VAST Data and CrowdStrike secure AI infrastructure with Falcon
VAST Data and CrowdStrike have announced a set of integrations designed to bring endpoint and threat-detection capabilities from CrowdStrike's Falcon platform directly into VAST's AI Operating System. The partnership covers three layers: infrastructure protection via native Falcon sensor support, audit-telemetry ingestion into Falcon Next-Gen SIEM, and AI-pipeline security through Falcon Guardian's integration with VAST's InsightEngine data-enrichment product.
Native Falcon sensor support for VAST environments is certified and generally available from today. Integrations with Falcon Next-Gen SIEM and Falcon Guardian are in private preview, with no stated general-availability date disclosed in the announcement.
What the integration does
The centrepiece of the deal is the connection between VAST's audit telemetry and CrowdStrike's Next-Gen SIEM. VAST's platform records how users, applications and machine agents access data stored in its infrastructure; that access log will now feed directly into CrowdStrike's detection and correlation engine. Security teams will be able to place data-access events alongside broader network and endpoint signals, which could reduce the investigation effort required when anomalous behaviour spans both infrastructure and data layers.
The second major component involves Falcon Guardian, CrowdStrike's AI Detection and Response product, integrating with VAST InsightEngine at the point of data ingestion. As unstructured data is processed and loaded into AI knowledge bases, Guardian will scan for sensitive categories such as personally identifiable information, and flag activity consistent with prompt injection or jailbreak attempts before those inputs reach downstream models. The companies say the joint system will be demonstrated within an NVIDIA-powered AI factory environment, using NVIDIA's AI Data Platform reference design.
Renen Hallak, founder and chief executive of VAST Data, said: "By combining the VAST AI Operating System with the intelligence of the Falcon platform, customers can build AI environments where security is part of the architecture from the foundation through the AI pipeline."
Market context
The partnership reflects a broader commercial dynamic in enterprise AI: as organisations move from proof-of-concept to production AI deployments, the attack surface has expanded well beyond the model itself. Data pipelines, vector stores, retrieval-augmented generation systems and agentic orchestration layers have all emerged as targets, and traditional perimeter security models do not map neatly onto these environments.
CrowdStrike is among the most widely deployed endpoint and SIEM vendors in large enterprises, which gives VAST a meaningful route to security teams already running Falcon. For VAST, whose positioning as an "AI Operating System" vendor places it in competition with hyperscaler-native storage and pipeline tooling, a certified integration with a major security platform adds enterprise credibility. The partnership also sits within the NVIDIA ecosystem, an important distribution channel for AI infrastructure vendors.
The broader AI security category is attracting both startups and established players. Vendors including Wiz, Palo Alto Networks and Protect AI are building dedicated capabilities around AI workload protection, data-pipeline scanning and LLM-specific threat detection. Regulatory pressure is adding urgency: the EU AI Act's provisions for high-risk systems require documented data-governance and access-control measures, and the UK's emerging AI code of practice similarly stresses provenance and integrity of training and inference data.
The private-preview status of the SIEM and Guardian integrations means enterprises considering the combined platform will need to assess timelines carefully. The press release's forward-looking disclaimer notes that features in preview may change or be delayed, a standard caveat that is nonetheless material for procurement decisions.