Urgent.News

What's breaking now, across thousands of outlets.

Tech

Exclusive: CoreWeave launches Remote Key Encryption to keep customer keys off its cloud

Artificial intelligence cloud provider CoreWeave Inc. today unveiled Remote Key Encryption, a service that encrypts customer data sitting on its infrastructure with keys the company itself never holds. The service takes aim at the key-custody problem that keeps enterprise AI projects parked in security review. Auditors want a named list of everyone able to decrypt […] The post Exclusive:…

Exclusive: CoreWeave launches Remote Key Encryption to keep customer keys off its cloud

Artificial intelligence cloud provider CoreWeave Inc. has unveiled Remote Key Encryption, a service that encrypts customer data on its infrastructure without holding the encryption keys itself. This service aims to address the key-custody issue that often hinders enterprise AI projects from moving to production. Auditors typically require a list of all parties with decryption rights, and on most clouds, the cloud provider is part of that list.

CoreWeave's solution ensures that encryption occurs on the client side, using keys generated and stored in the customer's existing secrets manager, key management system, or hardware security module. No keys are imported into CoreWeave's systems, meaning the company only ever handles ciphertext. Customers maintain control over access to the nodes, with CoreWeave's Support Access Management controls gating entry.

The service handles rotation, expiration, and revocation through the customer's existing tools and schedules. CoreWeave claims this approach streamlines key lifecycle management and is patent pending. The encryption algorithms used are standard industry ones. Andy Manoske, product lead for enterprise and security at CoreWeave, and Paul Friedman, head of security foundations, emphasize that the goal is to seamlessly integrate CoreWeave's security layer with the customer's existing security infrastructure.

This approach aligns with CoreWeave's identity management solution, CoreWeave IAM, which allows customers to use their own identity providers, such as Microsoft Entra or Okta, for authentication and authorization. Another key offering, SUNK, is designed to manage access for training clusters. It packages the open-source job scheduler Slurm for Kubernetes, syncing user and group information from the customer's federated identity provider to the Slurm account upon authentication.

This means that adding a researcher to a group in Microsoft Entra or Okta instantly grants them access to a cluster node. Remote Key Encryption will be available for limited availability later this year in partnership with IBM Corp. Initially, the service will protect data on CoreWeave AI Object Storage using keys held in HashiCorp Vault or any compatible key management system.

IBM acquired HashiCorp in February 2025. The service will enter limited availability later this year, with IBM as the launch partner. CoreWeave's Fully Connected conference will take place in San Francisco from September 30 to October 1, with coverage available on demand through SiliconANGLE Media's livestreaming studio, theCUBE.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in Tech

More from Tuesday 22 September →