VAST Previews DataEnclave for Confidential AI on Customer Infrastructure
The runtime uses hardware isolation, attestation and owner-controlled keys to bring protected models to sensitive data, but production shipment is not due until Q1 2027.
Edited by Tyronne Panaino
VAST Data previewed DataEnclave on September 22, 2026, as a confidential-AI runtime inside VAST DataEngine for organizations that need to run proprietary models near sensitive data. The company says the design keeps model weights and enterprise data inside hardware-protected memory, while the owners of those assets decide whether a verified environment receives the keys needed to use them.
The immediate audience is enterprises, model providers and infrastructure operators that cannot resolve their security requirements by moving protected data to a hosted model or handing closed model weights to a customer. VAST is presenting the runtime now, but its official release notice says DataEnclave remains in preview and is scheduled to ship in Q1 2027. That timing makes this a confirmed product preview, not evidence of a completed production rollout.
What the preview changes
DataEnclave packages AI workloads inside confidential virtual machines that span CPU and GPU resources. According to VAST's technical introduction, a workload starts without keys or credentials. Hardware produces signed evidence describing the environment, including the hardware, firmware, booted software and restrictions applied to the host. An attestation service controlled by the data or model owner checks that evidence against policy before releasing keys into protected memory.
This shifts the trust decision away from a general promise by the infrastructure operator. A model provider can retain control of the keys for an encrypted model package, while an enterprise retains control of the information sent to the model. VAST says the operator and its administrators cannot access the decrypted model or data while the workload runs. The company also describes a continuing control path: attestation occurs when workloads launch, and an owner can stop future instances from receiving keys by changing entitlement at its attestation service.
Why the separation matters
Ordinary encryption covers stored data and network traffic, but AI inference also needs prompts, intermediate data and model weights in memory while computation is happening. DataEnclave is designed around that in-use period. VAST says its confidential virtual machines extend isolation across CPU and GPU memory and use NVIDIA Confidential Computing as part of the hardware boundary.
The operating model also separates records. The infrastructure side logs workload lifecycle details without recording the protected contents, while the owner-side attestation service records which environments it verified and which keys it released. In principle, that gives security teams an audit trail without placing the model and the underlying enterprise data in the same administrative trust domain.
What remains uncertain
The available evidence comes from VAST itself. It explains the intended architecture and acknowledges an important limit: confidential execution can protect confidentiality and integrity, but it cannot guarantee that an infrastructure operator will keep a workload available. Developers also remain responsible for what enters and leaves through application interfaces.
The sources do not provide an independent security audit, certification, performance comparison or production customer result. The next meaningful checkpoints are the promised Q1 2027 shipment, documentation of supported hardware and operating conditions, and third-party testing of the attestation, key-management and isolation claims.
Status
Confirmed product preview, with medium confidence. VAST is the primary source for the design and availability schedule; operational and security outcomes have not been independently verified.
Sources
Update note: Last reviewed 2026-09-24. We will revise this post when VAST publishes shipment details or independent security evidence becomes available.
Sources
- VAST Data — Introducing DataEnclave — official
- VAST Data — DataEnclave press release — official
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.