Research Notes

VAST DataEnclave Brings Trusted Model Execution to Regulated Enterprise Data

Research Finder

Find by Keyword

VAST DataEnclave Brings Trusted Model Execution to Regulated Enterprise Data

Confidential execution extends the VAST AI Operating System into model placement, protecting enterprise data and proprietary model weights while both are in use.

9/23/2026

Key Highlights

  • VAST DataEnclave adds confidential AI execution to DataEngine, protecting sensitive enterprise data and proprietary model weights during processing.
  • Attestation verifies the execution environment before decryption keys are released. Enterprises retain control of data keys, while model builders retain control of model keys and weights.
  • The launch is backed by more than 20 ecosystem partners. Named model builders include Cohere, CrowdStrike, Deepgram, Factory, Fundamental, and TwelveLabs, while OEM partners include Cisco and Supermicro.
  • DataEnclave is built on NVIDIA Confidential Computing and supports customer data centers, trusted cloud infrastructure, sovereign environments, and air-gapped deployments.
  • VAST is previewing DataEnclave now, with availability planned for Q1 2027 through VAST and participating OEM partners.

The News

VAST announced DataEnclave, a confidential AI capability within VAST DataEngine designed to run proprietary and open models against sensitive enterprise data inside customer-controlled or trusted cloud environments. Built on NVIDIA Confidential Computing, the runtime combines hardware-isolated execution, cryptographic attestation, independent key control, and auditable execution. The launch is backed by more than 20 ecosystem partners spanning model providers, AI cloud providers, security providers, and OEMs. DataEnclave is being previewed now and is scheduled to ship in Q1 2027. For more information, see the VAST DataEnclave product page and official press release.

Analyst Take

DataEnclave addresses key constraints that can prevent enterprises from moving AI into regulated and sensitive environments. Valuable data and capable models frequently reside inside different trust domains. Enterprises may be unable to send regulated information to an external model endpoint, while model builders have good reason to restrict where proprietary weights can execute. Confidential execution creates a place where those assets can meet without either owner surrendering control. VAST puts attestation and key ownership at the center of that interaction.

HyperFRAME Research Lens: State of the Enterprise AI Stack (1H 2026) found that only 14% of enterprises describe their core data architecture as fully modernized for AI workloads, reinforcing the need for architectures that work with existing enterprise data locations as AI moves into production. Seventy percent of respondents rated compliance, security, and data sovereignty as very important drivers of data architecture modernization.

With VAST DataEnclave, the runtime verifies the execution environment and its policy before protected assets are decrypted and loaded. Customer data keys remain under customer control, while model keys and weights remain within the model builder's trust domain. Infrastructure operators and administrators can provide compute without gaining access to either asset during processing. That separation turns confidential computing into an enabler for distributed AI, extending security policy into the point where models and data are actively used. Enterprises gain access to models that can move closer to governed data, extending AI into environments where data residency, sovereignty, security, or latency limit external processing. Model builders gain a route into customers and workloads they previously could not serve without placing valuable IP onto infrastructure outside their control.

DataEnclave also extends VAST's model management strategy. The VAST AI Operating System already manages data, processing, governance, and distributed access; models now become another logical resource governed by the platform. As enterprises assemble portfolios of proprietary, open, fine-tuned, and internally developed models, decisions about model location, data access, identity, policy, and infrastructure begin to converge. VAST ultimately sees the AI OS pairing models to tasks based on factors such as purpose, cost, security requirements, and execution policy.

What Was Announced

DataEnclave uses confidential virtual machines and NVIDIA Confidential Computing to establish protected execution across CPU and GPU trusted execution environments. Guest memory, GPU memory, and NVLink traffic are protected while workloads are active, isolating models and enterprise data from infrastructure operators, administrators, and other tenants. VAST embeds the secure runtime and attestation service in DataEngine, extending protection beyond encryption at rest and in transit into active processing.

Attestation follows a verify-before-decrypt model. The execution environment, including NVIDIA GPU state, is cryptographically verified before decryption keys are released. Enterprises and model builders maintain their respective keys inside their own trust domains through Bring Your Own KMS integrations, allowing each party to apply its own release policy. If the environment cannot establish the required trust state, the keys remain unavailable and the protected assets are not released. The architecture supports connected and fully air-gapped environments, while VAST records attestation events, key releases, and enclave lifecycle actions in a queryable audit trail in VAST DataBase, providing visibility into what ran, where execution occurred, and which verified policy governed access without exposing the protected model or data itself. The same DataEngine secure runtime extends into AgentEngine, where isolated environments can govern the data, systems, tools, and actions available to AI agents.

The launch is supported by more than 20 ecosystem partners. Model builders include Cohere, CrowdStrike, Deepgram, Factory, Fundamental, and TwelveLabs, while Cisco and Supermicro are the named OEM partners. DataEnclave is scheduled to ship in Q1 2027 through VAST and participating OEM partners, including Cisco and Supermicro. NVIDIA provides the confidential computing foundation underlying the protected GPU execution environment.

Looking Ahead

DataEnclave expands the AI options available to enterprises with data that must remain inside tightly governed environments. Financial records, clinical information, source code, security telemetry, video, production data, and government information can support more capable AI without first being relocated to an external model service. Enterprises retain control of their data and keys while gaining greater choice over models and deployment locations, broadening the portion of the enterprise data estate that can participate in production AI.

Model builders gain access to the other side of that equation. Attested execution creates a mechanism for extending proprietary models into regulated, sovereign, on-prem, and isolated environments while keeping model weights under the provider's control. That gives model companies a path to new customers and new data while preserving the intellectual property that differentiates their offerings.

VAST appears well positioned to move ahead of much of the industry as confidential execution, model governance, and enterprise data control converge. DataEnclave extends the AI Operating System from managing enterprise data and computation into governing where protected models can execute against that data. As model portfolios expand, including enterprise-owned and fine-tuned models that encode proprietary knowledge, model placement, data access, security policy, and execution location will increasingly converge into the same infrastructure decision. A common control plane can give enterprises more deployment freedom while increasing the reachable market for model builders. Over time, that can expand VAST's role in the AI stack by connecting persistent data, trusted execution, governance, and model placement within the same architecture, moving the company closer to making models managed resources inside the AI Operating System.

Author Information

Don Gentile | Analyst-in-Residence, Data Platforms & Resiliency

Don Gentile brings three decades of experience turning complex enterprise technologies into clear, differentiated narratives that drive competitive relevance and market leadership. He has helped shape iconic infrastructure platforms including IBM z16 and z17 mainframes, HPE ProLiant servers, and HPE GreenLake — guiding strategies that connect technology innovation with customer needs and fast-moving market dynamics. 

His current focus spans flash storage, storage area networking, hyperconverged infrastructure (HCI), software-defined storage (SDS), hybrid cloud storage, Ceph/open source, cyber resiliency, and emerging models for integrating AI workloads across storage and compute. By applying deep knowledge of infrastructure technologies with proven skills in positioning, content strategy, and thought leadership, Don helps vendors sharpen their story, differentiate their offerings, and achieve stronger competitive standing across business, media, and technical audiences.