VAST Data Enclave Secures AI Models in Private Data Centers

VAST DataEnclave allows enterprises to run confidential AI models on sensitive data without exposing proprietary weights or customer records to external clouds.
Key points
- VAST DataEnclave uses NVIDIA Confidential Computing to isolate AI models and data in secure hardware enclaves.
- The system allows regulated industries to run proprietary AI models on sensitive data without moving data to external clouds.
- VAST Data treats AI models as managed system resources, governing their access and usage alongside traditional data assets.
VAST Data has announced DataEnclave, a new security feature integrated into its DataEngine platform. Built on NVIDIA Confidential Computing technology, the system allows organizations to run advanced AI models directly inside their own data centers or trusted cloud environments. This approach addresses a critical barrier for regulated industries where sensitive data cannot be moved to external services.
The solution creates a hardware-isolated secure runtime that protects both data and model weights during processing. By using cryptographic attestation to verify the environment before any assets are decrypted, the system ensures that neither infrastructure operators nor administrators can access the information while it is being analyzed. This keeps the most valuable intellectual property of both the model builder and the data owner secure.
Solving the Data Mobility Paradox
Financial institutions, healthcare providers, and government agencies often hold data that is legally restricted from leaving their infrastructure. Conversely, model developers are hesitant to distribute proprietary models into environments they do not control. This creates a standoff where sensitive data remains locked away and advanced AI capabilities remain inaccessible. HPCwire reports that VAST DataEnclave aims to break this impasse by allowing the model and the data to meet in a secure, isolated container.
In this setup, customer data keys stay under the enterprise’s control, while model keys remain within the developer’s trust domain. The technology extends protection beyond storage and network transmission to cover the actual execution phase. This ensures that even if the hardware is physically accessed, the data and model weights remain encrypted and unreadable.
Models Become Managed System Resources
VAST Data positions this launch as a step toward an AI Operating System vision. Instead of treating models as simple applications sitting on top of infrastructure, the company views them as logical resources that need to be managed alongside data. This involves governing which model runs, what data it can access, and under what policies it operates.
As organizations begin to fine-tune their own models for specific tasks, these weights become a new class of enterprise intellectual property. Renen Hallak, CEO of VAST Data, emphasized that managing this ecosystem requires the same level of security and operational boundaries applied to other critical assets. The goal is to make secure model management a standard function of the operating system.
Trade-Offs in Confidential Execution
While this technology expands access to sensitive data, it introduces specific dependencies and performance considerations. The solution relies heavily on third-generation NVIDIA Confidential Computing hardware, meaning it is not compatible with all existing server infrastructure. Organizations must ensure their hardware supports the necessary isolation features to benefit from the full security model.
Additionally, the complexity of managing cryptographic attestation and secure enclaves may require specialized expertise in deployment and maintenance. However, for industries where data leakage is a critical risk, the ability to run top-tier AI models locally without compromising privacy offers a significant advantage. The trade-off is a tighter lock-in to specific hardware ecosystems and a more complex operational environment.






