
Confidential AI: protecting enterprise data and model weights at once
VAST Data has launched DataEnclave, an architecture that keeps sensitive enterprise data under customer control while model builders retain their weights. It relies on encryption, hardware-isolated enclaves and cryptographic attestation.
Enterprises want to run AI on their most sensitive data, but the companies that build the models refuse to hand over their weights. That mutual need for control created a stalemate that confidential AI tries to break.
A two-sided trust problem
Enterprise AI must satisfy two parties. Organizations need to keep sensitive data under their control, while model builders must protect the weights and software that represent years of research and IP.
Alon Horev, CTO and co-founder of VAST Data, told The New Stack the problem is sharpest when AI handles customer data. “Even if you ask the model today to obfuscate a conversation or redact PII from a conversation, it's hard to have 100% confidence that's the case,” he said.
He says the most capable models are increasingly delivered as SaaS services, the simplest way for their creators to distribute them. But data sent across the WAN passes through more systems and operators, and organizations may be unwilling to rely on a provider's promise not to retain it. Many therefore keep some datasets on-premises.
How confidential computing works
Encryption at rest and in transit protects stored and moving data. Confidential computing extends that protection into the processing environment: hardware-isolated execution creates an enclave where data and model weights stay encrypted until released to an approved workload.
Cryptographic attestation verifies the hardware, virtual machine and software requesting access before keys are released. A model builder can encrypt its model with the public key of a specific confidential VM, so only that VM's private key can decrypt it in protected memory. The customer uses the model without accessing its weights.
Independent key control keeps the sides separate: the enterprise holds the keys to its data, the builder the keys to its model, and the operator controls neither.
VAST DataEnclave and its ecosystem
DataEnclave, launched on September 22, is a capability of the VAST AI Operating System. It brings the model, the application layer and the data platform together under customer-controlled conditions, so the provider ships software without surrendering IP.
Horev says the company works with model builders such as Cohere, Deepgram, Factory, Fundamental and TwelveLabs, alongside infrastructure and security providers including NVIDIA, CrowdStrike, Fortanix, Nscale, Cisco and Supermicro. Confidential AI needs more than a protected GPU.
Cost, operations and agentic AI
Customer-controlled infrastructure also changes the cost conversation, though it does not automatically make AI cheaper. “This world of agentic AI is moving extremely fast, and we need to limit what an agent can see and do,” Horev says. Teams need a single pane of glass, sandboxes and observability.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.