In this article

We explain what Intel TDX confidential computing actually protects, confirm which hardware configuration delivers it in our Amsterdam data center today, and walk through why pairing TDX with EU data residency matters for regulated workloads.


If your compliance requirements call for both EU data residency and confidential computing, you don’t have to choose between them or wait on a build-out. That combination is deployable in Amsterdam today, on hardware already in stock.

Confidential computing gets talked about a lot in the abstract. What it actually does, concretely, is worth being precise about, especially if you’re weighing it against a compliance deadline or a specific regulated workload.

What Intel TDX Protects

Most encryption protects data in two states: at rest, when it’s sitting on a disk, and in transit, when it’s moving across a network. Intel Trust Domain Extensions, or TDX, protects a third state: data in use, while it’s actively being processed in memory. For a deeper technical walkthrough of how Trust Domains work at the architecture level, see our in-depth exploration of Intel TDX.

TDX does this by isolating entire virtual machines into encrypted Trust Domains at the hardware level. Even someone with access to the physical host, including a cloud provider’s own administrators, cannot read the memory contents of a workload running inside a Trust Domain. This matters for workloads where the processing itself, not just storage or transmission, needs to be shielded: healthcare analytics on patient data, financial modeling on sensitive positions, or any workload where a compliance framework specifically calls out data-in-use protection.

TDX is available starting with Intel’s 5th Gen Xeon Scalable processors, known as Emerald Rapids, and continues into Intel’s newer Granite Rapids generation. It is not available on Ice Lake or earlier processor generations, so the underlying hardware generation matters before anything else.

The Hardware Requirement Behind TDX

Intel’s actual hardware requirements for TDX come down to two things, and neither one specifies a total amount of RAM:

  1. A supported CPU generation, meaning 5th Gen Intel Xeon Scalable (Emerald Rapids) or newer.
  2. Full memory channel population, meaning every memory channel across both CPU sockets needs a DIMM installed. Partially populated channels prevent TDX from activating at all, regardless of how much total RAM is installed.

The reason TDX-capable servers tend to get associated with a specific RAM figure, usually 1TB, comes down to how a provider chooses to populate those channels, not an Intel mandate. OpenMetal stocks 64GB RDIMMs. On a server with 16 DIMM slots split across two CPU sockets, fully populating every channel means installing 16 of those DIMMs, which works out to 1TB. That’s our production configuration, not Intel’s requirement. A provider using different DIMM sizes could reach full channel population at a different total RAM figure. Our full breakdown of SGX and TDX hardware requirements across the v4 and v5 lineup covers exactly which configurations activate TDX out of the box versus which need a RAM upgrade.

What’s Actually Available in Amsterdam Right Now

Our XL v4 server, built on Emerald Rapids, ships with 1TB of DDR5 RAM across fully populated memory channels and is TDX-active out of the box. It’s currently in stock in our Amsterdam data center, meaning a TDX-capable deployment in the EU doesn’t require a custom build or a wait on procurement.

This is worth being specific about because not every server tier gets you there. Smaller configurations in our EU lineup don’t ship with fully populated memory channels by default, since doing so at every tier would mean shipping more RAM than most workloads need. XL v4 is built around full channel population specifically because that’s what unlocks TDX, and it’s the configuration to ask for if confidential computing is a requirement rather than a nice-to-have. For workloads that need more headroom than XL v4 offers, our XXL v4 ships TDX-active at its base 2TB configuration and can be ordered for EU deployment, though it typically ships within a few weeks rather than being held in immediate stock.

Amsterdam Bare Metal Catalog

Explore our current bare metal server catalog

Why Pairing TDX With EU Residency Matters

Data residency and confidential computing solve different problems, and regulated workloads increasingly need both answered at once.

Residency addresses where your data physically sits and which jurisdiction’s data protection law governs it as a baseline matter. It doesn’t say anything about what’s technically visible to the infrastructure provider running the hardware underneath your workload. TDX addresses that second question directly: even within a facility you’ve chosen for residency reasons, TDX limits what’s technically accessible to anyone outside your own Trust Domain, provider included.

For workloads governed by GDPR, DORA, or the EU AI Act, that combination is increasingly what “reasonably secured” or “adequate technical safeguards” ends up meaning in practice, particularly for financial services and healthcare workloads where regulators expect specific, demonstrable controls rather than general assurances. A deployment that can point to both EU-based physical residency and hardware-level data-in-use protection is answering a more complete version of the question auditors and regulators actually ask.

What This Doesn’t Solve

TDX is a real technical control, not a compliance guarantee on its own. It doesn’t replace a Data Processing Agreement, doesn’t substitute for your organization’s own access controls and key management practices, and doesn’t change OpenMetal’s status as a US company subject to US legal process, a distinction we cover in more detail in our breakdown of data residency versus data sovereignty. What it does is narrow, meaningfully, what’s technically exposed even in scenarios where legal or physical access to infrastructure is in question.

Whether TDX satisfies a specific regulatory requirement for your organization is a question for your compliance team and counsel, not a marketing claim. What we can confirm is the technical configuration: full memory channel population, Emerald Rapids or newer silicon, and a Trust Domain isolating your workload from the host.

Getting Started

XL v4 with TDX is available now on our bare metal pricing page, deployable in our Amsterdam facility with details on the Amsterdam data center specs page. For a broader look at confidential computing use cases beyond the EU specifically, see our confidential computing infrastructure page. If you want to see how TDX affects real workload performance before committing, our TDX performance benchmarks on bare metal covers overhead across several workload types.

FAQ

Does Intel TDX require 1TB of RAM?

No. Intel’s requirement is full memory channel population across both CPU sockets, not a specific RAM total. OpenMetal’s 1TB figure comes from stocking 64GB RDIMMs to fully populate 16 DIMM slots, which is our production configuration rather than an Intel mandate.

Is TDX available on OpenMetal’s Amsterdam hardware today?

Yes. Our XL v4 server, built on Emerald Rapids with fully populated memory channels, is TDX-active out of the box and currently in stock in Amsterdam.

What does TDX protect that standard encryption doesn’t?

Standard encryption typically protects data at rest and in transit. TDX protects data in use, meaning the contents of memory while a workload is actively running, by isolating it into a hardware-encrypted Trust Domain inaccessible even to the infrastructure provider.

Does TDX make a workload GDPR or DORA compliant?

No single technical control makes a workload compliant on its own. TDX is a hardware-level safeguard that can support a compliance program’s technical requirements around data-in-use protection. Whether it satisfies a specific regulatory obligation depends on your full compliance program and should be confirmed with your legal or compliance team.

Can I run TDX workloads while keeping data resident in the EU?

Yes. Our Amsterdam data center provides both EU data residency and TDX-capable hardware in the same facility, so the two requirements don’t have to be solved by different vendors or locations.


Chat With Our Team

We’re available to answer questions and provide information.

Reach Out

Schedule a Consultation

Get a deeper assessment and discuss your unique requirements.

Schedule Consultation

Try It Out

Take a peek under the hood of our cloud platform or launch a trial.

Trial Options

 

 

 Read More on the OpenMetal Blog

Running Confidential Computing Workloads in the EU on Amsterdam

Jul 24, 2026

We explain what Intel TDX confidential computing actually protects, confirm which hardware configuration delivers it in our Amsterdam data center today, and walk through why pairing TDX with EU data residency matters for regulated workloads.

EU Data Residency and Data Sovereignty Are Not the Same Thing

Jul 20, 2026

We break down the real difference between data residency and data sovereignty, why many “sovereign cloud” claims from US-owned providers don’t hold up under scrutiny, and what EU-based infrastructure can and can’t actually guarantee.

Why MEV Block Building Infrastructure Is Moving to TDX Bare Metal

Jul 09, 2026

The operator trust problem in MEV block building has a hardware solution. This article explains why Intel TDX has become the substrate of choice for confidential block building, and what bare metal adds that cloud TDX doesn’t.

Enabling Intel SGX and TDX on OpenMetal v4 and v5 Servers: Hardware Requirements

Jun 11, 2026

Learn how to enable Intel SGX and TDX on OpenMetal’s v4 and v5 servers. This guide covers required memory configurations (full channel allotment and 1TB RAM), hardware prerequisites, and a detailed cost comparison for provisioning SGX/TDX-ready infrastructure.

Running Confidential AI Inference on Bare Metal TDX Servers

Jun 11, 2026

Running AI inference on sensitive data requires hardware-level isolation, not just software controls. This guide covers how to build a confidential inference pipeline on OpenMetal’s XL v5 using Intel TDX, including Trust Domain setup, vLLM deployment, attestation, and storage architecture.

How MSPs Can Win Clients With Compliance and Private Cloud

Apr 30, 2026

Enterprise clients in regulated industries are asking harder infrastructure questions than most MSPs are equipped to answer. This article covers where the Microsoft stack has limits for compliance workloads, what private cloud adds to an MSP’s portfolio, and how to start without overhauling your entire stack.

Is Your AI Infrastructure Ready for the EU AI Act?

Apr 28, 2026

EU AI Act compliance is more than a legal project, but an architecture decision. This article breaks down the four infrastructure requirements high-risk AI systems must meet, where public cloud creates compliance gaps, and how dedicated EU infrastructure with hardware-level isolation changes the picture.

Why Proof-of-Stake Validators Outgrow Their Hosting Provider

Apr 21, 2026

Professional PoS validator operations have specific infrastructure demands that general hosting and public cloud weren’t built for. This guide covers the five requirements that separate adequate from production-grade hosting, where public cloud falls short, and what to verify before signing with a provider.

Evaluating Intel TDX for Production Workloads in 2026

Mar 11, 2026

Intel TDX has matured past the proof-of-concept stage, but “production-ready” means different things depending on your workload and team. This guide covers real performance overhead figures, operational complexity, hardware options on OpenMetal v4 and v5, and when to adopt vs. wait.

Secret Network to Silicon: Building a True Confidential Computing Stack with Intel TDX on Bare Metal

Mar 01, 2026

Secret Network proves encrypted smart contracts work. Intel TDX on bare metal completes the confidential computing stack from application layer to silicon.