AI

VAST Data Launches DataEnclave for Confidential AI

Bakhtawar Majid

By: Bakhtawar Majid

4 min read

The new confidential AI runtime uses NVIDIA Confidential Computing to let model providers and enterprises bring proprietary models and sensitive data together inside trusted infrastructure. 

[For more news, click here]

Sensitive enterprise data is increasingly becoming a limiting factor in where advanced AI can be deployed. Banks, healthcare organizations, government agencies and other regulated businesses may have access to increasingly capable models, but moving the underlying data to an external service is not always an option. VAST Data is addressing that constraint with DataEnclave, a confidential AI capability designed to bring models into customer-controlled environments while keeping both the data and proprietary model weights protected during processing. 

Built into VAST DataEngine and based on NVIDIA Confidential Computing, DataEnclave uses hardware isolation and cryptographic attestation to establish a trusted environment before protected assets are made available to a workload. The approach is aimed at a problem on both sides of the AI deployment equation: enterprises need to control where sensitive information is processed, while model developers need to protect the weights that contain their intellectual property. VAST says DataEnclave allows the two to operatewithin the same environment without either party taking control of the other's protected assets. Independent coverage from NAND Research has also identified this two-sided trust issue as central to the technology's purpose. 

Before a workload can access protected assets, DataEnclave verifies the trusted execution environment through cryptographic attestation, including NVIDIA GPU attestation. Only after the environment and its policies have been verified are the required keys released. During processing, the company says the data and model weights remain protected in CPU and GPU memory, while NVIDIA Confidential Computing also encrypts GPU memory and NVLink traffic. Customer data keys remain under customer control, while model keys and weights stay within the model provider's trust domain, with Bring Your Own Key Management System integrations available to maintain that separation. 

The system also includes an audit layer for activity inside the protected environment. VAST says DataEnclave records attestation events, key releases and enclave lifecycle actions in a tamper-proof, queryable audit trail in VAST DataBase, allowing customers to see what ran, where it ran and under which verified policy without exposing the protected data or model weights. Deployments can run in customer data centers, trusted cloud environments or fully air-gapped settings, with VAST citing the open CNCF Trustee stack and Fortanix's confidential AI infrastructure as options for attestation and key management. 

"Models are becoming a resource the operating system has to manage, the same way it manages data," said Renen Hallak, Founder & CEO of VAST Data. "That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else. Bringing leading AI models securely to the world's most sensitive data is where this starts. Where it leads is a world where every organization is managing an ecosystem of fine-tuned models that represent its true intellectual property. The VAST AI Operating System is what keeps them secure, governed and useful." 

The launch includes model companies working across different types of AI, including Cohere, CrowdStrike, Deepgram, Factory, Fundamental and TwelveLabs. Their applications span language, cybersecurity, voice, coding, tabular data and video, giving the announcement a range of potential enterprise workloads rather than tying the technology to a single model or use case. The participating companies also illustrate the commercial premise behind the architecture: a model provider can make its software available inside infrastructure it does not operate, while the customer keeps control of the data being processed. 

"Enterprise data is essential to accurate, usable AI – and keeping business data confidential is critical to protecting IP in the age of agents. VAST Data’s integration of NVIDIA Confidential Computing delivers protection for both enterprises and model builders, providing security, identity, permissions, governance and compliance as a foundation of the agent architecture." Said Justin Boitano, Vice President of Enterprise AI at NVIDIA. 

The same runtime is also intended to support AI agents through VAST AgentEngine, where policies can govern which data, systems and tools an agent can access. Beyond enterprise data centers, VAST is working with AI infrastructure providers including BUZZ HPC, Nscale and Sharon AI on sovereign deployments, while Cisco and Supermicro are participating as OEM partners. The company says the architecture can support regional and sovereign AI environments in which model providers, enterprises and governments need to keep their respective data and intellectual property within defined jurisdictions. 

DataEnclave is being previewed now and is scheduled to ship in the first quarter of 2027 through VAST Data and participating OEM partners, including Cisco and Supermicro. The period leading up to that release will give customers time to assess how confidential AI fits their existing requirements around key management, auditing, policy enforcement and isolated infrastructure. For organizations that have held back particular AI workloads because their data could not leave controlled environments, the planned release provides a concrete deployment path to consider as they decide which models can be used in production. 


Related Articles 

VAST Data and CrowdStrike Extend Cybersecurity to Enterprise AI Data 

VAST Data and AMD Expand AI Infrastructure Alliance to Tackle the Industry's Inference Bottleneck 

WSO2 Brings AI Governance Under Customer Control 


 


 

Share this article

Related Articles