VAST Data put a confidential runtime inside its own platform, and it settles a standoff that has kept regulated AI in pilot. DataEnclave decrypts models and data only after the hardware proves what it is running.
- Built on NVIDIA Confidential Computing. Guest memory, GPU memory, and inter-GPU traffic stay encrypted during execution.
- Attestation runs before key release, so an environment that does not match the approved policy gets nothing.
- Data keys stay with the customer, model weights stay with the builder, and the infrastructure operator holds neither.
- Preview now, shipping in the first quarter of 2027, with attestation services built on the open CNCF Trustee stack.
The point is the two-sided problem. The buyer cannot move the data out, and the model builder will not hand over weights to infrastructure it does not control. Attestation is what lets both of them say yes to the same machine.
Read the full analysis, The Only Way to Prove You Cannot See the Data Is to Attest the Hardware.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
