VAST Data’s DataEnclave software creates a secure enclosure that lets enterprises grant AI models access to sensitive data while enabling model developers to run models without exposing proprietary weights.
The solution addresses two core pain points. Enterprises avoid feeding confidential data into public and new-cloud LLMs due to data leakage risks. Meanwhile, foundation model owners hesitate to deploy weights inside insecure enterprise data centers and colocation facilities.
DataEnclave can be deployed in customer premises or dedicated cloud hardware, running frontier AI models where they previously could not operate. This lets enterprises use top models for sensitive workloads and allows model builders to reach new customer environments.
![]()
VAST co-founder and CEO Renen Hallak said: "Models are becoming a resource the operating system has to manage, the same way it manages data. That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else.
Bringing leading AI models securely to the world's most sensitive data is where this starts. Where it leads is a world where every organisation is managing an ecosystem of fine-tuned models that represent its true intellectual property. The VAST AI Operating System is what keeps them secure, governed and useful."
Both enterprises and model developers must trust DataEnclave. It delivers hardware-isolated secure runtime and cryptographic attestation. The system validates the environment and policies before sensitive assets are decrypted and loaded into the secure container for analysis.
VAST co-founder Jeff Denworth said: “Model weights are fast becoming the most valuable intellectual property in the world. Base weights define the value of frontier models, while fine-tuned weights will increasingly represent proprietary enterprise AI intelligence. As stakes rise, securing enterprise data becomes critical so customers can run powerful AI against it. Today, VAST Data, partnering with Nvidia, advances the industry with a framework to validate untrusted compute environments and run any model against any data, anywhere.”
Traditional GPUs lack native protection for in-use data, unlike x86 confidential computing which has protected CPU memory for years. Encryption secures weights at rest and in transit, but weights must be decrypted inside GPU memory during inference. This memory is often multi-tenant and exposed to admins or threat actors exploiting compromised hypervisors and firmware.
DataEnclave’s secure runtime and attestation ensure proprietary models run within confidential VMs built on CPU trusted execution environments, paired with Nvidia GPUs in confidential computing mode. Nvidia VP of Enterprise AI Justin Boitano said: “Enterprise data is essential to accurate, usable AI — and keeping business data confidential protects IP in the agent era. VAST’s integration of Nvidia Confidential Computing protects both enterprises and model builders, delivering security, identity, permissions, governance and compliance as the foundation for agent architectures.”
![]()
DataEnclave supports both on-premises and cloud VAST deployments. Key features:
The security layer introduces compute overhead, typically single-digit to low double-digit percentage, depending on model size.
Adoption depends on dual trust: enterprises trust it with their data and model developers trust it to host proprietary weights.
VAST is aligning model builders, AI cloud providers and server vendors around a local AI architecture. Current committed model partners include Cohere, CrowdStrike, Deepgram, Factory, Fundamental, Nvidia and TwelveLabs, not the largest industry players.
John Mao, VAST VP of Business Development and Alliances, commented: “We’re talking to many model companies, big and small. All providers understand they lose roughly half the market if they cannot bring AI to wherever enterprise data resides. Many organisations of all sizes are actively working on this challenge, and we have spoken with most of them.”
Server partners are Cisco and Supermicro. Current AI cloud partners include Buzz, Nscale and Sharon.AI, with more expected soon.
Asked about industry standards for model-safe data enclaves, Mao said: “Some standards already exist. Our runtime aligns with Kata Containers backed by Microsoft, Red Hat and industry partners. We also follow the CNCF Confidential Containers incubating project for attestation. Nvidia’s confidential computing GPUs form the third pillar. We take a multi-pronged approach and will align further as the market matures.”
DataEnclave is in preview and will ship in Q1 2027 via VAST Data and OEM partners including Cisco and Supermicro.
Bootnote 1 Dell, HPE, Lenovo, Supermicro, ASUS, Foxconn, GIGABYTE, Pegatron, QCT, Wistron, Wiwynn, Aivres, ASRock Rack, Compal, Inventec, MiTAC, MSI, AIC and IBM build Vera Rubin NVL72 systems with rack-scale confidential computing: GPU, Vera CPU, NVLink encryption and attestation.
Bootnote 2 AI agents consume models. Mao said: “Agents sit as a layer on top of models. Our Agent Engine is a full agent orchestration framework. DataEnclave enables new models to run within the data engine for Agent Engine to access and use. Managed agents can invoke these state-of-the-art models hosted on the VAST operating system.”
Beijing Qianxing Jietong Technology Co., Ltd.
Sandy Yang/Global Strategy Director
WhatsApp / WeChat: +86 13426366826
Email: yangyd@qianxingdata.com
Website: www.qianxingdata.com/www.storagesserver.com
Business Focus:
ICT Product Distribution/System Integration & Services/Infrastructure Solutions
With 20+ years of IT distribution experience, we partner with leading global brands to deliver reliable products and professional services.
“Using Technology to Build an Intelligent World”Your Trusted ICT Product Service Provider!
Persona di contatto: Ms. Sandy Yang
Telefono: 13426366826