VAST Data Previews Secure AI for Sensitive Data Kept Under Customer Control

DataEnclave aims to protect both customer records and a model builder’s proprietary work while they run on the same infrastructure. It is in preview, with release expected in early 2027.

By 3 min read
VAST Data Previews Secure AI for Sensitive Data Kept Under Customer Control
VAST Data Previews Secure AI for Sensitive Data Kept Under Customer Control

Listen to this story

The audio brief

About 1:30
0:001:30
Read transcript
VAST Data is previewing DataEnclave, a system designed to let an outside AI model work on sensitive customer data without giving the infrastructure operator access to either side’s protected assets. The idea is to bring the model to the data, rather than send records to an external AI service. Before processing begins, cryptographic attestation checks that the computing environment matches an approved configuration. Only then are separate keys released: the customer controls the data key, while the model builder controls the key for its proprietary model. VAST says the protected workspace encrypts virtual-machine and GPU memory, as well as traffic between GPUs, while the workload runs. That matters for organizations that cannot readily expose health, financial, or other sensitive records—and for model makers wary of handing valuable models to an infrastructure provider. VAST also describes disconnected deployments, with Fortanix supporting on-site verification and key handling, plus a searchable audit trail. Sharon AI said it plans to offer the service through its AI Factory in Australia and across Asia-Pacific. But that announcement did not set a service date. DataEnclave is still in preview, and VAST expects release in the first quarter of 2027 through itself and equipment partners including Cisco and Supermicro. The open question is whether those separate controls can be delivered reliably at scale, especially when neither party is willing to trust the operator with its assets.

Story brief

3 key points

VAST Data is previewing DataEnclave, a confidential-computing product intended to let customers run outside models on sensitive data without exposing either party’s assets to the infrastructure operator. It uses cryptographic attestation before releasing separately controlled decryption keys and combines protected CPU and NVIDIA GPU processing; disconnected deployments are also planned. Sharon AI will offer it...

  1. 01

    VAST announced DataEnclave on September 22 as a DataEngine capability built on NVIDIA Confidential Computing.

  2. 02

    VAST says the system encrypts VM and GPU memory and GPU interconnect traffic, while customers and model builders retain separate keys.

  3. 03

    Fortanix supports on-site verification and key handling for disconnected deployments; VAST also describes a searchable audit trail.

A company could bring an outside AI model to its sensitive data without giving the infrastructure operator access to either one. That is the promise of VAST Data’s newly previewed DataEnclave. VAST says the system checks a protected computing environment before unlocking the customer’s data and the model builder’s proprietary assets. Whether that arrangement works for customers at scale remains a question for its planned release.

Two owners, one protected workspace

VAST announced DataEnclave on September 22 as a capability within its DataEngine, built on NVIDIA Confidential Computing. It is aimed at organizations that cannot readily send sensitive information to an external AI service. Model builders face the opposite problem: putting their proprietary models on machines they do not trust. The product is designed to let both sides work in a customer data center or on trusted cloud hardware without giving up control of their assets.

The crucial step comes before the model starts working. DataEnclave uses cryptographic attestation—a check that the hardware environment and its enforced policy match what was approved—before releasing the keys needed to decrypt data and model assets. Those assets are then loaded into an isolated environment for processing. VAST says the design keeps them out of reach of infrastructure operators and administrators while they are in use.

Protection extends into processing

Ordinary encryption can protect information in storage and transit, but VAST’s pitch also covers the moment a model uses it. The company says DataEnclave combines protected CPU environments with NVIDIA GPUs in confidential-computing mode. It encrypts virtual-machine memory, GPU memory and the traffic connecting GPUs, while isolating the active workload from other users of the hardware.

  • The customer controls the keys for its data; the model builder separately controls the keys for its model. VAST says integrations with each party’s own key-management system preserve that split.
  • For sites that cannot connect to an outside service, VAST says it supports fully disconnected deployments, with Fortanix helping provide on-site verification and key handling.
  • VAST says it records environment checks, key releases and protected-workspace actions in a searchable audit trail, so operators can review what ran under which verified policy without seeing the protected assets.
VAST’s video explains its proposed approach to bringing proprietary models to customer data while protecting both during processing. Video via vastdata.com.

Sharon AI takes the regional route

A day after VAST’s announcement, Sharon AI said it would offer DataEnclave through its AI Factory platform in Australia and the Asia-Pacific region. Sharon plans to use it for models hosted onshore, including for organizations that need disconnected environments. Its claim is unusually demanding for an infrastructure provider: neither the customer’s data nor the model builder’s weights should be accessible to Sharon while the model runs.

That separation is also the attraction for model providers. In VAST’s launch announcement, partners described potential uses involving sensitive code, financial or health records, voice data and restricted video archives. Those examples show the range VAST is targeting, not that every proposed workload is already running through DataEnclave. The common requirement is that the model goes to the data without either owner handing its protected asset to the machine’s operator.

The release is still ahead

DataEnclave is in preview. VAST expects it to ship in the first quarter of 2027 through the company and participating equipment partners, including Cisco and Supermicro. Sharon’s collaboration sets out a route to regional customers, but its announcement does not give a separate date for offering the service. For now, the test is whether the planned protections and key controls can be delivered in deployments where neither the data owner nor the model builder wants to trust the operator on its word alone.

Sources

  1. vastdata.comVAST Data Launches DataEnclave to Unite AI Models and Enterprise Data
  2. australiancybersecuritymagazine.com.auVAST Data launches DataEnclave confidential AI capability with Sharon AI - Australian Cyber Security Magazine
  3. prnewswire.comSharon AI Collaborates with VAST Data on the Launch of DataEnclave, Bringing Leading AI Models to Customer Controlled Infrastructure

Loading discussion...

YOUR READING SPACE

Notifications