CoreWeave launches encryption with customer-held keys, taking itself off the decrypt list
CoreWeave announced Remote Key Encryption: keys stay in the customer's KMS or HSM and the company holds only ciphertext; limited availability this year, object storage only, adoption unproven.
Original event 2026-09-22
CoreWeave announced Remote Key Encryption on September 22: encryption runs client-side inside the customer's own compute boundary, keys are generated and stored in the customer's existing key management system or hardware security module, and no key is imported into a CoreWeave-side store — the company holds only ciphertext.
The service targets the key-custody problem that keeps enterprise AI projects parked in security review, where the cloud provider itself sits on the list of parties able to decrypt. It enters limited availability later this year with IBM as launch partner, and the first release protects data only on CoreWeave AI Object Storage, with keys held in HashiCorp Vault or any KMIP-compatible product.
The boundary: this is the company's own announcement, training clusters are not covered yet, and there is no evidence of enterprise adoption so far.