AI Infrastructure Security
Security Engineered by Design

Security Engineered by Design

5/20/2026

What this post added

This post details the implementation of NVIDIA BlueField DPUs for hardware-enforced tenant isolation and strengthening security boundaries. It outlines encryption strategies for data in transit and at rest, including support for customer-managed keys and immutable logs for traceability. Compliance efforts are expanded to include SOC 2 Type II certification for Bare Metal and CKS, with alignment towards ISO/IEC 42001 for responsible AI management. Identity management is enhanced through federated IAM, SCIM automation, and workload federation using OIDC for real-time, fine-grained access control. A new framework for full-stack integrity is introduced, leveraging hardware-based attestation and cryptographic trust from firmware to runtime, covering GPUs, DPUs, and CPUs. The post also highlights the integration of security into the AI development lifecycle through Mission Control, AI Ops, and Weights & Biases, including the Telemetry Relay service for forwarding audit and access logs to SIEM platforms. A partnership with CrowdStrike is also mentioned as extending the security foundation.

Read the original post ↗