CoreWeave Remote Key Encryption keeps AI storage keys in customer-controlled KMS or HSM systems, while the provider stores ciphertext rather than keys.

Key takeaways

  • Remote Key Encryption keeps encryption keys in a customer-controlled KMS, HSM or secrets manager.
  • CoreWeave says encryption runs client-side and its storage receives ciphertext rather than customer keys.
  • Limited availability is planned later in 2026, so customers need to validate integrations and operating controls before production use.

What CoreWeave announced

CoreWeave introduced Remote Key Encryption on September 22 as a service for encrypting data stored on its AI cloud while leaving key custody with the customer. The company says encryption occurs client-side inside the customer’s trusted compute boundary. Keys remain in the customer’s secrets manager, key management system or hardware security module, and CoreWeave receives ciphertext. SiliconANGLE independently confirmed the launch, architecture and expected limited-availability timing.

Why key custody blocks AI projects

Training data, model weights and checkpoints can contain regulated or commercially sensitive information. Security reviewers need to know who can decrypt those assets and how access is revoked. A provider-managed key service can leave the cloud operator inside that trust boundary. CoreWeave Remote Key Encryption is designed to remove that dependency by making the customer’s existing key system the authority for generation, storage, rotation and revocation.

The design preserves existing controls

CoreWeave says the first release will protect AI Object Storage and work with HashiCorp Vault Enterprise plus systems that support the Key Management Interoperability Protocol. Reusing an existing KMS or HSM can keep audit trails, separation of duties and rotation procedures consistent across clouds. Customers should verify which algorithms, object operations, failure modes and latency characteristics are supported, and whether every data copy stays inside the encrypted boundary.

External keys create operational duties

Holding the keys gives customers control and responsibility. A deleted, expired or unavailable key can make data unrecoverable or interrupt training and inference. Teams need backup, quorum, disaster-recovery and break-glass procedures that do not undermine separation of duties. They should also test what happens when the key service is unreachable, when permissions change mid-job and when encrypted objects move between regions or services.

What to test before adoption

CoreWeave says support access to dedicated nodes remains subject to explicit customer permission, but buyers should request evidence for every trust-boundary claim. A pilot should trace plaintext, ciphertext, keys, logs and administrators through the complete lifecycle. It should measure encryption overhead, key rotation during active workloads, restore behaviour and revocation speed. The launch addresses a real enterprise objection; production value will depend on reliable integrations and auditable operations after limited availability begins.

CoreWeave Remote Key Encryption operating pathThe event moves from disclosure through deployment to measurable outcome.DisclosureDeploymentOutcome
The event moves from disclosure through deployment to measurable outcome.

Facts table

Disclosure date 22 September 2026
Availability Limited availability later in 2026
Initial storage target CoreWeave AI Object Storage
Named key system HashiCorp Vault Enterprise
Interoperability KMIP-compatible KMS and HSM products

Frequently asked questions

What is CoreWeave Remote Key Encryption?

A service that encrypts CoreWeave-hosted data while keeping keys in customer-controlled key infrastructure.

Does CoreWeave store the customer keys?

The company says no; CoreWeave stores ciphertext while keys remain in the customer trust boundary.

When is it available?

CoreWeave says limited availability is planned later in 2026.

Which key systems are planned?

HashiCorp Vault Enterprise and KMIP-compatible KMS or HSM products are named for the initial release.

Related Lapaas Voice coverage

Verification sources: CoreWeave announcement SiliconANGLE

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.