Identity and access management
CoreWeave Identity and Access Management (IAM) provides fine-grained, automated control over user access across CoreWeave services, now enhanced with Automated User Provisioning (AUP).
- Fine-grained. Define exactly who or what can perform specific actions on particular resources with precise, role-based policies.
- Federation-centric. With Automated User Provisioning (AUP), CoreWeave supports integration with existing enterprise Identity Providers (IdPs) through the SCIM protocol, along with OIDC and SAML. This enables customers to use their existing identity infrastructure to automatically federate users and groups into CoreWeave IAM for workforce sign-on and workload identity federation.
- Extend your trust boundary. With CoreWeave IAM and AUP, you can use your existing identity and access management infrastructure natively on CoreWeave. Fully manage your users and groups with no changes to your operations in external IdPs such as Okta and Microsoft Entra, while automatically prescribing access to policy workflows on these principals with CoreWeave IAM.
Kubernetes and container security
CoreWeave Kubernetes Service (CKS) offers node isolation, where every node is single-tenant. This key feature empowers customers requiring maximum security for their workloads. CKS ensures that each customer cluster node operates within a securely isolated environment.
Storage encryption
CoreWeave Storage follows industry best practices with security. Encryption at rest, identity access management, authentication, and policies with role-based access strengthen data protection. CoreWeave AI Object Storage also features encryption in transit, and supports server-side encryption with customer-provided keys.
Network access controls and encryption
Create virtual, accelerated networks to manage your cloud resources on CoreWeave, powered by NVIDIA BlueField-3 DPUs. Deploy VPC networking to ensure customer network traffic stays private.
Incident response and patching
We proactively monitor and patch common CVEs and communicate those remediations to clients. We partner with various intelligence verticals to prioritize patching as quickly as possible.
CoreWeave also contracts with industry-best pentesting companies to regularly check products and services for vulnerabilities.







