founder, Fireblocks
"Footprint’s mission is to bring trust back to the internet, and our first priority is to make sure that we use the most sophisticated and robust vaulting architecture to store, encrypt, and process sensitive financial and personal data for our customers and their users. To accomplish this, we’ve architected and built Footprint’s core vaulting infrastructure on top of AWS Nitro Enclaves because of the world-class security it provides: the ability to run cryptographically signed and attested code in a CPU, memory, and network isolated environment to massively lower the attack surface area and provide our customers with a security foundation that far outpaces the normal approaches businesses use today.”
Alex Grinman Co-founder & CTO of Footprint
"Fortanix, a pioneer in confidential computing, empowers multi-party data collaboration, federated machine learning, and confidential data search use cases. Fortanix customers can use Confidential Computing Manager to lift and shift their confidential applications and run them on a wide range of AWS Nitro Enclaves enabled on Amazon Elastic Compute Cloud (Amazon EC2) instances to ensure sensitive data remains protected during use. Fortanix helps customers across a variety of industries including healthcare, fintech, financial services, and manufacturing to accelerate their AWS migrations with enhanced security and protected data across its entire data life cycle—at rest, in motion, and in use."
Anand Kashyap, CEO, Fortanix
"Itaú Digital Assets is Itaú Unibanco's business unit responsible for the development of solutions using the blockchain technology. In this context, Nitro Enclaves has helped us create a safe environment for the manipulation of cryptographic keys of our cryptoassets custody services, adding yet another layer of protection for processing data while reducing the attack surface at the same time. This high-level of protection was a key factor that allowed the execution of complex solutions associated with the excellence in security, one of the main pillars of our institution."
Carlos Eduardo Mazzei, Chief Technology Officer at Itaú Unibanco
"M10 Networks, Inc develops and deploys their M10 Ledger Platform, a service for developing and distributing central bank digital currencies and tokenized regulated liabilities, on AWS. The Ledger Platform uses AWS Nitro Enclaves to perform signature verification and cryptographic re-signing of batches of transactions. Using AWS Nitro Enclaves on AWS latest M6i instances, M10 is able to deliver a performant and cost effective solution for the digital currency market.”
Sascha Wise, M10 Founding Engineer
"Okta, an Identity as a Service (IDaaS) company, helps connect any person with any application on any device. Okta provides enterprise-grade identity management service for customers in the cloud or using on-premises applications. Okta’s Privileged Access Management (PAM) solution helps organizations manage risk by bringing critical PAM capabilities into core Identity and Access Management solution, including privileged access management, credential vaulting, and compliance reporting. Okta uses Nitro Enclaves to securely manage and store customer infrastructure credentials in their respective Okta PAM solution. Okta’s PAM solution leverages Nitro Enclaves help to manage customer credentials in a vetted and cryptographically attested environment. Using AWS Nitro Enclaves, Okta protects customers from attacks as part of our defense-in-depth architecture. Okta looks forward to expanding the capabilities of Okta Privileged Access on top of Nitro Enclaves continuing to build a secure foundation for protecting access to customer ecosystem."
Smitha Prasad, Director of Engineering, Okta