Encryption is vital for keeping data secure. Yet in the world of AI, it’s not always a given. There’s still a gap, particularly when it comes to the accelerators on which AI models run. VAST Data aims to close that gap with DataEnclave.
When running AI workloads in which proprietary AI models use sensitive enterprise data, two issues often arise. First, enterprises are often unable or unwilling to allow such models access to their data. The creators of the AI models, in turn, do not want their so-called model weights to be disclosed in environments where they do not have control. However, that is precisely what is needed for the models to do their job.
A solution to these challenges lies in confidential computing. In the CPU world, this has been possible for about ten years now, through Trusted Execution Environments. For GPUs, however, the equivalent does not yet exist, according to John Mao, VP of Global Business Development at VAST Data. That’s where VAST Data’s new DataEnclave comes into play.
VAST DataEnclave is a confidential runtime
With DataEnclave, VAST is doing something it’s been talking about for a while. In a previous article, we already mentioned that the company wants to move closer to the GPU layer. It’s certainly doing that with DataEnclave. This is, in fact, a confidential runtime for Nvidia GPUs. In other words, the proprietary AI models do their work within the confidential VMs set up inside Trusted Execution Environments. The idea is that this way, model developers have nothing to worry about, and organizations’ data is also well protected.
In practice, VAST DataEnclave is designed to protect workloads within the confidential VMs, containers, and runtimes it provides. This means that memory and NVLink traffic (between GPUs) are encrypted. It does this while isolating data and models. Even on shared resources, which is very often the case, this ensures that everything remains within the same confidential environment.
Another key component of VAST DataEnclave is that, according to the company, tamper-proof observability has been added. This can also be verified using logs stored in the VAST DataBase. It is also possible to audit this. In this way, the confidential nature of DataEnclave should also be verifiable.
An interesting aspect of DataEnclave is that the CPU plays a key role. The Trusted Execution Environments (TEEs) of CPUs from Intel, AMD, and Nvidia form the foundation for the confidential environments that DataEnclave provides.
The OS for AI, part of the ecosystem
With DataEnclave, VAST Data is taking the next step in its mission to become the operating system for AI. To achieve this, it is important that it can play a role throughout the entire lifecycle of AI workloads. This is important in and of itself, because without control over the entire chain, it is difficult to ensure that models and data work together optimally. Bringing AI to the data, something many players in the AI market are touting these days, is only possible if it can be done in a responsible and secure manner. Control over the entire chain is equally important for this.
VAST Data, of course, focuses solely on developing what it calls the “OS” for AI. It does not sell hardware and does not build models itself. Naturally, the broader ecosystem is important for enabling local AI on local data, as envisioned with DataEnclave. It is therefore important to note, in conclusion, that this ecosystem is in place.
Naturally, the hardware suppliers with which VAST has been collaborating for years, such as Cisco and Supermicro, are part of the ecosystem. What we find more interesting, however, is that models from a wide variety of fields are also available. Models from companies including Nvidia, CrowdStrike, TwelveLabs, Cohere, and Deepgram can be deployed within DataEnclave.
As things stand now, VAST DataEnclave is expected to become available in Q1 of 2027.