TL;DR — Key Takeaways
– VAST Data extended its DataEnclave confidential computing capabilities to self-hosted and on-premises IT environments, helping organizations protect sensitive data accessed by AI applications and agents.
– DataEnclave uses NVIDIA Confidential Computing to isolate AI workloads within trusted execution environments (TEEs), protecting data during processing.
– Cryptographic attestation, customer-managed encryption keys and tamper-proof audit records enable organizations to enforce security policies and maintain visibility into AI workloads.
VAST Data this week extended a confidential computing capability to self-hosted and on-premises IT environments to protect data accessed by artificial intelligence (AI) applications and agents while running in memory.
The VAST DataEnclave platform is based on VAST DataEngine, an instance of a confidential computing framework developed by NVIDIA that VAST Data makes available for its VAST AI Operating System for managing data storage. The NVIDIA Confidential Computing framework requires processors that support virtual machines that provide a Trusted Execution Environment (TEE) running on NVIDIA graphics processing units (GPUs) and CPUs to isolate data while running in memory. IT administrators, as a result, are not able to access encrypted data running in guest memory, GPU memory or on the NVLink networking cards.
At the core of VAST DataEnclave is an isolated container runtime and cryptographic attestation that verifies the environment and enforces policies before AI models and sensitive data are decrypted and loaded to ensure security. AI models only execute inside secure enclaves established via a TEE that the VAST platform for auditing purposes is able to attest before releasing decryption keys. Records of attestation events, key releases and enclave lifecycle actions are stored in a tamper-proof, queryable VAST DataBase to provide an audit trail. IT teams, as a result, can maintain their own keys using their own key management system (KMS) to enforce controls and policies.
Finally, the container runtime can be based on the Trustee runtime for confidential computing that is being advanced by the Cloud Native Computing Foundation (CNCF) or, alternatively, IT teams can opt to deploy dedicated IT infrastructure provided by Fortanix.
Aaron Chaisson, vice president of product and solutions marketing for VAST Data, said the VAST DataEnclave platform is designed mainly for highly regulated industries that require data at rest, in motion and running in memory to always be encrypted. The overall goal is to enable IT teams to manage AI models as a logical resource alongside data rather than trying to manage them as another type of application that has been deployed on that IT infrastructure, he noted.
In the near future, VAST Data also plans to extend that capability further by making it possible to route prompts to a specific AI model that is best optimized to respond based on the data it has access to and the cost of the output generated, added Chaisson.
Adoption of confidential computing, in general, has been somewhat limited mainly because setting up and maintaining the virtual machines that require specific classes of processors is challenging. However, VAST Data is now making a case for managing that infrastructure at a higher level of abstraction. The overall goal is to make confidential computing more accessible at a time when many IT teams are revisiting their approach to data security in the AI era, noted Chaisson.
Hopefully, the end result will be more secure IT environments that are designed from the ground up to secure AI models and agents because, otherwise, the number of incidents that could occur when thousands of AI agents are accessing data in real time could easily spiral out of control.

