CoreWeave shipped a service that keeps decryption keys out of its own hands, and that is the part regulated AI projects were waiting on. Remote Key Encryption runs client-side, with keys in the customer’s own key store.
- Encryption happens inside the customer’s compute boundary, using keys generated and stored in the customer’s own secrets manager, key management system, or hardware security module.
- No key is imported provider-side, so the provider holds ciphertext and nothing else. Node access stays behind support controls the customer has to release.
- Limited availability comes later this year, IBM is the launch partner, and the first release covers AI Object Storage only.
- Key custody answers who can decrypt. It does not cover plaintext in memory while a job runs, which takes a different control.
Read the full analysis, CoreWeave Says It Cannot Read Your Data. That Is the Whole Offer.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
