Cohere Model Vault now offers an Encrypted tier that protects prompts and responses while models process them, not only while data is stored or travelling over a network. Cohere says the managed service uses confidential CPU and GPU environments plus remote attestation, giving security teams a technical check on the system that handled each request.
| Element | What Cohere documents |
|---|---|
| Deployment | Managed, single-tenant model inference |
| Protected path | Data in transit, at rest and in use |
| Compute boundary | Confidential VM plus NVIDIA GPU confidential-computing mode |
| Verification | Remote attestation checked by the Cohere OHTTP proxy |
| Public launch report | September 16, 2026 |
Cohere’s Encrypted Vault documentation says prompts, responses and intermediate data remain encrypted outside hardware-backed trusted execution environments. VentureBeat independently reported that the capability went live on September 16 and described it as an extension of Cohere’s existing single-tenant Model Vault service.
How Cohere Model Vault closes the in-use gap
Conventional controls usually protect a database at rest and a request in transit. Inference creates a third exposure point: a model must process the prompt in memory. Cohere Model Vault Encrypted moves that step into a trusted execution environment designed to keep the surrounding cloud operator, cluster administrator and Cohere outside the plaintext boundary.
The documented architecture spans a confidential virtual machine on the CPU side and an NVIDIA GPU running in confidential-computing mode. Cohere lists Intel TDX and AMD SEV-SNP as supported confidential-VM technologies. The design is intended to protect memory and the path between the CPU and GPU while the workload runs.
Cohere Model Vault Encrypted is a managed inference service whose central claim is verifiability: the customer can check the attested hardware and software environment before sending plaintext, while prompts and responses remain encrypted outside that trusted boundary.
Why attestation matters more than another privacy policy
Cohere documents a client-side OHTTP proxy that checks the deployment’s attestation before transmitting a request. If the measured software or security policy does not match the approved configuration, the proxy refuses the connection. Cohere also says each inference response carries an attestation certificate that a client can inspect.
This does not make every security question disappear. Buyers still need to examine key management, logging, model versions, access controls and the exact measurements covered by attestation. Yet it changes the audit conversation: a security team can ask for evidence about the environment that executed a workload instead of relying only on contractual assurances.
The mechanism fits a wider move toward governed enterprise AI stacks. Lapaas Voice has examined how AI infrastructure partnerships connect models with operational data and how agentic AI expands the security boundary. Cohere’s approach targets the inference layer itself, where sensitive prompts become readable for computation.
The India angle for regulated AI buyers
Indian banks, insurers, healthcare providers and government contractors often balance cloud convenience against data-governance obligations. Cohere Model Vault does not automatically satisfy any Indian rule or sectoral requirement, and its documentation frames GDPR, HIPAA and SOC 2 as compliance mappings rather than certifications for every customer workload.
The practical value is architectural choice. A team can assess whether confidential computing and remote attestation reduce the need to operate model-serving hardware itself, then test that claim against its own residency, audit and vendor-risk controls. The buying decision should hinge on verifiable boundaries and operational evidence, not the phrase “private AI” alone.
FAQs
What is Cohere Model Vault Encrypted?
It is an Encrypted tier of Cohere’s managed, single-tenant Model Vault inference service. Cohere says it protects data in transit, at rest and while models process it.
Can Cohere read customer prompts in the Encrypted tier?
Cohere says neither it nor the cloud operator can see plaintext outside the hardware-backed trusted execution environment. Customers should validate that claim using the available attestation evidence and their own security review.
What does remote attestation prove?
Remote attestation lets a client check that it is communicating with an approved confidential environment running expected hardware, software measurements and security policy before transmitting a request.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



