Photo by Evgeniy Surzhan on Unsplash. Source: https://unsplash.com/photos/colleagues-collaborate-while-examining-computer-designs-VFMhqkiL6E4 (Unsplash License).

Executive Summary

VAST Data announced DataEnclave on 22 September 2026, a confidential AI runtime inside the VAST DataEngine built on NVIDIA Confidential Computing. Models and data are decrypted only inside hardware-isolated enclaves, after cryptographic attestation verifies the environment, the GPU included, and matches it against policy. Data keys stay in the customer’s trust domain, model weights stay in the builder’s, and the infrastructure operator holds neither. The capability is in preview and ships in the first quarter of 2027 through VAST and OEM partners including Cisco and Supermicro.

Attestation is what changes the conversation. Regulated buyers cannot move the data out, and model builders will not put weights on infrastructure they do not control, so the two sides stall each other. Proving the environment before releasing a key is the only shipping architecture that satisfies both at once. What stays open is the trust root behind the attestation and what sealed execution costs in throughput. Both belong in a pilot, not in a datasheet.

The standoff is easy to describe. A bank cannot move customer records to an external AI service. The company that built the model will not hand over weights to run on hardware it does not control. The tie breaks with confidential computing, which removes the operator from the trust boundary using hardware instead of a contract clause. VAST Data put that runtime inside its own data platform, and named the partners it needs to make it real.

Five-step diagram of a confidential AI runtime showing attestation of the environment, a policy check, key release, sealed execution with encrypted memory and interconnects, and an audit record of each event.
Nothing is decrypted until the environment proves what it is running.

Attestation turns a promise into a check

Conventional encryption protects data at rest and in transit, and stops there. Confidential computing extends encryption to the moment of execution. DataEnclave uses NVIDIA Confidential Computing to create a secure container runtime inside the VAST DataEngine. Guest memory, GPU memory, and the links between GPUs stay encrypted while a model runs, and the workload is isolated from infrastructure operators, administrators, and other tenants sharing the same hardware.

The order of operations is the security property. The runtime verifies the trusted execution environment before it releases anything, and a measurement that does not match the approved policy gets no key. Attestation events, key releases, and enclave lifecycle actions are written to an audit trail in the VAST data warehouse, so a reviewer can see which workload ran under which policy without seeing the data or the weights.

Two key owners is the part procurement will care about

Most confidential designs protect one side. This one separates two. Jeff Denworth, co-founder at VAST Data, put the commercial case plainly, saying that model weights are fast becoming the most valuable intellectual property in the world. He is arguing from the builder’s side, and the architecture follows his logic. Enterprise data keys stay under customer control, model keys and weights stay inside the builder’s trust domain, and key management is bring-your-own over an interoperable protocol. Neither side has to trust the other’s operations, which is what makes a shared environment acceptable to both.

The deployment options follow from that. DataEnclave runs in customer data centers, in sovereign AI clouds, and in fully air-gapped sites, with attestation services built on the open CNCF Trustee stack or through a partner confidential AI offering such as Fortanix. NVIDIA’s confidential computing is in its third generation across Hopper, Blackwell, and Rubin platforms, so the hardware floor is real. A fleet that predates those parts is looking at a refresh, not a software upgrade.

Ask what the enclave costs before you believe the demo

Three things belong in a pilot. The first is the trust root. Attestation is only as good as the thing that signs the measurement and the process that decides what counts as an approved policy, and that is an operational problem more than a cryptographic one. The second is throughput. Confidential virtual machines and encrypted interconnects are not free, and the only number worth having is the one your own workload produces. The third is metadata. The audit trail records which workloads ran and under what policy, which is exactly what a regulator asks for and also a new dataset to govern.

Preview status is the practical constraint. DataEnclave ships in the first quarter of 2027 through VAST and OEM partners, with Cisco and Supermicro named at launch. Model makers including Cohere, CrowdStrike, Deepgram, and TwelveLabs are building against it now. That gives a regulated buyer a runway to design the pilot, and a reason to ask their own storage and GPU vendors what the equivalent answer is.

Three questions for the next briefing on this. Which parts of the stack does the attestation actually cover today? Who controls the policy that decides when a key is released? And what does sealed execution cost per inference hour once the enclave overhead lands in the bill?

Related reading. Workload sovereignty is the question procurement cannot answer sets out what a buyer can actually test. The argument that storage is the gap in every infrastructure newsroom explains why the data layer keeps deciding AI outcomes.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

One thought on “The Only Way to Prove You Cannot See the Data Is to Attest the Hardware”

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.