LOADING TRUST CENTER ·· 0%
For CISO · IT Security · Legal · Procurement

Enterprise procurement cycles require independent security review.
This page is built for your team.

Physical security, data handling commitments, compliance posture, and audit access — documented here for technical and legal review.

Zero Trust
Architecture — Identity-Verified Access at Every Layer
BYOK
Customer Key Sovereignty — Zero Verde Compute Access
20-Policy
Insurance Consortium — Lloyd's-class carriers · Client is Additional Insured — carrier identities confirmed at financial close
72h
Incident Notification Commitment
Protection Architecture

12 independent layers.
Every one named.

Legal isolation, financial transparency, technical sovereignty, regulatory compliance, and continuous independent audit — layered to eliminate single points of failure across every engagement.

Legal & Financial
L1
Delaware SPV
Legal ring-fence per engagement — no cross-contamination
L2
4-Account Escrow Waterfall
Lender-controlled · senior obligations paid first automatically
L3
Take-or-Pay Contract
Irrevocable 36-month client commitment — no exit
L4
20-Policy Insurance Consortium
Lloyd's-class carriers · Client named as Additional Insured — carrier identities confirmed at financial close
Technical & Infrastructure
L5
BYOK Encryption
AES-256 at-rest · TLS 1.3 in-transit · Zero Verde access
L6
Tier-3 Certified Facility
99.999% DC SLA · SOC 2 Type II · ISO 27001 · FM-200 — facility certifications confirmed at engagement
L7
Physical Access Control
Biometric 3-factor · 4-Eyes policy · 90-day CCTV retention
L8
NIST SP 800-88 Data Erasure
Zero retention · Certificate within 30 business days · NIST SP 800-88
Compliance & Audit
L9
OFAC / EAR / ITAR / GDPR
Regulatory compliance framework · OFAC screening at onboarding · Active at first engagement
L10
Daily MSOC Monitoring
Managed SOC platform · Commissioned from first operational day · SLA chronometer · NOC telemetry
L11
Monthly Financial Review
Independent CFO · Corporate Trust Officer · Stakeholder report
L12
Annual Institutional Audit
Balance sheet · Solvency opinion · Top-tier independent cyber audit + Annual Institutional Audit
Section A

Physical Security

Hardware-level physical controls governing access to client infrastructure.

Network-Isolated Dedicated Cage

Every client deployment occupies a physically isolated, locked cage with dedicated network segmentation. Zero physical or network sharing with any other client under any circumstance.

Biometric 3-Factor Access Control

All physical access to client cage requires three-factor biometric authentication. Access logs are designed to be immutable and available for client audit.

7/24 4K Thermal CCTV

Continuous 4K and thermal imaging surveillance across all facility areas. Footage retained per contractual and compliance requirements.

TEMPEST & EMP Shielding

Available for defense and classified deployments. Electromagnetic emanation controls per TEMPEST standards upon client specification.

Smart Hands On-Site 24/7

Trained facility personnel available on-site around the clock. All Smart Hands access is logged, authenticated, and auditable.

Section B

Data Handling

Absolute commitments on data residency, isolation, and handling.

"Your data never leaves your cage."

"Your data never trains anything."

No Cross-Client Data Access — Ever

Hardware-level and network-level isolation ensures no path exists between client environments. Architectural design commitment, not merely policy-based.

NIST SP 800-88 Data Erasure at Conclusion

All client data is securely erased per NIST SP 800-88 guidelines within 30 business days of engagement conclusion. A certificate of data destruction is issued to the client within this window.

72-Hour Incident Notification

In the event of a confirmed security incident, client notification within 72 hours of discovery — consistent with applicable breach notification frameworks (including GDPR Art. 33, CCPA, and NY SHIELD Act).

No Data Retention After Engagement

Verde Compute retains no client data, model weights, or workload artifacts following engagement conclusion. No backup exceptions.

Background Screening — All Engineers

Every engineer assigned per engagement is required to complete identity verification and professional background validation prior to deployment access being granted.

Annual Third-Party Penetration Test

Independent penetration testing of all infrastructure and network controls conducted annually, from first operational year. Results shared with authorized client counterparties upon request.

Formal Incident Response Plan

A documented Incident Response (IR) plan is provided to clients at engagement start. IR plan covers detection, containment, notification, and recovery procedures — tested prior to first operational day.

Engineer Access Logging

All Verde Compute engineer access to client infrastructure is logged, cryptographically hashed, and tamper-evident. Logs are available for client audit upon request at any time during the engagement.

Institutional Governance

Financial Architecture

Structural safeguards that protect clients, lenders, and insurers — built into every engagement by design.

4-Account Escrow Waterfall — Lender-Controlled

All client revenue flows through a 4-account escrow structure managed by an independent Tier-1 institutional trustee designated at financial close: A Revenue Collection · B Debt Service Reserve Account (multi-month buffer, lender-controlled) · C Progressive Enhanced DSRA (P-DSRA, builds toward one full month of contracted revenue) · D Operational Reserve Account (ORA). Verde distributions are residual-only — lender is paid first, automatically, before any Verde allocation. All authorized parties have real-time visibility into escrow balances and payment flow.

Escrow agent identity and full waterfall mechanics disclosed to qualified clients under NDA.

BYOK Hardware Encryption — Customer Keys Only

Customers hold sole possession of their hardware encryption keys. Verde Compute engineers have zero access to decrypted workload data, model weights, or training artifacts at any time. AES-256 at-rest + TLS 1.3 in-transit as standard. Keys provisioned by client prior to first operational day and never stored, copied, or accessible by Verde Compute personnel or infrastructure systems.

Tier-3 Certified Facilities · ISO 27001 · FM-200 · Seismic-Rated · 99.999% DC SLA

Pacific Northwest Tier-3+ data centers with SOC 2 Type II and ISO 27001 certification. FM-200 / NOVEC 1230 clean agent fire suppression (wet-pipe expressly prohibited in compute hall). Seismic-rated installation per Pacific Northwest code. DC power & cooling SLA: 99.999% (≤52 min/year) · Client-facing Verde managed service SLA: 99.9% (≤8.76 hrs/year). 100% renewable energy · REC-certified · monthly ESG certificates for client reporting.

Facility operator identity and full SLA terms disclosed to qualified clients under NDA.

20-Policy Insurance Consortium — Client as Additional Insured

All 20 insurance policies and endorsements pre-paid for the full engagement term at Financial Close. Consortium underwritten by Lloyd's-class carriers (carrier identities confirmed at financial close under NDA). Coverage spans: Hardware All-Risk (full replacement value) · Business Interruption (full-term BI coverage) · Cyber Liability with AI model data-recovery sub-limit · Technology E&O · Trade Credit · Surety Completion Bond · 14 further specialized policies and endorsements. Client named as Additional Insured on applicable policies — direct insurance rights, not merely a contractual claim against Verde. Zero monthly insurance invoices after go-live.

Full policy schedule and certificates of insurance provided to qualified clients under NDA.

Section C

Compliance Posture

Regulatory alignment and certification roadmap for enterprise and institutional procurement.

FrameworkDescriptionStatus
OFAC ComplianceReal-time sanctions screening via API — all engagements screened prior to executionActive — at engagement
EAR / ITARUS export control compliance architecture for all technology transfers. Technology Control Plan (TCP) documented. Denied party screening at onboarding and annuallyActive — at engagement
NIST SP 800-88Data erasure standard — applied within 30 business days of engagement conclusion; certificate of destruction issued to client within this windowActive — at engagement
GDPR / CCPA / NY SHIELD72-hour client notification commitment per applicable breach notification frameworks. Data residency and DPA documentation provided as standard. CCPA-compliant data subject request procedures in placeActive — at engagement
NIST CSF 2.0Verde's internal cybersecurity governance framework — all six core functions (Govern, Identify, Protect, Detect, Respond, Recover). Government and defense-adjacent clients. Foundation for NIST SP 800-53 readinessActive — at engagement
NIST SP 800-171Controlled Unclassified Information (CUI) protection framework — required for US Government and defense-adjacent clients. Aligns with CMMC Level 2 readiness. 110 security requirements documentedTarget: Q2 2027
HIPAA — Business AssociateHIPAA Business Associate Agreement (BAA) executed per healthcare engagement prior to go-live. PHI isolation guaranteed via infrastructure-level controls — Verde holds zero data access. Healthcare engagements additionally include FLARE Federated Learning and BioNeMo access under existing NVIDIA AI Enterprise SP licenseAvailable on Request
FM-200 / SeismicFM-200 / NOVEC 1230 clean agent fire suppression in all compute halls — wet-pipe sprinkler systems expressly prohibited. Seismic-rated infrastructure installation per Pacific Northwest building code requirementsActive
SOC 2 Type IPoint-in-time audit confirming controls are suitably designed. Distributed to lender and qualified clients. Big 4 engagement planned (competitive RFP process)Target: Q1 2027
SOC 2 Type II12-month observation period audit — security, availability, confidentiality, processing integrity, and privacy. Big 4 audited opinion. Annual re-certification cycleTarget: Q3 2027
ISO 27001Information security management system certification — aligns with NIST SP 800-53 and SOC 2 control objectives. Scope and target dates confirmed in partnership with each engagement counterpartyRoadmap TBD — confirmed at engagement
SSAE 18 / AT-C 320Financial controls audit — primary credential for lenders and insurance underwritersPlanned — Year 1
EU AI ActInfrastructure architecture alignment — high-risk AI system deployment supportRoadmap
NIST AI RMFAI Risk Management Framework alignment for US government and defense-adjacent clientsRoadmap
ISO 42001AI Management System standard — governance framework for AI operationsRoadmap
Section D

Audit Access

Independent, multi-layer audit framework — accessible to all authorized counterparties.

Layer 10 · Daily · Autonomous MSOC/MIM Monitoring

Planned security operations platform (Datadog / CrowdStrike / Palo Alto Unit 42 class) — to be commissioned from first operational day per engagement agreement. Real-time SLA chronometer and telemetry logs available to clients.

Layer 11 · Monthly · Financial Review

Independent Fractional CFO engagement (to be appointed prior to first client engagement). Dedicated Corporate Trust Officer. Monthly financial summary to all designated stakeholders.

Layer 12 · 6-Month Cyber Audit + Annual Institutional Audit

Tier-1 independent cyber audit (DNV / TÜV SÜD class, or equivalent) every 6 months. US-licensed CPA tax verification. Annual: top-tier internationally recognized balance sheet audit, independent hardware asset valuation, solvency opinion, and capital adequacy certificate. Full annual transparency report. Effective from first operational year.

Full Standards Detail

Complete audit methodology, vendor accountability framework, and engineering standards are documented on the Standards page →

SOC 2 Certification Timeline.
Independent. Big 4.

Verde Compute's compliance program is sequenced to match client procurement cycles — Type I ahead of first engagement, Type II by Q3 2027. Auditor engagement subject to a competitive selection from Big 4 firms.

Q2–Q4 2026 — Active
Controls Framework Design

Mapping internal procedures to all five AICPA Trust Services Criteria — Security (CC1–CC9), Availability (A1), Processing Integrity (PI), Confidentiality (C1), and Privacy (P). Scope: Verde NOC operations, BYOK key management, SLA monitoring, vendor access. All five TSC targeted for maximum institutional client coverage.

Planned — Q4 2026
Readiness Assessment

Independent readiness assessment with selected auditor — gap analysis against SOC 2 criteria. Remediation plan issued. Internal evidence collection procedures confirmed and tested.

Target — Q1 2027
SOC 2 Type I Report — Point-in-Time

Type I: auditor confirms controls are suitably designed at a specific date. Available to clients under NDA. Delivered in advance of or concurrent with first client go-live for regulated-industry clients requiring upfront compliance documentation.

Target — Q3 2027
SOC 2 Type II Report — 6-Month Observation Period

Type II: auditor confirms controls operated effectively over a 6-month period. Observation window begins Q1 2027. Report issued Q3 2027. Annual thereafter. Issued directly to clients upon execution of NDA — not via third-party portal.

Trust Services Criteria in Scope
  • Security (CC1–CC9) — Common Criteria: logical/physical access, change management, incident response, monitoring
  • Availability (A1) — Uptime SLA commitments, NOC shift coverage, capacity management
  • Confidentiality (C1) — BYOK encryption, data isolation, NDA enforcement
  • Processing Integrity (PI1) — Workload accuracy, completeness, authorization controls
  • Privacy (P1–P8) — Personal data handling, consent, retention, disclosure
SOC 2 Type II and ISO 27001 certification timelines will be confirmed in partnership with each engagement counterparty. Compliance documentation shared with qualified counterparties under NDA.
Enterprise Engagement

Security review complete.
Ready to proceed?

Submit your enterprise inquiry. Formal NDA and OFAC screening precede all technical engagements.