VAST Data Previews Secure AI for Sensitive Data Kept Under Customer Control
DataEnclave aims to protect both customer records and a model builder’s proprietary work while they run on the same infrastructure. It is in preview, with release expected in early 2027.
Listen to this story
The audio brief
Story brief
3 key pointsVAST Data is previewing DataEnclave, a confidential-computing product intended to let customers run outside models on sensitive data without exposing either party’s assets to the infrastructure operator. It uses cryptographic attestation before releasing separately controlled decryption keys and combines protected CPU and NVIDIA GPU processing; disconnected deployments are also planned. Sharon AI will offer it...
- 01
VAST announced DataEnclave on September 22 as a DataEngine capability built on NVIDIA Confidential Computing.
- 02
VAST says the system encrypts VM and GPU memory and GPU interconnect traffic, while customers and model builders retain separate keys.
- 03
Fortanix supports on-site verification and key handling for disconnected deployments; VAST also describes a searchable audit trail.
A company could bring an outside AI model to its sensitive data without giving the infrastructure operator access to either one. That is the promise of VAST Data’s newly previewed DataEnclave. VAST says the system checks a protected computing environment before unlocking the customer’s data and the model builder’s proprietary assets. Whether that arrangement works for customers at scale remains a question for its planned release.
Two owners, one protected workspace
VAST announced DataEnclave on September 22 as a capability within its DataEngine, built on NVIDIA Confidential Computing. It is aimed at organizations that cannot readily send sensitive information to an external AI service. Model builders face the opposite problem: putting their proprietary models on machines they do not trust. The product is designed to let both sides work in a customer data center or on trusted cloud hardware without giving up control of their assets.
The crucial step comes before the model starts working. DataEnclave uses cryptographic attestation—a check that the hardware environment and its enforced policy match what was approved—before releasing the keys needed to decrypt data and model assets. Those assets are then loaded into an isolated environment for processing. VAST says the design keeps them out of reach of infrastructure operators and administrators while they are in use.
Protection extends into processing
Ordinary encryption can protect information in storage and transit, but VAST’s pitch also covers the moment a model uses it. The company says DataEnclave combines protected CPU environments with NVIDIA GPUs in confidential-computing mode. It encrypts virtual-machine memory, GPU memory and the traffic connecting GPUs, while isolating the active workload from other users of the hardware.
- The customer controls the keys for its data; the model builder separately controls the keys for its model. VAST says integrations with each party’s own key-management system preserve that split.
- For sites that cannot connect to an outside service, VAST says it supports fully disconnected deployments, with Fortanix helping provide on-site verification and key handling.
- VAST says it records environment checks, key releases and protected-workspace actions in a searchable audit trail, so operators can review what ran under which verified policy without seeing the protected assets.
Sharon AI takes the regional route
A day after VAST’s announcement, Sharon AI said it would offer DataEnclave through its AI Factory platform in Australia and the Asia-Pacific region. Sharon plans to use it for models hosted onshore, including for organizations that need disconnected environments. Its claim is unusually demanding for an infrastructure provider: neither the customer’s data nor the model builder’s weights should be accessible to Sharon while the model runs.
That separation is also the attraction for model providers. In VAST’s launch announcement, partners described potential uses involving sensitive code, financial or health records, voice data and restricted video archives. Those examples show the range VAST is targeting, not that every proposed workload is already running through DataEnclave. The common requirement is that the model goes to the data without either owner handing its protected asset to the machine’s operator.
The release is still ahead
DataEnclave is in preview. VAST expects it to ship in the first quarter of 2027 through the company and participating equipment partners, including Cisco and Supermicro. Sharon’s collaboration sets out a route to regional customers, but its announcement does not give a separate date for offering the service. For now, the test is whether the planned protections and key controls can be delivered in deployments where neither the data owner nor the model builder wants to trust the operator on its word alone.
Sources
- vastdata.comVAST Data Launches DataEnclave to Unite AI Models and Enterprise Data
- australiancybersecuritymagazine.com.auVAST Data launches DataEnclave confidential AI capability with Sharon AI - Australian Cyber Security Magazine
- prnewswire.comSharon AI Collaborates with VAST Data on the Launch of DataEnclave, Bringing Leading AI Models to Customer Controlled Infrastructure
Reader comments
Newest comments first. Replies stay oldest first.