I can also see it possible to 'self-host' things once you use a cloud where you can do 'confidential computing' stuff aka. the hosting provider does not have access to whatever it is you're running. That functionality is there on the major clouds now (EC2, Azure, GCP) all have the Intel/AMD/Arm TME/SEV/RME stuff implemented but finding it on a device that you can self-host in your little storage cupboard is impossible right now (EPYC 9004 seems to be the lowest available with that technology). At a minimum you want secure boot + attestation + memory encryption if you are not in control of the hardware space itself.