VAST Data Introduces DataEnclave to Bring Leading AI Models & Enterprise Data Together on Trusted Infrastructure

193 Views

VAST Data, the AI Operating System company, today announced VAST DataEnclave, the confidential AI capability of the VAST DataEngine, built on NVIDIA Confidential Computing, with the support of ecosystem partners including top AI model builders, AI clouds, AI security and leading AI hardware providers. By enabling deployment inside customer data centers or trusted cloud hardware, including environments where leading AI models could not previously operate, VAST Data, in collaboration with NVIDIA and partners, is bringing proprietary and open AI models across a range of modalities to the world’s most sensitive data – while giving customers control over cost, performance, model selection and data privacy, and giving model builders reach into environments they could never serve before.

Across financial services, healthcare, government and other highly regulated industries, some of the world’s most valuable data remains inside tightly controlled environments where moving it to an external AI service is impractical or prohibited. That creates a fundamental challenge for AI: sensitive data often cannot move to where leading models run, while model builders cannot distribute proprietary models into infrastructure they do not trust.

VAST DataEnclave extends the VAST AI Operating System to resolve this impasse with a hardware-isolated secure runtime and cryptographic attestation that verifies the environment and its enforced policy before sensitive assets, such as proprietary models and sensitive data, are decrypted and loaded into the secure enclave container for analysis, where they remain protected in CPU and GPU memory during processing. Customer data keys remain under customer control, model keys and weights remain within the model builder’s trust domain, and infrastructure operators and administrators cannot access either while they are being processed.

Looking ahead, today’s announcement expands the range of advanced models organisations can deploy within their own environments, while advancing VAST’s broader AI Operating System vision, in which models are managed as a logical resource alongside data rather than as applications that simply sit on top of the infrastructure. As organisations adopt ecosystems of specialised models, each fit for a different purpose, priced differently and subject to different levels of trust, the AI OS will increasingly need to pair the right model with the right task and govern those models across environments: determining where they run, what data they can access, who or what can use them and the policies under which they operate. As organisations increasingly fine-tune their own models and agents generate specialised intelligence from their interactions, model weights become a new class of enterprise intellectual property, making secure management at scale an increasingly important function of the operating system.

“Models are becoming a resource the operating system has to manage, the same way it manages data,” said Renen Hallak, Founder & CEO of VAST Data. “That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else. Bringing leading AI models securely to the world’s most sensitive data is where this starts. Where it leads is a world where every organisation is managing an ecosystem of fine-tuned models that represent its true intellectual property. The VAST AI Operating System is what keeps them secure, governed and useful.”

Bringing AI to Sensitive Data

Conventional encryption protects model weights while they are stored and while they move across the network. Confidential computing extends encryption and protects data during execution. NVIDIA Confidential Computing, now in its third generation on Hopper, Blackwell, and Rubin platforms, ensures that sensitive data and models are only released during execution after the workload is verified and a secure enclave has been established. VAST DataEnclave uses NVIDIA Confidential Computing to create a secure container runtime and attestation service directly within the VAST DataEngine. Proprietary models execute inside secure enclaves established through CPU and GPU trusted execution environments.

Key capabilities include:

  • Hardware-Isolated Execution: Protects workloads inside confidential virtual machines and containers, using NVIDIA Confidential Computing to encrypt guest memory, GPU memory and NVLink traffic while isolating active data and models from infrastructure operators, administrators and other tenants sharing the same hardware.
  • Verify-Before-Decrypt Attestation: Cryptographically verifies the trusted execution environment – including NVIDIA GPU attestation – before releasing decryption keys, ensuring sensitive assets are accessible only to approved workloads running in a trusted environment.
  • Independent Key Control: Enables enterprises and model builders to maintain their respective keys within their own trust domains through Bring Your Own Key Management System (KMS) integrations so each party controls and enforces policy on its own assets. This protects an enterprise’s own fine-tuned weights, which are fast becoming critical IP, as much as a model builder’s base weights.
  • Connected or Air-Gapped Deployment: Supports connected or fully air-gapped environments with DataEnclave deployments using attestation services built on the open CNCF Trustee stack, or in partnership with Fortanix via its Confidential AI infrastructure for fully sovereign AI.
  • Governed and Auditable by Design: Records attestation events, key releases and enclave lifecycle actions in a tamper-proof, queryable audit trail in the VAST DataBase, providing visibility into what ran, where and under what verified policy without exposing protected data or weights.
  • Secure Agent Sandboxes: The same DataEngine secure runtime provides isolated execution environments for AI agents through VAST AgentEngine, enforcing policy over the data, systems and tools agents can access and the actions they can take. Unlike people, agents are not accountable for their actions, so they need identity, a contained runtime and observability into when, how and why they each took action, plus auditability if something went wrong.

“Model weights are fast becoming the most valuable intellectual property in the world. Base weights define the value of frontier models, while fine-tuned weights will increasingly represent the proprietary intelligence of AI-driven enterprises,” said Jeff Denworth, Co-Founder at VAST Data. “As the stakes get higher, so does the need to secure enterprise data so customers can apply the most intelligent AI models against it. Today, VAST Data – in partnership with NVIDIA – is moving the industry forward with a comprehensive approach to verifying previously untrusted computing environments and unlocking the ability to run any model against any data, anywhere.”

VAST DataEnclave extends confidential execution across the infrastructure where AI models and sensitive data are processed, combining hardware isolation and verifiable attestation to protect both while they are in use.

“Enterprise data is essential to accurate, usable AI – and keeping business data confidential is critical to protecting IP in the age of agents. VAST Data’s integration of NVIDIA Confidential Computing delivers protection for both enterprises and model builders, providing security, identity, permissions, governance and compliance as a foundation of the agent architecture.”

– Justin Boitano, Vice President of Enterprise AI at NVIDIA 

Watch the video: VAST Founder & CEO Renen Hallak and NVIDIA Vice President of Enterprise AI Justin Boitano discuss the architecture behind VAST DataEnclave.

An Ecosystem for {un}bounded AI

VAST is bringing together model builders, AI clouds, AI security, and infrastructure providers around a shared architecture for customer-controlled environments. Customers can now execute on their AI strategies without running into boundaries that previously cut off access to cloud-hosted models. At the same time, they can bring these newly available models within their own carefully constructed boundaries to manage cost, security, and other operational concerns.

“Nscale and VAST have worked together for years to build AI environments where enterprises and governments retain control of their data. DataEnclave takes that a step further, combining Nscale’s sovereign AI cloud infrastructure with VAST’s attestation-based architecture so frontier models and sensitive data can come together securely in a verified environment. That opens up workloads that were previously out of reach and expands what sovereign AI infrastructure can deliver.”

– Tom Burke, Chief Revenue Officer, Nscale 

“Customers around the world have unique regulatory and sovereignty requirements, and they are asking for AI that is encrypted end-to-end—not just at rest but in motion and during inference. Cohere has prioritised confidential compute for some time, and by working with VAST we can now bring that same level of security and governance to any data center, wherever customers choose to deploy. Together we are building a confidential compute strategy that gives customers more choice and more control, so they can run our models and the agents they build on North where their data already lives: their infrastructure, their jurisdiction, their rules.”

Frank O’Dowd, Chief Revenue and Commercial Officer at Cohere

“CrowdStrike SafeMind models are trained on the world’s largest pureplay cyber dataset, and that intelligence relies on the trust built around it. Defenders in regulated industries want to put these models to work against their most sensitive data, inside their own boundaries, while maintaining control of their data and protecting the models themselves. VAST’s attestation-based approach brings model weights and enterprise data together in a verified environment while keeping both protected and under their respective owners’ control. That’s what it takes to put frontier security models to work where the stakes are highest.”

Dr. Bartley Richardson, Chief AI and Autonomous Systems Officer, CrowdStrike

“The most sensitive data in the world sits in tables. Confidential computing turns trust from a promise into a proof, and that’s the difference between AI that regulated industries can pilot and AI they can actually put into production. The guarantee comes from the architecture, not our word. Fundamental’s Large Tabular Model, NEXUS, can run directly inside a bank’s or health system’s own infrastructure, in a sealed execution environment where our model and their records are exposed to neither party, working in environments we could never have reached otherwise.”

Jeremy Fraenkel, CEO of Fundamental

“Video is where an enormous amount of institutional knowledge lives, and it is also the data that is hardest to move. Archives, sensor feeds and full-motion video sit in environments that are disconnected by design. TwelveLabs built our video intelligence models Marengo and Pegasus to run wherever that video already is, with no degradation in capability. With VAST DataEnclave, we can bring video intelligence into the most restricted environments while keeping our models protected and our customers’ footage entirely under their control.”

– Jae Lee, CEO & Co-founder, TwelveLabs

Watch the video: See how VAST DataEnclave enables model builders to bring proprietary AI models to sensitive enterprise data while protecting model IP and customer data.

VAST DataEnclave also enables AI cloud providers worldwide to deliver attested, sovereign environments where model builders, enterprises, and governments retain control over their IP and data within their own jurisdictions. Because isolation is enforced in hardware, sovereign and regional AI clouds can establish verifiable trust without dedicating entire machines to a single tenant, and can offer the newest accelerated computing systems, such as NVIDIA Vera Rubin infrastructure, from facilities operated within national borders.

This new VAST AI OS capability also provides OEMs the opportunity to deliver integrated confidential AI infrastructure that brings together trusted execution, accelerated computing and VAST-powered data infrastructure.

Availability

VAST DataEnclave is being previewed today and will ship in Q1 2027 through VAST Data and participating OEM partners, including Cisco and Supermicro.