# VAST's DataEnclave protects private enterprise data and AI model builders' weights

> Source: <https://www.blocksandfiles.com/ai-ml/2026/09/22/vasts-dataenclave-protects-private-enterprise-data-and-ai-model-builders-weights/5298161>
> Published: 2026-09-22 13:50:00+00:00

AI/ML

# VAST's DataEnclave protects private enterprise data and AI model builders' weights

VAST Data has DataEnclave software providing a safe and secure enclosure in which enterprises can give AI models access to their data, and model developers can run their models without exposing proprietary weights to leakage.

The company is trying to kill two birds with one stone. Organizations don’t want to supply their sensitive data to large language models (LLMS) running in public and neoclouds because their data could be exposed to copying. Similarly, foundation model developers don’t want to have their model weights, classic proprietary and sensitive data exposed to leakage by letting them run in insecure enterprise data centers and colos. VAST’s DataEnclave enables deployment inside customer data centers or dedicated cloud hardware, including environments where frontier AI models could not previously operate. That means enterprises can use the best models to process their most sensitive data, and give model builders reach into environments they could never serve before.

VAST co-founder and CEO Renen Hallek said: "Models are becoming a resource the operating system has to manage, the same way it manages data. That means knowing which model fits which task, what it can see, who can use it and under what rules, and doing all of that inside the same security and operational boundaries an enterprise applies to everything else. Bringing leading AI models securely to the world's most sensitive data is where this starts. Where it leads is a world where every organisation is managing an ecosystem of fine-tuned models that represent its true intellectual property. The VAST AI Operating System is what keeps them secure, governed and useful."

Both parties addressed by VAST’s DataEnclave, enterprise customers and model builders, have to trust it. The DataEnclave provides a hardware-isolated secure runtime and cryptographic attestation directly within its [DataEngine](https://www.blocksandfiles.com/ai-ml/2024/08/13/vasts-data-engine-previewed/1600972 ) software. This verifies the environment and its enforced policy before sensitive assets are decrypted and loaded into the secure enclave container for analysis. 

VAST Data co-founder Jeff Denworth said: “Model weights are fast becoming the most valuable intellectual property in the world. Base weights define the value of frontier models, while fine-tuned weights will increasingly represent the proprietary intelligence of AI-driven enterprises. As the stakes get higher, so does the need to secure enterprise data so customers can apply the most intelligent AI models against it. Today, VAST Data - in partnership with Nvidia - is moving the industry forward with a comprehensive approach to verifying previously untrusted computing environments and unlocking the ability to run any model against any data, anywhere.”

GPUs previously would not typically protect data they are processing, VAST says, unlike confidential (x86) computing which has protected data in CPU memory for a decade. Conventional encryption protects model weights while they are stored and while they move across the network, but, VAST says, “to run, a model's weights must be decrypted in GPU memory, which is often shared across tenants and exposed to cloud administrators, or worse, to rogue actors via compromised hypervisors and firmware exploits.”

Now, and crucially, DataEnclave’s secure container runtime and attestation service ensures proprietary models execute inside confidential virtual machines established through CPU-level trusted execution environments, with Nvidia GPUs operating in [Confidential Compute](https://www.nvidia.com/en-gb/glossary/confidential-computing/) mode. Justin Boitano, Nvidia’s VP of Enterprise AI, said: “Enterprise data is essential to accurate, usable AI – and keeping business data confidential is critical to protecting IP in the age of agents. VAST Data’s integration of Nvidia Confidential Computing delivers protection for both enterprises and model builders, providing security, identity, permissions, governance and compliance as a foundation of the agent architecture.”

The DataEnclave is supported by on-prem VAST deployments and cloud VAST deployments. Its main features are:

- **Hardware-Isolated Execution:** Protects workloads inside confidential virtual machines and containers, encrypting guest memory, GPU memory and NVLink traffic while isolating active data and models from infrastructure operators, administrators and other tenants sharing the same hardware.
- **Verify-Before-Decrypt Attestation:** Establishes a cryptographically verified trust boundary so sensitive assets are released only to approved environments.
- **Independent Key Control:** Enables enterprises and model builders to maintain their respective keys within their own trust domains through Bring Your Own KMS integrations, so each party enforces policy on its own assets. This protects an enterprise’s own fine-tuned weights, which are fast becoming critical IP, as much as a model builder’s base weights
- **Connected or Air-Gapped Deployment:** Supports connected deployments through the DataEnclave attestation service, built on the open CNCF Trustee stack, with VAST and Fortanix enabling on-premises attestation and key brokering for fully air-gapped environments.
- **Governed and Auditable by Design:** Records attestation events, key releases and enclave lifecycle actions in a tamper-proof, queryable audit trail in the VAST DataBase, providing visibility into what ran, where and under what verified policy without exposing protected data or model weights.
- **Secure Agent Sandboxes:** The same DataEngine  secure runtime provides isolated execution environments for AI agents through VAST[AgentEngine](https://www.blocksandfiles.com/ai-ml/2025/05/21/vast-data-launches-ai-operating-system/1613219) , enforcing policy over the data, systems and tools agents can access and the actions they can take. Unlike people, agents are not accountable for their actions, so they need identity, a contained runtime and observability into when, how and why something went wrong.

There is a compute cost to this, varying with model size, and expected to be in the single-digits-to-low-double-digits percent area.

This DataEnclave is only going to work if both enterprises and other organization model users trust it with their data and model builders trust it enough to expose their model weight data inside it.

VAST says it’s bringing together model builders, AI clouds, and infrastructure (server) providers around a shared architecture for locally hosted AI. Committed model builders include Cohere, CrowdStrike, Deepgram, Factory, Fundamental, Nvidia and TwelveLabs; clearly not the big ones.

Asked about this, John Mao, VAST VP of Business Development and Alliances, said: “We're talking to every single model company you can imagine under the sun. Well, not as an exaggeration. We're talking to a lot, and I think everybody understands big and small. All of these model providers understand that if they don't figure out a path to bring their AI to the data, wherever the enterprise data is, they're missing out on about half of the market. And so I can tell you that without naming names, that many, many, many organisations, big and small, are actively trying to figure this out. We've spoken to the majority of them today.”

Server partners include Cisco, Lenovo and Supermicro. AI cloud partners are slim on the ground at the moment: Buzz, Nscale and Sharon.AI. We expect more to arrive shortly.

We asked Mao if here needs to be an industry standard for such model safeguarding data enclaves? He replied: “There are some standards already. … what we're leaning on is from a standards-based perspective on the run time is we're following and aligning with [Kata](https://katacontainers.io/). This was backed by Microsoft, backed by Red Hat, backed by a whole bunch of people in the industry. Kata's an open source container native runtime interface for confidential computing. … We are also aligning around the CNCF's open source project [Trustee](<https://www.cncf.io/blog/2026/07/22/confidential-containers-becomes-a-cncf-incubating-project/ >). That's going to be one of the modes that we support for attestation.” Nvidia GPUs supporting confidential computing is a third standards leg

Mao finished up this point by saying: “We're taking a multi-pronged approach … for supporting those. And then of course, as the market matures, there's more convergence there, then we'll align as necessary.”

VAST DataEnclave is being previewed today and will ship in Q1 2027 through VAST Data and participating OEM partners, including Cisco and Supermicro. Read a [blog](https://www.vastdata.com/blog/introducing-vast-dataenclave-confidential-ai-for-sensitive-data-and-proprietary-models) and [white paper](https://www.vastdata.com/resources/white-papers/dateenclave-architecture-trust-model) for more information.

##### **Bootnote 1**

Dell, HPE, Lenovo, Supermicro, plus ASUS, Foxconn, GIGABYTE, Pegatron, QCT, Wistron, Wiwynn, Aivres, ASRock Rack, Compal, Inventec, MiTAC, MSI, AIC, and IBM all build specific, SKU-level, Vera Rubin NVL72 systems with rack-scale Confidential Computing (GPU + Vera CPU + NVLink encryption + attestation)

##### **Bootnote 2**

Where do AI agents fit in this? Agents use models. Mao said: “Agents consume models, so you could think about managing agents as a layer on top. We announced …Agent Engine, which is basically an entire framework for orchestrating agents. What this allows with Data Enclave is; you can think about now models, additional types of models being able to be run within the data engine in which Agent Engine can actually now tap into and be able to leverage. So think of it as if I had a bunch of models that agents could actually run and orchestrate against. There'll be newer and potentially more state-of-the-art models now available on the VAST operating system that those agents that we're managing can now invoke as well.”
