Buckypaper is a specialized confidential virtual machine (VM) solution designed to secure sensitive workloads through hardware-based confidential compute. It creates protected execution environments, or "blind boxes," that isolate data and code to prevent unauthorized access, insider threats, and intellectual property theft. Every virtualized workload operating within Buckypaper is continuously encrypted, authenticated, and integrity-protected, ensuring that data remains secure and pseudonymized during storage, transit, and active processing.
The solution is engineered for seamless integration into existing virtualized infrastructures, allowing confidential VMs to run alongside non-confidential VMs. Operating with a minimal 3% CPU cycle overhead, Buckypaper maintains computational efficiency while delivering secure multi-tenancy. It is built to support shared public, private, and hybrid cloud environments, enabling organizations to deploy secure enclaves for proprietary software, self-managed databases, and highly regulated data workloads.