LOADING STANDARDS ·· 0%
5 Interlocking Frameworks

"We say no more often than we say yes.
That's what makes yes mean something."

Five interlocking frameworks — engineering, legal, insurance, vendor accountability, and audit — that together form the institutional trust architecture of Verde Compute.

A · Engineering B · Legal Architecture C · Insurance D · Vendor Accountability E · Audit & Transparency
A
Engineering Standards
The people behind
the infrastructure.

Hardware is a commodity. The team operating it is not. These standards govern every engineer on every Verde Compute deployment.

A1 — Engineer Level

L3 Minimum · L4 Leads on Every Deployment

L1 and L2 engineers do not work on Verde Compute infrastructure — under any circumstance. Every team includes L3 engineers capable of autonomous root-cause analysis without escalation, and L4 leads for system design and complex problem resolution. AI Architecture leads are assigned to every client deployment.

A2 — NVIDIA Certification

NVIDIA-Certified Engineering Standard · L3 Minimum Required · Vendor-Validated

Theoretical knowledge is insufficient. Every engineer is required to hold a current, valid NVIDIA certification — not a credential from a prior generation — as a condition of deployment assignment. Verde Compute is designed to maintain direct access to NVIDIA Core Engineering support channels for all active client deployments, per engagement.

A3 — Dedicated Model

Your Team. No One Else's.

The conventional approach — a shared pool serving multiple clients — is incompatible with the level of focus institutional workloads require. Verde Compute operates exclusively on the dedicated model.

Conventional Approach
Client A →
Client B → Shared Pool → Engineers
Client C →

Divided attention. Competing priorities.
Verde Compute
Client A → Team A (~20 engineers)
exclusively yours

Client B → Team B (~20 engineers)
exclusively theirs
A4 — Hardware Standard

NVIDIA Blackwell · Priority Allocation Track · 72-Hour Burn-in Mandatory

No hardware below the Blackwell generation is deployed — for any client, at any price point. Every pod completes a minimum 72-hour factory burn-in validation, required to be independently certified by a qualified third party. A certificate of validation is to be provided to the client prior to go-live.

A5 — Infrastructure Commitment

Mission-Critical · 2N Fault-Tolerant — Contractually Enforced

Verde Compute does not operate from facilities below this standard:

CriterionVerde Compute Standard
Client SLA99.9% client-facing managed service (≤8.76 hrs/year) · Emergency Cloud Compute automated failover · activation timeline committed per engagement MSA
Infra Uptime99.999% DC power & cooling SLA (≤52 min/year) · contractual DC obligation with SLA credit tiers
MaintenanceConcurrently maintainable · 72-hour advance notice for maintenance windows
Redundancy2N dedicated power path + cooling
Fault ToleranceSingle failure cannot cause downtime
SLA BreachFinancial compensation — not service credits
C
Insurance Consortium — 20 Policies
Institutional risk mitigation
designed for every scenario.

Verde's insurance framework encompasses 20 policy layers — covering hardware, business interruption (full-term BI coverage), force majeure, cyber-physical events, delay in start-up (DSU), contingent BI, employment practices, trade credit, and engagement-sized surety bonds. Clients are named Additional Insured on Cyber Liability, CGL, and Property layers — giving direct insurance rights. Policy terms, carrier details, and coverage limits are confirmed at engagement execution and documented in the applicable MSA. Key policies documented below; full schedule available under NDA. See Protection → for the complete 20-policy breakdown.

ALOP / DSU Coverage

Targeted coverage for revenue loss from project-start delays. 24-hour waiting period design. Financier-named beneficiary structure. Policy structured at engagement.

Political Risk & Export Control

Targeted coverage for geopolitical disruptions and export restriction events. Multi-jurisdictional coverage design. Terms confirmed at engagement.

E&O Recourse Clause

Engineering error liability framework — designed with contractual recourse to vendor. Client-facing coverage structured independently of vendor response timelines.

Key-Person Coverage

Business continuity design for loss of key personnel. Succession protocol pre-defined in engagement agreement. Policy confirmed at operational launch.

Hardware Replacement

Zero-wait hardware replacement in the event of GPU hardware failure. Spare parts on-site via consignment depot.

Commercial Credit Structure

Credit guarantee structure available — terms and structure disclosed under NDA at engagement stage.

Data Center Disruption

Mission-critical facility operator disruption coverage. Coordinated with operator SLA enforcement.

Cyber & Data Breach

Data exfiltration and ransomware event coverage. 72-hour client notification commitment.

Trade Receivables Insurance

Financier-named client receivables policy. Structured as a senior credit enhancement instrument.

Political Surety Bond

Government-action disruption coverage. Relevant for sovereign AI and defense-adjacent deployments.

D
Vendor Accountability
Every vendor.
Same standard we hold ourselves to.

Our commitments to you are backed by contractual obligations from every vendor in our supply chain. The accountability chain extends to every partner.

Primary Hardware OEM

Tier-1 NVIDIA-Certified Manufacturer · Contractual SLAs

  • 72-hour factory burn-in validation · independently certified · certificate issued
  • 4-hour on-site service SLA — technician physically on-site within 4 hours
  • Delivery delay liquidated damages: targeting 0.5% of contracted hardware value per week, max. 10% cap (rate confirmed in OEM agreement at engagement)
  • Consignment spare parts depot maintained on-site
  • Rapid inventory replenishment — SLA-committed response
  • 7/24 OEM resident engineer on-site during deployment lifecycle (contractually required per vendor accountability framework)
NVIDIA

NVIDIA AI Enterprise SP License · Full Stack · Mission Critical Support

  • Service Provider / MSP license: Verde is licensed operator — all Verde clients access full NVIDIA AI Enterprise suite under Verde's master agreement, no per-client NVIDIA contract required
  • Full software stack: NIM Microservices · NeMo · Triton Inference Server · TensorRT-LLM · Run:ai Pro · DCGM Enterprise · RAPIDS · NGC Enterprise
  • Run:ai Pro Orchestration: fractional GPU, MIG partitioning, per-client quotas, guaranteed GPU floor + burst — complete workload isolation between clients
  • Managed Inference API (Standard): Triton Inference Server REST/gRPC endpoints, P99 latency target: <50ms for models up to 7B parameters under standard load (confirmed per engagement SLA)
  • P1 L3/L4 direct NVIDIA engagement within 2 hours · Dedicated TAM — named contact, not a queue · escalation to VP Engineering
  • CVE patch SLA: CVSS ≥7.0 patched within 30 days · 12-month advance EOL notice · benchmark compatibility guaranteed before any update
  • Confidential Computing (TEE) enabled for all clients · PSIRT direct security advisory feed · annual GPU hardware attestation for regulated-industry clients
  • Annual roadmap briefing · 30-day early access to new NIM models before GA
Facility Operator

Tier-3 Certified Facilities · Pacific Northwest · Multi-Certified

  • DC power & cooling SLA: 99.999% (≤52 min unplanned downtime/year) · Verde client-facing managed service SLA: 99.9% · both contractually committed per engagement
  • 2N dedicated power path + cooling — fault-tolerant, no single point of failure
  • SOC 2 Type II · ISO 27001 certified facility · annual audit reports provided to Verde and client auditors
  • SSAE 18 / AT-101 physical security certification · HIPAA-ready physical infrastructure (DC operator standard)
  • FM-200 / NOVEC 1230 clean agent fire suppression — wet-pipe sprinkler systems expressly prohibited in Verde's compute hall
  • Seismic-rated installation — Pacific Northwest code compliance · seismic zone certificate provided at contract signing
  • 4-Eyes Policy: minimum 2 authorized personnel required for all cage access · biometric + PIN double-door man-trap
  • 7/24 Smart Hands VIP: 15-minute P1 on-site response · 90-day CCTV retention · 24/7 on-site security personnel
  • 100% renewable energy · REC-certified · LEED certification · monthly REC + carbon footprint certificates for client ESG reporting
  • BGP failover <30 seconds · carrier-diverse dual fiber · 40Gbps DDoS scrubbing included
  • SLA breach: financial compensation per defined credit tiers — not service credits only
E
Audit & Transparency
Four-layer independent
audit. Every stakeholder.

Verde Compute provides periodic independent audit reports to all authorized counterparties. Transparency is a contractual commitment, not a marketing claim.

Daily · AutonomousLayer 1
  • Automated infrastructure health monitoring — GPU utilization, thermal, power, memory, network I/O
  • Anomaly detection and automated alerting — immediate escalation for threshold breach
  • Uptime tracking against SLA targets — real-time availability ledger maintained
Monthly · InternalLayer 2
  • Internal operational review: SLA performance, incident log, resolution timeline analysis
  • Financial reporting to all designated counterparties: compute utilization, invoicing, escrow reconciliation
  • Engineer performance review against certification and response-time SLA commitments
Quarterly · IndependentLayer 3
  • Independent third-party audit of infrastructure standards, security posture, and physical access controls
  • Vendor SLA compliance review — OEM, NVIDIA, facility operator performance against contractual commitments
  • Audit reports issued simultaneously to all designated counterparties — no sequencing, no pre-clearance
Annual · Full ScopeLayer 4
  • Full-scope annual review including legal structure, SPV compliance, insurance coverage adequacy, and regulatory alignment
  • Hardware lifecycle and refresh assessment — generation maintenance confirmed against engagement standard
  • Annual GPU Performance Benchmark — independent validation confirms ≥95% rated TFLOPS per GPU and NVLink bandwidth within specification. Written benchmark report delivered to all designated counterparties — financier, client, and Verde board
  • Comprehensive stakeholder report — executive summary available to institutional counterparties on request
F
Standard F — Compliance & Regulatory
Four frameworks.
One compliance posture.

Verde's compliance architecture covers the full spectrum of institutional client requirements — financial services, healthcare, government, and defense. All four frameworks are structured as integrated operational systems — activated at first client engagement.

Mandatory — All Engagements
SOC 2 Type II — All 5 Trust Service Categories
AICPA · 12-Month Observation Period · Big 4 Auditor

Verde's primary certification. SOC 2 Type II is a universal requirement for Verde's institutional client base — no engagement can proceed to go-live without it. Observation period begins at Commercial Go-Live (Q1 2027); Type II report issued Q3 2027. All five Trust Services Criteria in scope — Security (CC1–CC9), Availability (A1), Processing Integrity (PI), Confidentiality (C1), and Privacy (P). Type I issued Q1 2027 for early-stage client procurement requirements. Big 4 auditor selected via competitive RFP.

Security CC1–CC9Availability A1Processing Integrity PIConfidentiality C1Privacy PBig 4 AuditorQ3 2027 Type II
Activated — Healthcare Clients
HIPAA Security Rule — Business Associate Framework
45 CFR Part 164 · BAA Required · Annual SRA

Verde functions as a Business Associate under HIPAA — providing compute infrastructure that may process Protected Health Information on behalf of healthcare clients. HIPAA compliance is activated at first healthcare client onboarding: Business Associate Agreement (BAA) executed, Annual HIPAA Security Risk Assessment (SRA) conducted, HIPAA-specific training for client-facing staff completed. Verde's SOC 2 Technical Safeguards substantially satisfy HIPAA technical requirements — CC6 (access controls), CC7 (monitoring), CC9 (incident response). HIPAA Breach Notification: Verde notifies client within 2 hours of incident confirmation (contractual P1 SLA). Client notifies HHS within 60 days per statute.

BAA Executed at Go-LivePHI Encryption AES-256Audit Logging 1yrBreach: 2hr Verde → ClientAnnual HIPAA SRA
Ongoing — All Engagements
ITAR / EAR Export Controls
22 CFR Parts 120–130 · 15 CFR Parts 730–774 · Annual Review

NVIDIA Blackwell-class compute systems and NVIDIA AI Enterprise software are subject to US Export Administration Regulations. Verde's export control posture: (i) ECCN classification confirmed by outside counsel for all hardware SKUs; (ii) End-User Certificate signed by each client at contract execution — certifying no prohibited end-use, no re-export without authorization, no foreign government transfer; (iii) Denied Party Screening — client entity and all beneficial owners ≥25% screened against OFAC SDN, BIS Entity List, BIS Denied Persons List, and DDTC Debarred Parties List before contract signing and annually thereafter; (iv) Technology Control Plan (TCP) documenting access control for controlled technology. All Verde hardware remains on US soil. Verde operates 100% US jurisdiction in Phase 1.

ECCN ClassificationEnd-User CertificateOFAC ScreeningBIS Entity ListTCP DocumentedUS Soil Only
Internal Governance Standard
NIST Cybersecurity Framework 2.0
CSF 2.0 (Feb 2024) · 6 Functions · SP 800-53 Ready (Phase 2)

Verde adopts NIST CSF 2.0 as its internal cybersecurity governance standard — de facto requirement for US government and defense clients, and the most recognized framework for institutional procurement. CSF 2.0's six functions implemented: Govern (GV) — board-level cybersecurity policy, CISO reporting line, lender covenant reporting; Identify (ID) — full asset inventory, annual risk assessment; Protect (PR) — MFA/RBAC/PAM, AES-256 encryption, annual security training (engagement NOC team); Detect (DE) — SIEM real-time alerting, NVIDIA DCGM GPU anomaly detection, monthly vulnerability scans; Respond (RS) — IRP P1–P4 classification, 2-hour P1 client notification, semi-annual tabletop exercises; Recover (RC) — BCP/DR plan, annual DR drill, Emergency Cloud Compute activation. NIST SP 800-53 readiness and CMMC Level 2 are Phase 2 extensions for government/defense clients.

Govern (GV) · new in CSF 2.0Identify · Protect · DetectRespond · RecoverSP 800-53 Phase 2CMMC L2 Phase 2
Security Operations Toolchain
GPU Health Monitoring
NVIDIA DCGM
ECC SBE/DBE, XID errors, PCIe health, thermal throttle — real-time across all deployed GPUs
SIEM & Alerting
Grafana Enterprise + PagerDuty
90-day log retention minimum. Real-time anomaly detection. On-call rotation with 15-min P1 response target
Compliance Automation
GRC Platform
Vanta / Drata / Secureframe (to be selected). Continuous evidence collection. Auditor read-only portal access during Type II observation period
Annual Security Test
Penetration Test
External + internal + social engineering + GPU infrastructure-specific. Full report with remediation tracking delivered to Verde CISO and lender summary
Security Policies
  • Information Security Policy
  • Access Control Policy
  • Privileged Access Management Policy
  • Password / Credential Policy
  • Encryption Policy (AES-256 / TLS 1.3+)
  • Network Security Policy
  • Endpoint Security Policy
  • Patch Management Policy (30-day CVSS≥7.0)
  • Vulnerability Management Policy
  • Physical Security Policy
  • BYOD Policy
Operations & Governance
  • Change Management Policy (CAB process)
  • Incident Response Plan (IRP · P1–P4)
  • Business Continuity Plan (BCP)
  • Disaster Recovery Plan (DRP)
  • Vendor Risk Management Policy
  • Asset Management Policy
  • Risk Management Policy
  • Acceptable Use Policy
  • Security Awareness Training Policy
  • Background Check Policy
  • Log Management & SIEM Policy
Data, Privacy & Regulatory
  • Data Classification Policy
  • Data Retention & Deletion Policy
  • Privacy Policy (External)
  • HIPAA Security Policy (healthcare)
  • HIPAA Breach Notification Policy
  • Export Control / ITAR Policy
  • Technology Control Plan (TCP)
  • Whistleblower / Ethics Policy
  • Software License Compliance Policy
  • Media Sanitization Policy
32 policies total · Approved by CEO/CISO · Annual review cycle
Begin the Conversation
Standards you can
take to your board.

Full technical and legal documentation available post-NDA. No commitment required until MSA is signed.