Last Updated on 8. October 2026
Digital government faces a trade-off that agencies feel every day. On one side is the need for control over applications, data, and operations. On the other, digital services require availability, scalability, and performance, qualities that cloud infrastructure delivers better than in-house data centers. But the real question isn’t on-premises or cloud. It’s how to bring the two together.
The Gap Many Overlook
When people think about cloud security, they think about encryption first. And it’s true: data at rest is encrypted by default today, for example on hard drives, in databases, and in backups. So is data in transit, through TLS, VPNs, and encrypted connections.
What gets far less attention: as soon as an application processes data, that data has to be available in plaintext in memory. No database encryption and no TLS protects it at that moment. This third dimension, data in use, is exactly what cloud providers, privileged administrators, external attackers in a compromised infrastructure, and foreign governments relying on laws such as the US CLOUD Act can access.
For government agencies and public institutions, this is not an abstract threat. It is the real reason why many applications still can’t be migrated to the cloud.
A12: The Platform Behind Specialized Government Applications
The A12 AI Low Code Platform has been open source since May 2026 and has been in production use for years, including for ELSTER, MODUL-F, the German Chambers of Tax Advisors, and the replacement of Access applications in Schleswig-Holstein, as well as at companies such as Allianz. It combines model-driven development with professional enterprise architecture: a TypeScript/React frontend, a Java/Spring Boot backend, open standards, and no vendor lock-in.
A12 runs on-premises, off-premises, or in the cloud, depending on what each agency requires. The platform can also run on C12, mgm’s cloud platform, with geo-redundant data centers in Germany, ISO 27001 certification, and GDPR compliance. But the problem of data visibility remains. Even in this hardened environment, data has so far been in plaintext during processing. C12 is certified and audited, yet no certificate protects against a compromised administrator or government access to the provider’s infrastructure.
What Confidential Computing Changes
This is where enclaive comes in. The German deep-tech security company uses confidential computing to protect data even while it is being processed, inside hardware-based, isolated trusted execution environments, also known as enclaves. A12 applications can run in such an enclave, shielded from any outside access, from privileged admins, and from the infrastructure provider itself. Not even the platform operator can technically read what is processed inside the enclave. What matters most for adoption in practice: the application itself doesn’t need to change. No refactoring, no new interfaces, no changes to the code.
Regulatory Tailwinds
The requirement isn’t new, but it is becoming more concrete. In C5:2026, its Cloud Computing Compliance Criteria Catalogue, Germany’s Federal Office for Information Security (BSI) has formally established confidential computing as a standalone criterion for the first time. That’s a clear signal that the protection of data during processing will need to be auditable going forward. For processing health data in Germany’s telematics infrastructure, gematik already mandates technical operator exclusion: the infrastructure operator must not have access to the processed data, not only by contract but also technically. NIS2 and DORA add further pressure on resilience and data protection. The consequence for agencies: compliance no longer has to be promised. It can be proven technically.
What This Makes Possible
The same approach can be applied to A12-based government applications. Confidential computing is planned as an optional module on C12 for all applications where the sensitivity of the data calls for it. A pilot can be set up quickly.
Agencies that run A12 applications on third-party infrastructure or in a hybrid cloud can activate an additional layer of protection with enclaive. The result isn’t a compromise between sovereignty and performance. It delivers both. For public administration, this means that cloud migration can be discussed without restrictions for the first time, even for applications with the strictest data protection requirements. Not because you trust the provider. Because you no longer have to.
More information
• Website: A12 AI Low Code Platform for Public Sector
• Website: Confidential Computing by enclaive





