Singapore – VAST Data has launched VAST DataEnclave, a confidential AI runtime that allows leading AI models to run directly against sensitive enterprise data without exposing either the data or the models’ underlying intellectual property, the company announced on 23 September 2026.
Built on NVIDIA Confidential Computing, the new capability sits within the VAST AI Operating System and has been developed with support from ecosystem partners including Cohere, CrowdStrike, Deepgram, Factory, Fundamental, TwelveLabs and NVIDIA itself.
According to VAST Data, DataEnclave can be deployed inside customer data centres or on trusted cloud hardware, extending access to leading AI models into environments where they previously could not operate.
The launch addresses a persistent bottleneck across financial services, healthcare, government and other regulated sectors, where much of the world’s most valuable data sits in tightly controlled environments that make moving it to an external AI service impractical or prohibited.
That dynamic has historically cut both ways, the company says: sensitive data cannot travel to where the most capable models run, while model builders have been reluctant to distribute proprietary weights into infrastructure they do not trust.
VAST Data says DataEnclave resolves this standoff through a hardware-isolated secure runtime paired with cryptographic attestation, which verifies both the environment and its enforced policy before any sensitive assets are decrypted.
Once verified, proprietary models and protected data are loaded into a secure enclave container, where they remain protected in CPU and GPU memory throughout processing, according to the company.
Customer data keys stay under customer control, model keys and weights remain within the model builder’s own trust domain, and infrastructure operators and administrators cannot access either asset while it is being processed, VAST Data says.
“Models are becoming a resource the operating system has to manage, the same way it manages data,” said Renen Hallak, Founder and CEO, VAST Data.
“That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else. Bringing leading AI models securely to the world’s most sensitive data is where this starts. Where it leads is a world where every organisation is managing an ecosystem of fine-tuned models that represent its true intellectual property. The VAST AI Operating System is what keeps them secure, governed and useful,” Hallak further commented.
Turning to the underlying technology, VAST Data notes that conventional encryption already protects model weights while they are stored and in transit across a network, but confidential computing extends that protection to data during execution.
NVIDIA Confidential Computing, now in its third generation across Hopper, Blackwell and Rubin platforms, ensures sensitive data and models are released only after a workload is verified and a secure enclave has been established, according to NVIDIA.
VAST DataEnclave draws on this capability to create a secure container runtime and attestation service directly within the VAST DataEngine, with proprietary models executing inside enclaves established through CPU and GPU trusted execution environments.
Among the key capabilities VAST Data has outlined are hardware-isolated execution, which protects workloads inside confidential virtual machines and containers by encrypting guest memory, GPU memory and NVLink traffic.
The system also applies verify-before-decrypt attestation, cryptographically checking the trusted execution environment — including NVIDIA GPU attestation — before releasing decryption keys to approved workloads.
Independent key control lets enterprises and model builders maintain separate keys within their own trust domains through Bring Your Own Key Management System integrations, the company says, protecting both an enterprise’s fine-tuned weights and a model builder’s base weights.
Deployment options span connected and fully air-gapped environments, with attestation services built on the open CNCF Trustee stack, or delivered in partnership with Fortanix via its Confidential AI infrastructure for fully sovereign AI.
Every attestation event, key release and enclave lifecycle action is logged in a tamper-proof, queryable audit trail within the VAST DataBase, giving organisations visibility into what ran, where, and under what verified policy, according to VAST Data.
The same secure runtime also underpins VAST AgentEngine, providing isolated sandboxes for AI agents and enforcing policy over the data, systems and tools those agents can access.
“Model weights are fast becoming the most valuable intellectual property in the world. Base weights define the value of frontier models, while fine-tuned weights will increasingly represent the proprietary intelligence of AI-driven enterprises,” said Jeff Denworth, Co-Founder, VAST Data.
“As the stakes get higher, so does the need to secure enterprise data so customers can apply the most intelligent AI models against it. Today, VAST Data – in partnership with NVIDIA – is moving the industry forward with a comprehensive approach to verifying previously untrusted computing environments and unlocking the ability to run any model against any data, anywhere,” Denworth added.
NVIDIA, meanwhile, frames the integration as a foundation for agentic AI security more broadly.
“Enterprise data is essential to accurate, usable AI – and keeping business data confidential is critical to protecting IP in the age of agents. VAST Data’s integration of NVIDIA Confidential Computing delivers protection for both enterprises and model builders, providing security, identity, permissions, governance and compliance as a foundation of the agent architecture,” said Justin Boitano, Vice President Enterprise AI, NVIDIA.
Several ecosystem partners have already moved to apply the capability to their own model portfolios and customer bases.
“Video is where an enormous amount of institutional knowledge lives, and it is also the data that is hardest to move. Archives, sensor feeds and full-motion video sit in environments that are disconnected by design,” said Jae Lee, CEO & Co-founder, TwelveLabs.
“TwelveLabs built our video intelligence models Marengo and Pegasus to run wherever that video already is, with no degradation in capability. With VAST DataEnclave, we can bring video intelligence into the most restricted environments while keeping our models protected and our customers’ footage entirely under their control,” said Lee.
“As a trusted AI infrastructure provider, Sharon AI exists to make secure, scalable and sovereign AI compute available to every organisation that needs it,” said James Manning, CEO and Co-founder, Sharon AI.
“Our customers across Australia and Asia-Pacific need to run AI at full speed without compromising on data sovereignty, and increasingly they also want access to frontier models that were previously only available offshore. Building on our sovereign data foundation with VAST, DataEnclave lets us host those models onshore, inside attested environments where the model owner’s weights and the customer’s data are both protected from everyone, including us. That gives our customers the flexibility to operate on their own terms, backed by sovereignty they can demonstrate, not just declare,” Manning continued.
“Customers around the world have unique regulatory and sovereignty requirements, and they are asking for AI that is encrypted end-to-end – not just at rest but in motion and during inference. Cohere has prioritised confidential compute for some time, and by working with VAST we can now bring that same level of security and governance to any data centre, wherever customers choose to deploy,” said Frank O’Dowd, Chief Revenue and Commercial Officer, Cohere.
“Together we are building a confidential compute strategy that gives customers more choice and more control, so they can run our models and the agents they build on North where their data already lives: their infrastructure, their jurisdiction, their rules,” added O’Dowd.
“CrowdStrike SafeMind models are trained on the world’s largest pureplay cyber dataset, and that intelligence relies on the trust built around it. Defenders in regulated industries want to put these models to work against their most sensitive data, inside their own boundaries, while maintaining control of their data and protecting the models themselves,” Dr Bartley Richardson, Chief AI and Autonomous Systems Officer, CrowdStrike said.
“VAST’s attestation-based approach brings model weights and enterprise data together in a verified environment while keeping both protected and under their respective owners’ control. That’s what it takes to put frontier security models to work where the stakes are highest,” continued Richardson.
“Bringing the most capable AI models to sensitive enterprise data requires trust across the entire infrastructure. Cisco Secure AI Factory with NVIDIA brings together secure, validated compute, networking, security and data infrastructure so customers can put AI into production with greater confidence and control,” said Jeremy Foster, Senior Vice President and General Manager, Cisco Compute.
“With VAST DataEnclave, that foundation can extend to some of the most sensitive workloads and regulated environments, giving customers more freedom to use the models they want, where their data needs to remain,” said Foster.
“Supermicro brings together the compute, storage, networking, cooling and infrastructure expertise required to make advanced AI practical at scale. Working with VAST and NVIDIA, we’re delivering pre-integrated, validated systems that combine NVIDIA Vera Rubin accelerated computing with confidential computing and the VAST AI Operating System. This enables enterprises to deploy frontier AI faster and with greater control over their data, models and infrastructure – even in sovereign and air-gapped environments,” said Matthew Thauberger, Chief Revenue Officer, Supermicro.
VAST Data says the capability also allows AI cloud providers to deliver attested, sovereign environments in which model builders, enterprises and governments retain control over their IP and data within their own jurisdictions.
Because isolation is enforced in hardware rather than through dedicated single-tenant machines, the company adds, sovereign and regional AI clouds can establish verifiable trust while still offering the newest accelerated computing systems, such as NVIDIA Vera Rubin infrastructure, from facilities operated within national borders.
VAST DataEnclave is now available as part of the VAST AI Operating System, with support from partners including Cohere, CrowdStrike, Deepgram, Factory, Fundamental, TwelveLabs, Sharon AI, Cisco, Supermicro and Fortanix.

