VAST Data has introduced DataEnclave, a confidential AI capability designed to allow organisations to run proprietary and open AI models against sensitive data without moving that information outside controlled infrastructure. Built on NVIDIA Confidential Computing as part of the VAST DataEngine, the system protects enterprise data and model software while they are actively being processed. It is capable of running in customer data centres, trusted cloud infrastructure, and fully isolated environments, including systems where proprietary AI models may previously have been difficult to deploy.

The technology directly targets sectors such as financial services, healthcare, and government, where regulatory or security requirements can restrict the movement of sensitive information to externally hosted AI services. In addition, it gives model developers a secure way to make proprietary models available inside customer-controlled infrastructure without exposing their underlying model weights.

DataEnclave verifies the environment before releasing protected assets

To protect sensitive assets, DataEnclave combines hardware-based isolation with cryptographic verification throughout the computation lifecycle. Before any protected data or model weights are decrypted, the system verifies that the workload is running inside an approved environment and confirms that required security policies are enforced. This hardware protection is provided by NVIDIA Confidential Computing, which safeguards processor memory, GPU memory, and NVLink traffic while workloads are running. Decryption keys are released only after DataEnclave completes verification of the trusted environment, including NVIDIA GPU attestation. VAST confirms that infrastructure operators and platform administrators cannot access either the data or the model software while processing takes place.

Cryptographic control remains divided between the participating parties, with customer data encryption keys remaining under customer control while model keys and weights stay within the provider’s trust domain. Both sides can integrate their own key management systems to enforce independent policies, a capability that similarly safeguards models fine-tuned internally with proprietary enterprise weights.

The platform accommodates both network-connected and fully air-gapped deployments to suit varied operational perimeters. For attestation, VAST relies on services built on the open CNCF Trustee stack, working alongside Fortanix to support confidential AI infrastructure for fully sovereign environments. All attestation events, key releases, and secure-environment lifecycle actions are logged directly into VAST DataBase. This builds a queryable audit record that documents what ran, where it ran, and which verified policies were applied, without exposing any underlying data or model weights.

This secure runtime is also being extended to autonomous agents through VAST AgentEngine. In these isolated operational environments, AI agents operate under granular policies that dictate which data, systems, and tools they can access, while their subsequent actions remain fully recorded for auditing.

AI and infrastructure partners are supporting DataEnclave

VAST is collaborating with a wide spectrum of model developers, AI cloud providers, security firms, and infrastructure vendors to build out the DataEnclave ecosystem. Named partners supporting the initiative include Cohere, CrowdStrike, Deepgram, Factory, Fundamental, NVIDIA, and TwelveLabs. The underlying architecture is also designed for sovereign AI implementations, catering to organisations and governments that require data and computing workloads to remain strictly within a specific national jurisdiction. Within this framework, Sharon AI plans to use DataEnclave to host models locally for customers across Australia and Asia-Pacific while protecting both customer data and model weights.

“As a trusted AI infrastructure provider, Sharon AI exists to make secure, scalable and sovereign AI compute available to every organisation that needs it,” said James Manning, CEO and Co-founder, Sharon AI. “Our customers across Australia and Asia-Pacific need to run AI at full speed without compromising on data sovereignty, and increasingly they also want access to frontier models that were previously only available offshore. Building on our sovereign data foundation with VAST, DataEnclave lets us host those models onshore, inside attested environments where the model owner’s weights and the customer’s data are both protected from everyone, including us. That gives our customers the flexibility to operate on their own terms, backed by sovereignty they can demonstrate, not just declare.”

On the hardware side, Cisco and Supermicro are participating as partners, with VAST noting that manufacturers can deploy DataEnclave within integrated systems that combine confidential computing, accelerated computing, and its underlying data infrastructure. NVIDIA Vice President Enterprise AI Justin Boitano described the integration as providing essential protection for enterprises and model developers, alongside comprehensive security, identity, permissions, governance, and compliance controls for AI agent architectures.

Commercial availability is planned for Q1 2027

VAST DataEnclave is being previewed from 23 September and is scheduled to ship in Q1 2027 through VAST Data and participating hardware partners, including Cisco and Supermicro. The capability also forms part of VAST’s broader AI Operating System model for managing AI models alongside enterprise data. Under this model, the company envisages organisations applying policies that determine where individual models run, what data they can access, who or what can use them, and the specific conditions under which they operate.

Share