CoreWeave Launches Encryption Service, Never Holds Customer Keys
CoreWeave has unveiled Remote Key Encryption, a service that encrypts customer data on its infrastructure using keys the company never possesses. Encryption runs client-side within the customer's own compute boundary, with keys stored in the customer's existing secrets manager, key management system, or hardware security module. CoreWeave holds only ciphertext.
The service targets the key-custody problem blocking enterprise AI projects in security review, allowing customers to manage rotation, expiration, and revocation through their own existing tooling. Remote Key Encryption enters limited availability later this year, with IBM as launch partner, initially protecting data on CoreWeave AI Object Storage using HashiCorp Vault-compatible systems.
