AI model and encrypted enterprise data converging inside a secure GPU computing enclave in a data center.
Article Icon
Rachel Horton
@
TechArena
Sep 22, 2026

VAST DataEnclave Guards Model Weights and Enterprise Data at Once

VAST Data today introduced VAST DataEnclave, a confidential AI runtime that lets model builders place proprietary models inside a customer's own data center and run them against regulated data. The capability, built on NVIDIA Confidential Computing, previews today and ships in Q1 2027 through VAST and OEM partners including Cisco and Supermicro.

DataEnclave keeps data and model weights encrypted while they are in use, and releases decryption keys only after it verifies the environment those assets are about to enter. That gives an enterprise a way to apply a frontier model to data it cannot move, and gives a model builder a way to deploy weights into infrastructure it does not own.

The Gap at Execution

Encryption already covers model weights on storage and across the network. The gap opens at execution. To serve a prompt, weights decrypt into GPU memory, where the infrastructure's administrators, a compromised hypervisor, other tenants sharing that memory and firmware exploits can all reach them.

Enterprises and model builders each give something up to that exposure. Banks, hospitals and government agencies hold data they cannot ship to a hosted AI service, so the best models never see it. Model builders treat base weights as their most valuable asset and keep them on a short list of trusted platforms, which puts air-gapped and sovereign facilities out of reach. VAST, citing Synergy Research, puts about 50% of the world's data somewhere frontier models cannot go today.

Verify First, Decrypt Second

DataEnclave adds a secure container runtime and an attestation service inside the VAST DataEngine.

Hardware-isolated execution runs workloads in confidential virtual machines and containers, using trusted execution environments from Intel, AMD and NVIDIA Vera to encrypt guest memory, GPU memory and NVLink traffic. Active data and models stay isolated from infrastructure administrators and from other tenants on the same hardware.

Verify-before-decrypt attestation checks the trusted execution environment, including NVIDIA GPU attestation, before any decryption key is released. VAST states the rule plainly in its briefing: "No attestation. No access."

Independent key control lets each party hold its own keys in its own trust domain through bring-your-own KMS integrations. The model builder protects base weights. The enterprise protects its data and the fine-tuned weights that increasingly carry its own IP.

That key control is what VAST says separates DataEnclave from the confidential VMs cloud providers already sell. The weight owner verifies the platform itself, keeps its own keys and gets the same arrangement whether the deployment sits on-premises, in a cloud or behind an air gap.

VAST logs attestation events, key releases and enclave lifecycle actions to a tamper-proof audit trail in the VAST DataBase. Deployments run connected or fully air-gapped, on the open CNCF Trustee stack or on Fortanix confidential AI infrastructure. The same runtime gives agents isolated sandboxes through VAST AgentEngine.

More Than 20 Partners at Launch

Cohere, CrowdStrike, Deepgram, Factory, Fundamental, NVIDIA and TwelveLabs are among the model builders signed on. Cisco and Supermicro will deliver integrated confidential AI systems. BUZZ HPC, Nscale and Sharon AI plan to offer attested sovereign environments, and Fortanix supplies the attestation and key management layer.

Fundamental sells NEXUS, a large tabular model it says runs inside a bank's or health system's own infrastructure.

"Confidential computing turns trust from a promise into a proof, and that's the difference between AI that regulated industries can pilot and AI they can actually put into production," said Jeremy Fraenkel, CEO of Fundamental.

Sovereign clouds gain a second benefit. Hardware enforces the isolation, so a regional provider can host proprietary models and regulated data without dedicating a whole machine to each tenant.

Models as a Managed Resource

DataEnclave also advances a larger VAST position. Models belong under the operating system rather than on top of it, managed as a logical resource alongside data and paired to tasks by purpose, cost and security constraints.

"Models are becoming a resource the operating system has to manage, the same way it manages data," said Renen Hallak, founder and CEO of VAST Data. "That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else."

TechArena Take

The most interesting part of this launch sits one level above the enclave. VAST is treating models the way it treats data, as a resource the operating system manages, and DataEnclave turns that idea into an enforceable policy about where a model runs and who holds the keys.  

Operators running more than a handful of models across their environments should look closely at what it means to govern models with the same controls they already apply to data. The detail worth the most attention here is key control over fine-tuned weights. Those weights carry what an organization has learned about its own business, and many teams still treat them as a byproduct of training. Giving enterprises the same protection the frontier labs hold for their base weights sets a precedent we expect the rest of the market to follow.

The partner list tells its own story. Seven model builders agreed to send their models into environments they do not control, which points to where enterprise AI is heading. Models travel to the data. For financial services, healthcare and government, that direction of travel opens use cases that have been waiting on it.

We will be watching two things through 2027: the first deployments in regulated sectors, and the performance envelope operators get with attestation and enclave execution in the path.

Subscribe to Our Newsletter

Read the latest in the world of AI, data center, and edge innovation.