In this article
We explain what Intel TDX confidential computing actually protects, confirm which hardware configuration delivers it in our Amsterdam data center today, and walk through why pairing TDX with EU data residency matters for regulated workloads.
If your compliance requirements call for both EU data residency and confidential computing, you don’t have to choose between them or wait on a build-out. That combination is deployable in Amsterdam today, on hardware already in stock.
Confidential computing gets talked about a lot in the abstract. What it actually does, concretely, is worth being precise about, especially if you’re weighing it against a compliance deadline or a specific regulated workload.
What Intel TDX Protects
Most encryption protects data in two states: at rest, when it’s sitting on a disk, and in transit, when it’s moving across a network. Intel Trust Domain Extensions, or TDX, protects a third state: data in use, while it’s actively being processed in memory. For a deeper technical walkthrough of how Trust Domains work at the architecture level, see our in-depth exploration of Intel TDX.
TDX does this by isolating entire virtual machines into encrypted Trust Domains at the hardware level. Even someone with access to the physical host, including a cloud provider’s own administrators, cannot read the memory contents of a workload running inside a Trust Domain. This matters for workloads where the processing itself, not just storage or transmission, needs to be shielded: healthcare analytics on patient data, financial modeling on sensitive positions, or any workload where a compliance framework specifically calls out data-in-use protection.
TDX is available starting with Intel’s 5th Gen Xeon Scalable processors, known as Emerald Rapids, and continues into Intel’s newer Granite Rapids generation. It is not available on Ice Lake or earlier processor generations, so the underlying hardware generation matters before anything else.
The Hardware Requirement Behind TDX
Intel’s actual hardware requirements for TDX come down to two things, and neither one specifies a total amount of RAM:
- A supported CPU generation, meaning 5th Gen Intel Xeon Scalable (Emerald Rapids) or newer.
- Full memory channel population, meaning every memory channel across both CPU sockets needs a DIMM installed. Partially populated channels prevent TDX from activating at all, regardless of how much total RAM is installed.
The reason TDX-capable servers tend to get associated with a specific RAM figure, usually 1TB, comes down to how a provider chooses to populate those channels, not an Intel mandate. OpenMetal stocks 64GB RDIMMs. On a server with 16 DIMM slots split across two CPU sockets, fully populating every channel means installing 16 of those DIMMs, which works out to 1TB. That’s our production configuration, not Intel’s requirement. A provider using different DIMM sizes could reach full channel population at a different total RAM figure. Our full breakdown of SGX and TDX hardware requirements across the v4 and v5 lineup covers exactly which configurations activate TDX out of the box versus which need a RAM upgrade.
What’s Actually Available in Amsterdam Right Now
Our XL v4 server, built on Emerald Rapids, ships with 1TB of DDR5 RAM across fully populated memory channels and is TDX-active out of the box. It’s currently in stock in our Amsterdam data center, meaning a TDX-capable deployment in the EU doesn’t require a custom build or a wait on procurement.
This is worth being specific about because not every server tier gets you there. Smaller configurations in our EU lineup don’t ship with fully populated memory channels by default, since doing so at every tier would mean shipping more RAM than most workloads need. XL v4 is built around full channel population specifically because that’s what unlocks TDX, and it’s the configuration to ask for if confidential computing is a requirement rather than a nice-to-have. For workloads that need more headroom than XL v4 offers, our XXL v4 ships TDX-active at its base 2TB configuration and can be ordered for EU deployment, though it typically ships within a few weeks rather than being held in immediate stock.

Explore our current bare metal server catalog
Why Pairing TDX With EU Residency Matters
Data residency and confidential computing solve different problems, and regulated workloads increasingly need both answered at once.
Residency addresses where your data physically sits and which jurisdiction’s data protection law governs it as a baseline matter. It doesn’t say anything about what’s technically visible to the infrastructure provider running the hardware underneath your workload. TDX addresses that second question directly: even within a facility you’ve chosen for residency reasons, TDX limits what’s technically accessible to anyone outside your own Trust Domain, provider included.
For workloads governed by GDPR, DORA, or the EU AI Act, that combination is increasingly what “reasonably secured” or “adequate technical safeguards” ends up meaning in practice, particularly for financial services and healthcare workloads where regulators expect specific, demonstrable controls rather than general assurances. A deployment that can point to both EU-based physical residency and hardware-level data-in-use protection is answering a more complete version of the question auditors and regulators actually ask.
What This Doesn’t Solve
TDX is a real technical control, not a compliance guarantee on its own. It doesn’t replace a Data Processing Agreement, doesn’t substitute for your organization’s own access controls and key management practices, and doesn’t change OpenMetal’s status as a US company subject to US legal process, a distinction we cover in more detail in our breakdown of data residency versus data sovereignty. What it does is narrow, meaningfully, what’s technically exposed even in scenarios where legal or physical access to infrastructure is in question.
Whether TDX satisfies a specific regulatory requirement for your organization is a question for your compliance team and counsel, not a marketing claim. What we can confirm is the technical configuration: full memory channel population, Emerald Rapids or newer silicon, and a Trust Domain isolating your workload from the host.
Getting Started
XL v4 with TDX is available now on our bare metal pricing page, deployable in our Amsterdam facility with details on the Amsterdam data center specs page. For a broader look at confidential computing use cases beyond the EU specifically, see our confidential computing infrastructure page. If you want to see how TDX affects real workload performance before committing, our TDX performance benchmarks on bare metal covers overhead across several workload types.
FAQ
Does Intel TDX require 1TB of RAM?
No. Intel’s requirement is full memory channel population across both CPU sockets, not a specific RAM total. OpenMetal’s 1TB figure comes from stocking 64GB RDIMMs to fully populate 16 DIMM slots, which is our production configuration rather than an Intel mandate.
Is TDX available on OpenMetal’s Amsterdam hardware today?
Yes. Our XL v4 server, built on Emerald Rapids with fully populated memory channels, is TDX-active out of the box and currently in stock in Amsterdam.
What does TDX protect that standard encryption doesn’t?
Standard encryption typically protects data at rest and in transit. TDX protects data in use, meaning the contents of memory while a workload is actively running, by isolating it into a hardware-encrypted Trust Domain inaccessible even to the infrastructure provider.
Does TDX make a workload GDPR or DORA compliant?
No single technical control makes a workload compliant on its own. TDX is a hardware-level safeguard that can support a compliance program’s technical requirements around data-in-use protection. Whether it satisfies a specific regulatory obligation depends on your full compliance program and should be confirmed with your legal or compliance team.
Can I run TDX workloads while keeping data resident in the EU?
Yes. Our Amsterdam data center provides both EU data residency and TDX-capable hardware in the same facility, so the two requirements don’t have to be solved by different vendors or locations.
Schedule a Consultation
Get a deeper assessment and discuss your unique requirements.
Read More on the OpenMetal Blog

































