For CISO · IT Security · Legal · Procurement

Enterprise procurement cycles
require independent security review.
This page is built for your team.

Physical security, data handling commitments, compliance posture, and audit access — documented here for technical and legal review.

BYOK Hardware Enclave Security architecture

BYOK · Hardware Enclave · Zero Knowledge

Section A

Physical Security

Hardware-level physical controls governing access to client infrastructure.

Air-Gapped Dedicated Cage

Every client deployment occupies a physically isolated, locked cage. Zero physical sharing with any other client under any circumstance.

Biometric 3-Factor Access Control

All physical access to client cage requires three-factor biometric authentication. Access logs are immutable and available for client audit.

7/24 4K Thermal CCTV

Continuous 4K and thermal imaging surveillance across all facility areas. Footage retained per contractual and compliance requirements.

TEMPEST & EMP Shielding

Available for defense and classified deployments. Electromagnetic emanation controls per TEMPEST standards upon client specification.

Smart Hands On-Site 24/7

Trained facility personnel available on-site around the clock. All Smart Hands access is logged, authenticated, and auditable.

Section B

Data Handling

Absolute commitments on data residency, isolation, and handling.

"Your data never leaves your cage."

"Your data never trains anything."

No Cross-Client Data Access — Ever

Hardware-level and network-level isolation ensures no path exists between client environments. Architectural guarantee, not policy-based.

NIST SP 800-88 Data Erasure at Conclusion

All client data is securely erased per NIST SP 800-88 guidelines at engagement conclusion. A certificate of data destruction is issued to the client.

72-Hour Incident Notification

In the event of a confirmed security incident, client notification within 72 hours of discovery — aligned with GDPR, CCPA, and NY SHIELD Act requirements.

No Data Retention After Engagement

Verde Compute retains no client data, model weights, or workload artifacts following engagement conclusion. No backup exceptions.

Background Screening — All Engineers

Every engineer assigned to your deployment completes identity verification and professional history validation before engagement access is granted.

Institutional Governance

Financial Architecture

Structural safeguards that protect clients, lenders, and insurers — built into every engagement by design.

Tripartite Debt Service Escrow Protected

All client payments are held in a Tripartite Debt Service Escrow managed by an independent, licensed corporate trustee — not Verde Compute directly. Funds are disbursed to Verde Compute, the financing lender, and reserve accounts on a pre-agreed schedule. Clients and lenders have direct, real-time visibility into escrow balances and payment flow at all times.

The identity of the appointed independent trustee institution (institutional-grade US corporate trustee) is disclosed to qualified clients under NDA during the engagement process.

BYOK Hardware Encryption — Customer Keys Only

Customers hold sole possession of their hardware encryption keys. Verde Compute engineers have zero access to decrypted workload data, model weights, or training artifacts at any time. Keys are provisioned by the client prior to first operational day and are never stored, copied, or accessible by Verde Compute personnel or infrastructure systems.

BYOK Hardware Enclave Security Architecture — Customer Key Sovereignty, Zero-Knowledge Infrastructure

BYOK Architecture · Customer Key Sovereignty · Zero-Knowledge Infrastructure

Tier-3 Datacenter · 2N Redundancy · 100% Renewable Energy (I-REC Committed)

All Verde Compute facilities are selected to meet or exceed Uptime Institute Tier-3 operational standards — concurrently maintainable, 2N fault-tolerant power and cooling, with zero single points of failure. 100% of facility energy will be sourced from renewable generation. I-REC certificates will be issued and retired on client behalf annually from first operational year.

Section C

Compliance Posture

Regulatory alignment and certification roadmap for enterprise and institutional procurement.

Framework Description Status
OFAC Compliance Real-time sanctions screening via API — all engagements subject to screening prior to execution Active
EAR / ITAR US export control compliance architecture for all technology transfers Active
NIST SP 800-88 Data erasure standard — applied at engagement conclusion with certificate issued Active
GDPR / CCPA / NY SHIELD 72-hour incident notification commitment aligned with applicable data protection law Active
SOC 2 Type II Annual independent security, availability, and confidentiality audit Planned — Year 1
ISO 27001 Information security management system certification — supports GDPR posture and EU enterprise procurement Planned — Year 1
SSAE 18 / AT-C 320 Financial controls audit — primary credential for lenders and insurance underwriters Planned — Year 1
EU AI Act Infrastructure architecture alignment — high-risk AI system deployment support Roadmap
NIST AI RMF AI Risk Management Framework alignment for US government and defense-adjacent clients Roadmap
ISO 42001 AI Management System standard — governance framework for AI operations Roadmap
Section D

Audit Access

Independent, multi-layer audit framework — accessible to clients, financiers, and insurers.

Layer 1 · Daily · Autonomous MSOC/MIM Monitoring

Datadog · CrowdStrike · Palo Alto Unit 42. Real-time SLA chronometer from first operational day. Telemetry logs available to clients.

Layer 2 · Monthly · Financial Review

Independent Fractional CFO audit. Dedicated Corporate Trust Officer. Monthly financial summary to all designated stakeholders.

Layer 3 · 6-Month · Cyber & Tax Audit

Tier-1 independent cyber audit (DNV · TÜV SÜD class). US-licensed CPA tax verification. SOC 2 Type II interim controls report.

Layer 4 · Annual · Institutional Audit

Big-4 / Top-10 balance sheet audit (PwC · EY · Deloitte · KPMG class). Independent hardware asset valuation. Solvency opinion and capital adequacy certificate. Full annual transparency report. Effective from first operational year.

Full Standards Detail

Complete audit methodology, vendor accountability framework, and engineering standards are documented on the Standards page.

Section E — Security Questionnaire

Security questionnaire
available under NDA.

Enterprise procurement teams may request Verde Compute's full security questionnaire as part of the NDA & Corporate Verification phase of engagement. Responses are provided in writing within 5 business days.

Or contact directly: [email protected]