Physical security, data handling commitments, compliance posture, and audit access — documented here for technical and legal review.
BYOK · Hardware Enclave · Zero Knowledge
Every client deployment occupies a physically isolated, locked cage. Zero physical sharing with any other client under any circumstance.
All physical access to client cage requires three-factor biometric authentication. Access logs are immutable and available for client audit.
Continuous 4K and thermal imaging surveillance across all facility areas. Footage retained per contractual and compliance requirements.
Available for defense and classified deployments. Electromagnetic emanation controls per TEMPEST standards upon client specification.
Trained facility personnel available on-site around the clock. All Smart Hands access is logged, authenticated, and auditable.
"Your data never leaves your cage."
"Your data never trains anything."
Hardware-level and network-level isolation ensures no path exists between client environments. Architectural guarantee, not policy-based.
All client data is securely erased per NIST SP 800-88 guidelines at engagement conclusion. A certificate of data destruction is issued to the client.
In the event of a confirmed security incident, client notification within 72 hours of discovery — aligned with GDPR, CCPA, and NY SHIELD Act requirements.
Verde Compute retains no client data, model weights, or workload artifacts following engagement conclusion. No backup exceptions.
Every engineer assigned to your deployment completes identity verification and professional history validation before engagement access is granted.
All client payments are held in a Tripartite Debt Service Escrow managed by an independent, licensed corporate trustee — not Verde Compute directly. Funds are disbursed to Verde Compute, the financing lender, and reserve accounts on a pre-agreed schedule. Clients and lenders have direct, real-time visibility into escrow balances and payment flow at all times.
The identity of the appointed independent trustee institution (institutional-grade US corporate trustee) is disclosed to qualified clients under NDA during the engagement process.
Customers hold sole possession of their hardware encryption keys. Verde Compute engineers have zero access to decrypted workload data, model weights, or training artifacts at any time. Keys are provisioned by the client prior to first operational day and are never stored, copied, or accessible by Verde Compute personnel or infrastructure systems.
All Verde Compute facilities are selected to meet or exceed Uptime Institute Tier-3 operational standards — concurrently maintainable, 2N fault-tolerant power and cooling, with zero single points of failure. 100% of facility energy will be sourced from renewable generation. I-REC certificates will be issued and retired on client behalf annually from first operational year.
| Framework | Description | Status |
|---|---|---|
| OFAC Compliance | Real-time sanctions screening via API — all engagements subject to screening prior to execution | Active |
| EAR / ITAR | US export control compliance architecture for all technology transfers | Active |
| NIST SP 800-88 | Data erasure standard — applied at engagement conclusion with certificate issued | Active |
| GDPR / CCPA / NY SHIELD | 72-hour incident notification commitment aligned with applicable data protection law | Active |
| SOC 2 Type II | Annual independent security, availability, and confidentiality audit | Planned — Year 1 |
| ISO 27001 | Information security management system certification — supports GDPR posture and EU enterprise procurement | Planned — Year 1 |
| SSAE 18 / AT-C 320 | Financial controls audit — primary credential for lenders and insurance underwriters | Planned — Year 1 |
| EU AI Act | Infrastructure architecture alignment — high-risk AI system deployment support | Roadmap |
| NIST AI RMF | AI Risk Management Framework alignment for US government and defense-adjacent clients | Roadmap |
| ISO 42001 | AI Management System standard — governance framework for AI operations | Roadmap |
Datadog · CrowdStrike · Palo Alto Unit 42. Real-time SLA chronometer from first operational day. Telemetry logs available to clients.
Independent Fractional CFO audit. Dedicated Corporate Trust Officer. Monthly financial summary to all designated stakeholders.
Tier-1 independent cyber audit (DNV · TÜV SÜD class). US-licensed CPA tax verification. SOC 2 Type II interim controls report.
Big-4 / Top-10 balance sheet audit (PwC · EY · Deloitte · KPMG class). Independent hardware asset valuation. Solvency opinion and capital adequacy certificate. Full annual transparency report. Effective from first operational year.
Complete audit methodology, vendor accountability framework, and engineering standards are documented on the Standards page.
Enterprise procurement teams may request Verde Compute's full security questionnaire as part of the NDA & Corporate Verification phase of engagement. Responses are provided in writing within 5 business days.
Or contact directly: [email protected]