VAST Data targets AI data sovereignty with DataEnclave
Wed, 30th Sep 2026 (Today)
VAST Data is positioning its new DataEnclave technology as a way for enterprises and governments to run AI workloads on sensitive information without exposing either the underlying data or the AI models being used to the other party.
The technology addresses a gap in protecting data while it is actively being processed, according to the company, extending security controls beyond data stored on disk or moving across a network.
John Mao, VP, Global Technology Alliances at VAST Data, said the technology is particularly relevant to the APAC region, where organisations must navigate data sovereignty and regulatory considerations across multiple countries.
"It's much more complex because you have lots of sovereign nations with their own rules and regulations," Mao said.
For multinational organisations operating across the region, data may need to remain within specific national borders while still being made available to increasingly sophisticated AI systems.
Mao said the challenge is becoming more pronounced as enterprises seek to use AI services that may otherwise require sensitive information to be transferred to an external cloud or AI processing environment.
"The AI has to be deployed in countries sovereignly with wherever the data is already residing," he said.
The company is consequently looking to reverse the traditional model of moving data to AI infrastructure, instead bringing AI processing to where the data is held.
Protecting data while it is in use
VAST Data's pitch centres on three stages of data protection: data at rest, data in transit and data in use.
It has historically focused on protecting data while it is stored, including through encryption and integrations with key management providers.
Data can also be protected while travelling between systems, including across data centre networks or the internet.
The remaining challenge is what happens once encrypted information reaches the processor.
For conventional computing, data ultimately needs to be decrypted before a CPU or GPU can process it.
Mao said this creates a potential security gap because sensitive information can temporarily exist in system memory in an unencrypted form.
"If you don't have something like DataEnclave or trusted computing technology, a rogue actor, or unauthorised use or vulnerability in the system could effectively dump or look into the memory space of either the CPU or the GPU," he said.
VAST Data is using confidential computing to address this stage of the process, protecting information while it is actively being used by the computing environment.
The same principle applies to AI models.
Weights can represent highly valuable intellectual property for model developers, while enterprises can create their own sensitive intellectual property by fine-tuning publicly available or open-weight models with proprietary internal data.
Organisations will often take an existing model and conduct additional training or tuning using their own datasets, Mao said.
"The output of that becomes an optimised, tailored model for your organisation," he said.
That customised model can then become a proprietary asset in its own right.
For AI model developers, the model itself may represent the core intellectual property behind their business. For enterprises, meanwhile, the model can potentially contain information derived from the data used during training or post-training.
Tampering with or extracting information from those models therefore could create risk for both sides.
Data sovereignty becomes AI challenge
Data sovereignty is a critical consideration for multinational organisations, particularly in highly regulated industries.
AI is introducing a new dimension, as organisations increasingly seek to use it without moving sensitive datasets outside the jurisdictions in which they are stored.
The problem is particularly relevant across APAC, where countries operate under different regulatory frameworks within the region.
While multinational cloud providers have already developed infrastructure designed to address some data residency requirements, AI creates a more complex problem because many AI services are still delivered from infrastructure outside the country where an organisation's data resides.
"A lot of enterprises really want access to AI, but the AI has to be deployed in countries sovereignly with wherever the data is already residing," Mao said.
Under the conventional model, an organisation may send information to an external AI SaaS platform or cloud environment for processing.
For some organisations, particularly those operating under strict regulatory requirements, that may not be viable.
VAST Data's approach is to enable AI workloads to operate within the same sovereign environment as the data, rather than requiring organisations to export sensitive information for processing.
Government, regulated industries represent initial use cases
VAST Data expects government and highly regulated industries to be among the initial markets for the technology.
Banking, healthcare and retail are among the sectors Mao identified as relevant because they commonly handle personally identifiable information and other sensitive consumer data.
Regulation is a major driver in these industries, but security concerns spanning multiple sectors could broaden the market beyond government and regulated industries, Mao said.
"Everybody obviously cares about security," he said.
The rise of AI introduces additional security considerations because organisations are increasingly incorporating external models, AI services and AI-generated processes into their technology environments.
That creates a wider requirement to understand not only where enterprise data is stored, but what happens to it while AI systems are processing it.
Trust factor remains critical
Despite the emphasis on cryptographic protection, Mao acknowledged that technology alone cannot establish trust between organisations.
A platform providing secure AI processing still has to be operated by an organisation that customers and partners are prepared to trust.
He compared the issue with the way large enterprises assess cloud providers.
Trust can be based on factors including the provider's size, corporate structure, certifications, compliance requirements and operational processes.
"Trust is not just based on one thing; it's many, many things," Mao said.
VAST Data says its technology provides the technical foundation for that trust, while recognising that service providers will need to address broader operational and organisational requirements.
The company is also looking at external assessments and certifications as part of the process of establishing confidence among customers and partners.
Much of the existing trust between technology providers and customers is also reinforced through contracts and legal agreements.
Mao said confidential computing adds a technological layer of assurance by allowing organisations to verify how their data and intellectual property are protected during processing.
The broader objective is to give the owners of sensitive data and AI models greater control over how those assets are used.
As enterprises across APAC increase their adoption of AI, that question is becoming increasingly important: not simply where an AI model is hosted, but where sensitive information is processed and who can access it while the model is running.
VAST Data is betting that confidential computing can help organisations answer those questions without having to choose between sovereign control and access to advanced AI capabilities.