VAST Data's DataEnclave targets AI's $sensitive-data impasse

VAST Data's confidential AI runtime brings frontier models to regulated industries' locked-down data, partnering NVIDIA, Cohere and CrowdStrike.

A brightly lit modern control room features a large, curved display wall showing blue and purple digital graphics and three interactive touchscreen consoles.

VAST Data, the AI operating system company, has unveiled DataEnclave, a confidential computing architecture designed to solve one of enterprise AI's most stubborn structural problems: roughly half of the world's data sits in environments, regulated financial institutions, government agencies, defence contractors, healthcare systems, where it cannot legally or operationally move to where leading AI models run. DataEnclave inverts that constraint, bringing the models to the data rather than the reverse, while preserving the intellectual property rights of both the data owner and the model builder.

The product, built on NVIDIA Confidential Computing and announced on 22 September 2026, is currently in preview and will ship commercially in Q1 2027 via VAST and OEM partners including Cisco and Supermicro. Partners at launch include AI model builders Cohere, CrowdStrike, TwelveLabs, and Fundamental, alongside cloud infrastructure provider Nscale.

How the architecture works

DataEnclave creates a hardware-isolated secure runtime inside VAST's DataEngine. Before any sensitive asset, a proprietary model's weights or an enterprise's records, is decrypted, the system runs cryptographic attestation to verify the execution environment meets enforced policy. Data and model weights are then loaded into CPU and GPU trusted execution environments (TEEs), where they remain encrypted in memory during processing. Infrastructure operators and administrators cannot access either. Enterprises retain their own encryption keys; model builders retain theirs. The system supports both connected deployments and fully air-gapped environments, the latter relevant to intelligence agencies and defence operators who run networks deliberately isolated from the public internet.

"Models are becoming a resource the operating system has to manage, the same way it manages data," said Renen Hallak, Founder and CEO of VAST Data. "Bringing leading AI models securely to the world's most sensitive data is where this starts. Where it leads is a world where every organisation is managing an ecosystem of fine-tuned models that represent its true intellectual property."

The architecture also extends to AI agents, providing sandboxed execution environments that enforce policy over what data an agent can access and what actions it can take, a governance layer that is increasingly significant as agentic workflows proliferate across enterprise IT.

Cross-sector and capital implications

The sectors DataEnclave is explicitly targeting, financial services, healthcare, life sciences, defence and government, represent some of the largest concentrations of sensitive, high-value data in the global economy, and collectively some of the most cautious adopters of cloud-hosted AI. The product is, in effect, a strategic wedge: if confidential computing can establish verifiable trust at the hardware level rather than requiring regulated entities to accept a vendor's contractual assurances, it removes the principal barrier to AI adoption in markets that have so far watched the generative AI wave from the sidelines.

For the defence and intelligence community specifically, the air-gapped deployment mode and Fortanix partnership for fully sovereign AI infrastructure speak directly to a procurement reality: national-security buyers will not place frontier model weights on infrastructure they do not control, and many will not place them on infrastructure outside their own jurisdiction. DataEnclave's attestation-based model, where trust is mathematical rather than contractual, is architecturally aligned with how NATO-allied governments are framing their own digital sovereignty requirements.

The capital read-across is equally significant. Sovereign AI infrastructure has attracted substantial sovereign wealth and government-backed investment across the Gulf, Southeast Asia and Europe over the past 18 months. A technology that allows a national AI cloud to host frontier third-party models on domestic hardware, in a verified environment, without the model builder ceding control of its weights, materially expands the commercial surface area for those infrastructure plays. For investors allocating across the data infrastructure and defence-tech convergence, DataEnclave represents an early commercial articulation of what "sovereign AI" looks like in practice rather than in policy documents.

VAST's broader AI OS vision, treating models as managed logical resources alongside data, governed by policy across heterogeneous environments, positions the company in a competitive layer above pure storage or compute infrastructure. Whether that vision sustains differentiation as hyperscalers develop comparable confidential computing offerings of their own remains the central strategic question as DataEnclave moves from preview to general availability.