Skip to content
Navigation Menu

IBM Cloud

  • CatalogCatalog
  • Cost EstimatorCost Estimator
    • HelpHelp
      • Docs
      • Send feedback
  • Catalog
  • Cost Estimator
  • Help
    • Docs
    • Send feedback

  • Navigation settings

Error

Change theme

This feature is in early stage, some parts of the platform might not fully support different themes yet.

  • Log in
  • Sign up
  1. Catalog

IBM Cloud Data Shield

IBM Cloud™ Data Shield enables users to run containerized applications in a secure enclave on an IBM Cloud Kubernetes host, providing data-in-use protection

  • Date of last update: 09/23/2020
  • Docs
Type
  • Service
Provider
  • IBM
Updated on
  • 09/23/2020
Category
  • Security
Compliance
  • IAM-enabled
Related links
  • Docs
  • Terms

Pricing plans

PlanFeaturesPricing

Summary

IBM Cloud Data Shield

    Already have an account? Log in
    Type
    • Service
    Provider
    • IBM
    Updated on
    • 09/23/2020
    Category
    • Security
    Compliance
    • IAM-enabled
    Related links
    • Docs
    • Terms

    Summary

    Get started today by installing the Helm chart: https://cloud.ibm.com/kubernetes/helm/iks-charts/ibmcloud-data-shield

    Features

    Data in use protection

    Protect data while it is in use by running IBM Cloud Data Shield to encrypt your app’s memory at runtime. You can run IBM Cloud Data Shield on IBM Cloud Kubernetes Service and OpenShift clusters.

    Secure enclaves

    Run your app code and data in trusted areas of memory on the worker node, known as CPU-hardened enclaves, to protect the critical aspects of your apps. Enclaves help to keep code and data confidential and prevent modification. If you or your company require data sensitivity because of internal policies, government regulations, or industry compliance requirements, this solution might help you to move to the cloud.

    User friendly SGX workloads

    Integrate the service with your DevOps toolchains to seamlessly convert your existing containers into runtime-encrypted counterparts with a single API call. The service extends SGX capabilities from C and C++ to Python and Java and makes the attestation process effortless by distributing attestation reports through certificates that are signed by the Enclave Manager.