CoreWeave Remote Key Encryption keeps AI storage keys in customer-controlled KMS or HSM systems, while the provider stores ciphertext rather than keys.
Key takeaways
- Remote Key Encryption keeps encryption keys in a customer-controlled KMS, HSM or secrets manager.
- CoreWeave says encryption runs client-side and its storage receives ciphertext rather than customer keys.
- Limited availability is planned later in 2026, so customers need to validate integrations and operating controls before production use.
What CoreWeave announced
CoreWeave introduced Remote Key Encryption on September 22 as a service for encrypting data stored on its AI cloud while leaving key custody with the customer. The company says encryption occurs client-side inside the customer’s trusted compute boundary. Keys remain in the customer’s secrets manager, key management system or hardware security module, and CoreWeave receives ciphertext. SiliconANGLE independently confirmed the launch, architecture and expected limited-availability timing.
Why key custody blocks AI projects
Training data, model weights and checkpoints can contain regulated or commercially sensitive information. Security reviewers need to know who can decrypt those assets and how access is revoked. A provider-managed key service can leave the cloud operator inside that trust boundary. CoreWeave Remote Key Encryption is designed to remove that dependency by making the customer’s existing key system the authority for generation, storage, rotation and revocation.
The design preserves existing controls
CoreWeave says the first release will protect AI Object Storage and work with HashiCorp Vault Enterprise plus systems that support the Key Management Interoperability Protocol. Reusing an existing KMS or HSM can keep audit trails, separation of duties and rotation procedures consistent across clouds. Customers should verify which algorithms, object operations, failure modes and latency characteristics are supported, and whether every data copy stays inside the encrypted boundary.
External keys create operational duties
Holding the keys gives customers control and responsibility. A deleted, expired or unavailable key can make data unrecoverable or interrupt training and inference. Teams need backup, quorum, disaster-recovery and break-glass procedures that do not undermine separation of duties. They should also test what happens when the key service is unreachable, when permissions change mid-job and when encrypted objects move between regions or services.
What to test before adoption
CoreWeave says support access to dedicated nodes remains subject to explicit customer permission, but buyers should request evidence for every trust-boundary claim. A pilot should trace plaintext, ciphertext, keys, logs and administrators through the complete lifecycle. It should measure encryption overhead, key rotation during active workloads, restore behaviour and revocation speed. The launch addresses a real enterprise objection; production value will depend on reliable integrations and auditable operations after limited availability begins.
Facts table
| Disclosure date | 22 September 2026 |
|---|---|
| Availability | Limited availability later in 2026 |
| Initial storage target | CoreWeave AI Object Storage |
| Named key system | HashiCorp Vault Enterprise |
| Interoperability | KMIP-compatible KMS and HSM products |
Frequently asked questions
What is CoreWeave Remote Key Encryption?
A service that encrypts CoreWeave-hosted data while keeping keys in customer-controlled key infrastructure.
Does CoreWeave store the customer keys?
The company says no; CoreWeave stores ciphertext while keys remain in the customer trust boundary.
When is it available?
CoreWeave says limited availability is planned later in 2026.
Which key systems are planned?
HashiCorp Vault Enterprise and KMIP-compatible KMS or HSM products are named for the initial release.
Related Lapaas Voice coverage
- NTT DATA expands AI infrastructure operations
- Amazon Leo adds six Ariane 64 launches
- OpenAI model misalignment framework
Verification sources: CoreWeave announcement SiliconANGLE
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



