BlogsCoreweaveAI Infrastructure Security

AI Infrastructure Security

AI Infrastructure Security

3
posts
2026

CoreWeave is enhancing its AI infrastructure security by integrating NVIDIA BlueField-4 DPUs. This provides hardware-enforced tenant isolation using EVPN VXLAN, offloads networking and security tasks from CPUs to DPUs, and extends the zero-trust infrastructure model with finer-grained, hardware-based isolation via the BlueField Advanced Secure Trusted Resource Architecture. This aims to deliver extreme performance, scale, next-gen security, and maximum efficiency for AI workloads.

2026

CISOs' New Bar for AI Infra Security | CoreWeave Blog

7/30/2026

This post defines the new security bar for AI infrastructure, emphasizing automated enforcement, continuous visibility into existing SIEMs, hardware-enforced process isolation via DPUs, and verifiable trust through certifications and documentation. It outlines specific questions CISOs should ask providers regarding tenant isolation, shared responsibility, disclosure-to-patch cadences, telemetry integration, key management, and identity revocation.

Powering AI Innovation: CoreWeave + NVIDIA BlueField-4 | CoreWeave Blog

5/20/2026

This post details the integration of NVIDIA BlueField-4 DPUs into CoreWeave's AI cloud infrastructure. It highlights how BlueField-4's increased compute power and throughput, combined with the NVIDIA DOCA software framework, enable hardware-enforced tenant isolation through EVPN VXLAN, offloading of networking and security tasks from CPUs to DPUs, and the extension of zero-trust security with hardware-based isolation via the BlueField Advanced Secure Trusted Resource Architecture. The post emphasizes the performance, security, and efficiency benefits for AI workloads.

Security Engineered by Design

5/20/2026

This post details the implementation of NVIDIA BlueField DPUs for hardware-enforced tenant isolation and strengthening security boundaries. It outlines encryption strategies for data in transit and at rest, including support for customer-managed keys and immutable logs for traceability. Compliance efforts are expanded to include SOC 2 Type II certification for Bare Metal and CKS, with alignment towards ISO/IEC 42001 for responsible AI management. Identity management is enhanced through federated IAM, SCIM automation, and workload federation using OIDC for real-time, fine-grained access control. A new framework for full-stack integrity is introduced, leveraging hardware-based attestation and cryptographic trust from firmware to runtime, covering GPUs, DPUs, and CPUs. The post also highlights the integration of security into the AI development lifecycle through Mission Control, AI Ops, and Weights & Biases, including the Telemetry Relay service for forwarding audit and access logs to SIEM platforms. A partnership with CrowdStrike is also mentioned as extending the security foundation.