The post has been translated automatically. Original language: Russian
Digital Qazaqstan Ltd (UK)
Category: Security / System Architecture / Cloud
Title: Zero Trust in the cloud: Confidential Space and hardware protection of AI systems (SRE Standard)
Concluding a series of publications on Enterprise development standards, it is impossible to avoid the topic of security. For the UK banking and fintech sector (FCA compliance), data protection is the basis. At Digital Qazaqstan Ltd (UK), we are building an architecture based on the principle of Zero Trust, where we do not trust even the cloud provider itself.
Tools for ensuring sovereignty in the GCP:
- Confidential Space: When AI processes confidential data (PII), we use hardware isolation of virtual machines (AMD SEV/Intel TDX) with remote attestation (vTPM). This ensures that the data is protected in use.
- Cloud Armor & NGFW: Perimeter construction begins with protection at the edge of the network (Edge). Naming lists, rate limiting, and L7 ILB allow you to cut off DDoS attacks before they reach Serverless containers.
- Cloud KMS Autokey & IAM: Automatic Encryption Key Management (CMEK) and Hard segmentation of access rights (VPC Service Controls).
The final conclusion for Astana Hub is that Scaling a startup is impossible without user trust. Trust in 2026 is not based on legal policies (Privacy Policy), but on mathematically provable hardware cryptography.
Digital Qazaqstan Ltd Strategic Software Engineering & Architecture. Office 1142, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW, United Kingdom. © 2026 Digital Qazaqstan Ltd. All rights reserved.
Digital Qazaqstan Ltd (UK)
Категория: Безопасность / Системная архитектура / Cloud
Заголовок: Zero Trust в облаке: Confidential Space и аппаратная защита ИИ-систем (SRE Standard)
Завершая серию публикаций о стандартах Enterprise-разработки, невозможно обойти тему безопасности. Для банковского и финтех сектора Великобритании (FCA compliance) защита данных — это базис. В Digital Qazaqstan Ltd (UK) мы выстраиваем архитектуру по принципу Zero Trust, где мы не доверяем даже самому облачному провайдеру.
Инструменты обеспечения суверенитета в GCP:
- Confidential Space: Когда ИИ обрабатывает конфиденциальные данные (PII), мы используем аппаратную изоляцию виртуальных машин (AMD SEV/Intel TDX) с удаленной аттестацией (vTPM). Это гарантирует, что данные защищены in use.
- Cloud Armor & NGFW: Построение периметра начинается с защиты на границе сети (Edge). Списки именования, rate limiting и L7 ILB позволяют отсекать DDoS-атаки до того, как они дойдут до Serverless-контейнеров.
- Cloud KMS Autokey & IAM: Автоматическое управление ключами шифрования (CMEK) и жесткое сегментирование прав доступа (VPC Service Controls).
Финальный вывод для Astana Hub: Масштабирование стартапа невозможно без доверия пользователей. Доверие в 2026 году строится не на юридических политиках (Privacy Policy), а на математически доказуемой аппаратной криптографии.
Digital Qazaqstan Ltd Strategic Software Engineering & Architecture. Office 1142, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW, United Kingdom. © 2026 Digital Qazaqstan Ltd. All rights reserved.