Skip to content
AI.info

The Pulse

VAST Data Unveils Hardware-Isolated Runtime for Confidential AI

VAST Data introduced DataEnclave, a confidential AI runtime built on NVIDIA Confidential Computing. The system is designed to let proprietary models process sensitive enterprise data while keeping both model weights and customer information

VAST Data Unveils Hardware-Isolated Runtime for Confidential AI

AI.info Team ·

VAST Data says enterprises should not have to send sensitive information to an external AI service, while model providers should not have to place proprietary weights on infrastructure they do not control. The company’s answer is DataEnclave, a hardware-isolated runtime announced on September 22 that is designed to bring protected models and protected data together without giving either side access to the other’s assets.

DataEnclave is a new confidential AI capability within VAST DataEngine and the VAST AI Operating System. Built on NVIDIA Confidential Computing, it uses trusted execution environments across CPUs and GPUs, cryptographic attestation and independent key management to control when encrypted models and data can be decrypted.

VAST is previewing the system now and says it will ship in the first quarter of 2027 through VAST Data and participating original equipment manufacturers, including Cisco and Supermicro.

VAST targets the trust problem between models and data

Regulated organizations in financial services, healthcare and government often keep their most sensitive records inside tightly controlled environments. Sending those records to a hosted AI service may conflict with security rules, data-sovereignty requirements or internal policies. Model companies face the opposite concern: placing proprietary weights on customer-owned or third-party infrastructure can expose them to administrators who operate the hardware.

VAST describes DataEnclave as a way to separate ownership from infrastructure control. A model provider can deploy an encrypted model into an enterprise’s GPU cluster, while the enterprise keeps its data in its own environment. The model and data are decrypted only inside a confidential virtual machine, where VAST says the host operating system, hypervisor, infrastructure administrators and other workloads cannot access their unencrypted contents.

“Models are becoming a resource the operating system has to manage, the same way it manages data,” said Renen Hallak, founder and CEO of VAST Data. “That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else.”

Attestation comes before key release

DataEnclave does not release model or data keys when a workload simply starts. The runtime first produces hardware-signed evidence describing the environment, including the hardware, firmware, software and restrictions applied to the host. An attestation server controlled by the model provider or data owner checks that evidence against its security policy.

Only after the environment passes verification are the keys released. VAST says the keys arrive encrypted so they can be decrypted only inside the protected memory of the approved confidential virtual machine. If verification fails, the encrypted workload cannot start.

The process also gives owners continuing control after deployment. VAST’s technical description says attestation occurs when each workload launches, for every new replica and whenever a running workload requests another key. A model provider can therefore stop new instances from receiving keys if a license ends or a deployment no longer meets its requirements, without relying on the infrastructure operator to intervene.

DataEnclave uses NVIDIA’s confidential computing capabilities to protect guest memory, GPU memory and NVLink traffic. VAST says the system supports NVIDIA Hopper, Blackwell and Rubin platforms, and can operate in connected or fully air-gapped environments using attestation services based on the Cloud Native Computing Foundation’s Trustee project or through Fortanix’s confidential AI infrastructure.

Separate keys keep both parties in control

The design assigns different responsibilities to the enterprise and the model provider. Enterprises can retain control of keys for their own data and fine-tuned models through bring-your-own-key-management-system integrations. Model providers retain control of the keys for their base models and can decide which verified environments receive them.

VAST’s own example involves a bank deploying a proprietary model onto its GPU cluster. The bank’s retrieval system searches internal documents and sends selected excerpts to the model’s inference service. The bank’s administrators can operate the servers, but VAST says they cannot access the model’s decrypted container image or weights. The model provider, in turn, does not receive the bank’s underlying records and sees only the information the bank places in a prompt.

The company also draws a boundary around what DataEnclave does not guarantee. Hardware isolation can protect confidentiality and integrity during processing, but an infrastructure operator can still refuse to run a workload or stop one that is already running. The developers of each AI service remain responsible for the data that enters and leaves through its APIs.

Model builders and infrastructure partners join the preview

VAST lists Cohere, CrowdStrike, Deepgram, Factory, Fundamental, NVIDIA and TwelveLabs among the model and technology companies supporting the announcement. Their potential use cases range from voice and cybersecurity systems to coding agents, tabular models and video analysis.

“Enterprise data is essential to accurate, usable AI – and keeping business data confidential is critical to protecting IP in the age of agents,” said Justin Boitano, vice president of Enterprise AI at NVIDIA. “VAST Data’s integration of NVIDIA Confidential Computing delivers protection for both enterprises and model builders, providing security, identity, permissions, governance and compliance as a foundation of the agent architecture.”

VAST says the same secure runtime can support isolated environments for AI agents through VAST AgentEngine. Those sandboxes are intended to constrain which data, systems and tools an agent can access, while recording the actions it takes. The company says attestation events, key releases and enclave lifecycle activity are written to a tamper-resistant, queryable audit trail in VAST DataBase without exposing the protected models or data.

Shipping is scheduled for early 2027

The announcement remains a preview rather than a generally available product. VAST says DataEnclave will ship in the first quarter of 2027 through VAST Data and participating OEM partners, with Cisco and Supermicro named among the initial providers.

The immediate proposition is narrower than a general promise to run any AI workload privately: model owners must still define their policies, operate or trust an attestation service, and manage what their APIs expose. But the proposed runtime changes the point at which trust is established. Instead of relying only on contracts that prohibit administrators from inspecting data or model weights, DataEnclave is designed to withhold the decryption keys unless the hardware and software environment produces acceptable evidence.

Source

VAST Data

Explore

More articles