Photo by Christina @ wocintechchat.com on Unsplash. Source: https://unsplash.com/photos/woman-in-black-top-using-surface-laptop-glRqyWJgUeY (Unsplash License).

CoreWeave shipped a service that keeps decryption keys out of its own hands, and that is the part regulated AI projects were waiting on. Remote Key Encryption runs client-side, with keys in the customer’s own key store.

  • Encryption happens inside the customer’s compute boundary, using keys generated and stored in the customer’s own secrets manager, key management system, or hardware security module.
  • No key is imported provider-side, so the provider holds ciphertext and nothing else. Node access stays behind support controls the customer has to release.
  • Limited availability comes later this year, IBM is the launch partner, and the first release covers AI Object Storage only.
  • Key custody answers who can decrypt. It does not cover plaintext in memory while a job runs, which takes a different control.

Read the full analysis, CoreWeave Says It Cannot Read Your Data. That Is the Whole Offer.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.