Five interlocking frameworks — engineering, legal, insurance, vendor accountability, and audit — that together form the institutional trust architecture of Verde Compute.
Hardware is a commodity. The team operating it is not. These standards govern every engineer on every Verde Compute deployment.
L1 and L2 engineers do not work on Verde Compute infrastructure — under any circumstance. Every team includes L3 engineers capable of autonomous root-cause analysis without escalation, and L4 leads for system design and complex problem resolution. AI Architecture leads are assigned to every client deployment.
Theoretical knowledge is insufficient. Every engineer is required to hold a current, valid NVIDIA certification — not a credential from a prior generation — as a condition of deployment assignment. Verde Compute is designed to maintain direct access to NVIDIA Core Engineering support channels for all active client deployments, per engagement.
The conventional approach — a shared pool serving multiple clients — is incompatible with the level of focus institutional workloads require. Verde Compute operates exclusively on the dedicated model.
No hardware below the Blackwell generation is deployed — for any client, at any price point. Every pod completes a minimum 72-hour factory burn-in validation, required to be independently certified by a qualified third party. A certificate of validation is to be provided to the client prior to go-live.
Verde Compute does not operate from facilities below this standard:
| Criterion | Verde Compute Standard |
|---|---|
| Client SLA | 99.9% client-facing managed service (≤8.76 hrs/year) · Emergency Cloud Compute automated failover · activation timeline committed per engagement MSA |
| Infra Uptime | 99.999% DC power & cooling SLA (≤52 min/year) · contractual DC obligation with SLA credit tiers |
| Maintenance | Concurrently maintainable · 72-hour advance notice for maintenance windows |
| Redundancy | 2N dedicated power path + cooling |
| Fault Tolerance | Single failure cannot cause downtime |
| SLA Breach | Financial compensation — not service credits |
Verde Compute's legal framework is designed around the requirements of institutional procurement, banking-grade compliance, and multi-jurisdictional operations — to be executed with qualified US corporate technology counsel, engaged prior to first client commitment.
Each Verde Compute client engagement is established as a legally independent Special Purpose Vehicle under the Verde Compute brand — ensuring complete isolation of assets, liabilities, and contractual obligations between engagements. No client's financial or operational exposure is connected to any other.
All engagements are structured under Delaware law, executed with specialized US corporate technology and institutional financing counsel. Jurisdiction is established in advance and never ambiguous.
All engagements are subject to OFAC sanctions compliance screening prior to initiation. EAR / ITAR export control architecture governs all technology transfers. Compliance review is conducted at engagement stage.
All engagements are governed by AAA (American Arbitration Association) Commercial Arbitration Rules, administered under Delaware jurisdiction. The arbitration framework is structured for efficient resolution without defaulting to courts. Seat, timeline, and arbitrator selection criteria are pre-agreed at contract signing.
Verde's insurance framework encompasses 20 policy layers — covering hardware, business interruption (full-term BI coverage), force majeure, cyber-physical events, delay in start-up (DSU), contingent BI, employment practices, trade credit, and engagement-sized surety bonds. Clients are named Additional Insured on Cyber Liability, CGL, and Property layers — giving direct insurance rights. Policy terms, carrier details, and coverage limits are confirmed at engagement execution and documented in the applicable MSA. Key policies documented below; full schedule available under NDA. See Protection → for the complete 20-policy breakdown.
Targeted coverage for revenue loss from project-start delays. 24-hour waiting period design. Financier-named beneficiary structure. Policy structured at engagement.
Targeted coverage for geopolitical disruptions and export restriction events. Multi-jurisdictional coverage design. Terms confirmed at engagement.
Engineering error liability framework — designed with contractual recourse to vendor. Client-facing coverage structured independently of vendor response timelines.
Business continuity design for loss of key personnel. Succession protocol pre-defined in engagement agreement. Policy confirmed at operational launch.
Zero-wait hardware replacement in the event of GPU hardware failure. Spare parts on-site via consignment depot.
Credit guarantee structure available — terms and structure disclosed under NDA at engagement stage.
Mission-critical facility operator disruption coverage. Coordinated with operator SLA enforcement.
Data exfiltration and ransomware event coverage. 72-hour client notification commitment.
Financier-named client receivables policy. Structured as a senior credit enhancement instrument.
Government-action disruption coverage. Relevant for sovereign AI and defense-adjacent deployments.
Our commitments to you are backed by contractual obligations from every vendor in our supply chain. The accountability chain extends to every partner.
Verde Compute provides periodic independent audit reports to all authorized counterparties. Transparency is a contractual commitment, not a marketing claim.
Verde's compliance architecture covers the full spectrum of institutional client requirements — financial services, healthcare, government, and defense. All four frameworks are structured as integrated operational systems — activated at first client engagement.
Verde's primary certification. SOC 2 Type II is a universal requirement for Verde's institutional client base — no engagement can proceed to go-live without it. Observation period begins at Commercial Go-Live (Q1 2027); Type II report issued Q3 2027. All five Trust Services Criteria in scope — Security (CC1–CC9), Availability (A1), Processing Integrity (PI), Confidentiality (C1), and Privacy (P). Type I issued Q1 2027 for early-stage client procurement requirements. Big 4 auditor selected via competitive RFP.
Verde functions as a Business Associate under HIPAA — providing compute infrastructure that may process Protected Health Information on behalf of healthcare clients. HIPAA compliance is activated at first healthcare client onboarding: Business Associate Agreement (BAA) executed, Annual HIPAA Security Risk Assessment (SRA) conducted, HIPAA-specific training for client-facing staff completed. Verde's SOC 2 Technical Safeguards substantially satisfy HIPAA technical requirements — CC6 (access controls), CC7 (monitoring), CC9 (incident response). HIPAA Breach Notification: Verde notifies client within 2 hours of incident confirmation (contractual P1 SLA). Client notifies HHS within 60 days per statute.
NVIDIA Blackwell-class compute systems and NVIDIA AI Enterprise software are subject to US Export Administration Regulations. Verde's export control posture: (i) ECCN classification confirmed by outside counsel for all hardware SKUs; (ii) End-User Certificate signed by each client at contract execution — certifying no prohibited end-use, no re-export without authorization, no foreign government transfer; (iii) Denied Party Screening — client entity and all beneficial owners ≥25% screened against OFAC SDN, BIS Entity List, BIS Denied Persons List, and DDTC Debarred Parties List before contract signing and annually thereafter; (iv) Technology Control Plan (TCP) documenting access control for controlled technology. All Verde hardware remains on US soil. Verde operates 100% US jurisdiction in Phase 1.
Verde adopts NIST CSF 2.0 as its internal cybersecurity governance standard — de facto requirement for US government and defense clients, and the most recognized framework for institutional procurement. CSF 2.0's six functions implemented: Govern (GV) — board-level cybersecurity policy, CISO reporting line, lender covenant reporting; Identify (ID) — full asset inventory, annual risk assessment; Protect (PR) — MFA/RBAC/PAM, AES-256 encryption, annual security training (engagement NOC team); Detect (DE) — SIEM real-time alerting, NVIDIA DCGM GPU anomaly detection, monthly vulnerability scans; Respond (RS) — IRP P1–P4 classification, 2-hour P1 client notification, semi-annual tabletop exercises; Recover (RC) — BCP/DR plan, annual DR drill, Emergency Cloud Compute activation. NIST SP 800-53 readiness and CMMC Level 2 are Phase 2 extensions for government/defense clients.
Full technical and legal documentation available post-NDA. No commitment required until MSA is signed.