Skip to content

Legal

Security Protocols for As-a-Service Delivery

iFrame Corporation · 101 Jefferson Dr, Menlo Park, CA 94025 · www.iframe.ai. This document is written to be shared with customers, partners, and prospects, and is binding on iFrame personnel. Sections 3 and 18 define the security responsibilities that iFrame allocates to customers and suppliers respectively. It describes the protocols by which iFrame secures the delivery of its GPU and AI compute platform as a service (“iFrame Services”).

Last updated · Version 1.0 · Prepared July 2, 2026

Document control

Document titleSecurity Protocols for As-a-Service Delivery
Version1.0
PreparedJuly 2, 2026
Effective dateDate of signature (see Section 21)
Document ownerChief Information Security Officer (CISO) / Head of Security, iFrame Corporation
ClassificationPublic — External-facing; binding on personnel and, where stated, on customers and suppliers
Next scheduled reviewAnnually, or upon material change in architecture, threat landscape, or regulation

1. Purpose and scope

iFrame Corporation (“iFrame”) operates a high-performance GPU and AI compute platform and delivers access to it as a service. This document sets out the security protocols that govern how iFrame designs, operates, and delivers iFrame Services, and the security commitments iFrame makes to its customers.

In scope: the physical facilities, hardware, network fabric, storage, virtualization and isolation layers, management plane, identity systems, and operational processes that iFrame uses to deliver iFrame Services; and the division of security responsibility between iFrame and its customers.

Out of scope:the security of customer workloads, data, code, models, credentials, and configurations that reside within the customer’s area of responsibility as defined in Section 3, and third-party services that customers elect to connect to iFrame Services.

This document should be read together with iFrame’s Trade Compliance Policy, Acceptable Use Policy, data protection and privacy notices, and the applicable customer agreement.

2. Security governance and framework

2.1 Program. iFrame maintains an information security program aligned to recognized industry frameworks, including the ISO/IEC 27001 information security management standard, the AICPA SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, and, where applicable, Processing Integrity and Privacy), the NIST Cybersecurity Framework, and the CIS Critical Security Controls. iFrame maps its controls to these frameworks and maintains documented policies, standards, and procedures beneath this document.

2.2 Ownership and accountability. The CISO / Head of Security owns this document and the security program, reports to executive management, and has the authority and resources to implement and enforce security controls, including the authority to halt a change or isolate a system in response to a security risk.

2.3 Risk management. iFrame maintains a risk-management process to identify, assess, treat, and monitor information security risks across the platform, and reviews risk on a scheduled basis and upon material change.

2.4 Certifications and attestations. iFrame pursues and maintains third-party certifications and attestations appropriate to its service and customer base. Current status and target dates are set out in Section 16.

3. Shared responsibility model

Security of iFrame Services is a shared responsibility. iFrame is responsible for the security of the platform — the facilities, hardware, network, storage, isolation layers, and management plane. The customer is responsible for security in the platform — the workloads, data, and access that the customer places on or through iFrame Services. Responsibility shifts depending on whether the customer consumes bare-metal or virtualized/managed offerings; the table below states the default allocation.

DomainiFrame responsibilityCustomer responsibility
Physical facility & environmentalData-center security, power, cooling, physical access
Hardware & firmwareServer, GPU, DPU, NIC, and switch hardware; firmware and BMC integrity; hardware supply-chain integrity
Network fabricFabric segmentation, tenant isolation, encryption in transit across the fabric, DDoS protection, perimeter controlsConfiguration of customer-controlled virtual networks, security groups, and application-layer firewalls (where offered)
Host / hypervisor (virtualized offerings)Hypervisor and host OS security, patching, isolationGuest OS hardening and patching within the customer instance
Bare-metal host (bare-metal offerings)Provisioning integrity, firmware, sanitization between tenantsGuest OS, all software above the metal, patching, and hardening
Compute / GPU isolationIsolation between tenants; GPU and memory sanitization on reprovisioningIsolation of processes within the customer's own allocation
StoragePhysical storage security, encryption at rest, media sanitization and disposal, platform-level key managementCustomer-managed encryption and key management (where the customer elects to bring or manage keys), data classification, in-workload data protection
Identity & accessSecurity of the control-plane IAM system, MFA enforcement for iFrame accounts, RBAC of the platformManagement of customer users, roles, keys, secrets, and MFA within the customer's account and workloads
DataProtection of data at the infrastructure layer; secure deletion on decommissioningContent, lawful basis, classification, backup of customer data, and in-application controls
Logging & monitoringPlatform, infrastructure, and control-plane logging and monitoringApplication- and workload-level logging within the customer environment
ComplianceInfrastructure certifications and attestationsCompliance of the customer's own use, data, and workloads

Where iFrame offers managed or higher-level services, iFrame assumes a correspondingly greater share of responsibility, as described in the applicable service documentation.

4. Physical and environmental security

4.1 Facilities. iFrame Services are delivered from purpose-built, access-controlled data-center environments. iFrame’s production environment is deployed in colocation space engineered for high-density AI compute, with hot- and cold-aisle containment, structured overhead cable management, and power and cooling provisioned for sustained high-density operation (production cages are engineered for multi-megawatt IT load at high per-cabinet density).

4.2 Physical access control. Access to data-center space is restricted to authorized personnel on a least-privilege, need-to-access basis, and is enforced through layered controls that include perimeter security, controlled entry, identity verification, and access logging. Physical access rights are reviewed periodically and revoked promptly on role change or departure.

4.3 Environmental controls. Facilities provide redundant power, cooling, and fire detection and suppression appropriate to high-density compute, with environmental monitoring. Power and thermal design supports the sustained load of dense GPU cabinets under containment.

4.4 Hardware supply-chain integrity. iFrame sources hardware through authorized channels and maintains provenance and integrity controls over its hardware supply chain, including receiving inspection and asset registration. iFrame prohibits counterfeit, diverted, or grey-market components (see Section 18), and validates firmware integrity before hardware enters production.

5. Infrastructure and host security

5.1 Platform. iFrame’s compute platform is built on hardened, enterprise-grade GPU servers — dense 8-GPU accelerator nodes — interconnected by a high-speed, low-latency fabric. Each node integrates high-performance network adapters and data-processing units (DPUs) that provide hardware-accelerated networking, storage, and security offload, including support for a hardware root of trust and isolation of infrastructure functions from tenant workloads.

5.2 Hardening. Hosts and infrastructure components are provisioned from controlled, hardened baselines. Unnecessary services and interfaces are disabled, secure configuration standards are applied, and configuration drift is monitored.

5.3 Firmware and BMC security. iFrame manages firmware and baseboard management controller (BMC) security as a first-class control: firmware is validated and kept current, management interfaces are placed on an isolated out-of-band network (Section 6.4), and secure/verified boot is used where supported to protect boot integrity and establish a hardware root of trust.

5.4 DPU-enforced isolation. Where the platform uses DPUs to offload and isolate networking, storage, and security functions, these functions are separated from the tenant-accessible compute domain, reducing the tenant’s ability to reach the infrastructure control path.

6. Network security and tenant isolation

iFrame operates physically and logically separated network fabrics, each dedicated to a distinct traffic class. This separation is a core isolation control.

6.1 GPU east–west fabric. GPU-to-GPU traffic (RDMA over Converged Ethernet) runs on a dedicated, physically separate high-speed fabric built on a multi-rail leaf/spine topology carrying GPU traffic only. Segregating GPU interconnect from north–south and management traffic limits the blast radius of any single fabric and supports tenant isolation of high-bandwidth workloads.

6.2 North–south fabric. Storage, in-band, and customer-facing traffic runs on a separate north–south fabric, with distinct leaf groups for storage (RDMA) and for in-band services, feeding an aggregation/spine layer and border and edge routers.

6.3 Perimeter and connectivity. Customer connectivity is delivered through controlled edge and border routing with support for redundant internet transit and private, dedicated interconnect (e.g., cloud direct-connect / private links) for customers who require private ingress rather than the public internet. Perimeter controls include filtering, DDoS mitigation posture, and segmentation between the edge, border, and internal fabrics.

6.4 Out-of-band management network. All infrastructure management — BMC/IPMI, switch management, and platform administration — runs on a dedicated out-of-band (OOB) management network that is isolated from tenant and customer traffic. Management-plane access is restricted, authenticated, and logged, and is not reachable from tenant workloads.

6.5 Tenant isolation. iFrame isolates tenants from one another through a combination of physical fabric separation, network segmentation (VLAN/VRF/overlay isolation), and, for virtualized offerings, hypervisor-enforced isolation. For bare-metal offerings, tenants receive dedicated hosts and are isolated at the physical and fabric layer. Customers do not share a memory or compute domain with other tenants within their allocated resources.

6.6 Encryption in transit. iFrame supports and, on customer-facing and inter-site paths, enforces encryption of data in transit using current, industry-standard protocols and cipher suites. Customers are responsible for enabling encryption within their own workloads and for any application-layer transport security they require.

6.7 DDoS and abuse protection. iFrame maintains protections against volumetric and protocol-based denial-of-service activity at the network edge, and monitors for abusive traffic patterns.

7. Compute and GPU lifecycle security

7.1 Provisioning integrity. Hosts and GPU nodes are provisioned from trusted images and validated baselines. iFrame verifies firmware and configuration integrity as part of bringing a node into service.

7.2 Sanitization between tenants. When a host or GPU resource is released by one tenant and prepared for another, iFrame performs reprovisioning that includes clearing of GPU and system memory and wiping or securely reprovisioning local storage, so that no residual tenant data or state persists into the next allocation. Bare-metal hosts are re-imaged and sanitized between customers.

7.3 Attestation. Where supported by the hardware, iFrame uses platform attestation to verify that a node is in a known-good state before it is returned to the allocatable pool.

7.4 Confidential computing (where offered). For workloads requiring hardware-enforced confidentiality, iFrame can make available confidential-computing capabilities that use hardware isolation to protect data and code in use. Availability depends on the specific offering and hardware; details are provided in the applicable service documentation.

8. Data security

8.1 Encryption at rest. Customer data stored on iFrame’s platform storage is protected by encryption at rest. iFrame’s primary storage platform employs self-encrypting drives and platform-level encryption, so that data at rest on the storage tier is encrypted by default.

8.2 Key management. iFrame manages encryption keys for platform-level encryption using controlled key-management practices, including protected key storage, access restriction, and rotation. Where an offering supports customer-managed keys (“bring your own key”), the customer controls the key lifecycle for its data as described in the applicable service documentation.

8.3 Data residency. iFrame Services are delivered from defined facility locations. iFrame will identify the region(s) in which a customer’s data is stored and processed, and will honor contractual data-residency commitments where offered.

8.4 Data deletion, sanitization, and media disposal. On termination of service or decommissioning of media, iFrame securely deletes customer data and sanitizes or destroys storage media in accordance with recognized media-sanitization guidance (e.g., NIST SP 800-88). Sanitization between tenants is addressed in Section 7.2.

8.5 Backups. iFrame protects the availability of its platform and management data through appropriate backup and redundancy. Backup of customer workload data is the customer’s responsibility unless a specific managed backup service is contracted.

9. Identity and access management

9.1 Control-plane IAM. Access to iFrame’s control plane and management systems is governed by centralized identity and access management enforcing strong authentication, multi-factor authentication (MFA), role-based access control (RBAC), and least privilege.

9.2 Privileged access. Administrative and privileged access is restricted to authorized personnel, granted on a need-to-use basis, separated from standard user access, and logged. iFrame applies just-in-time and/or approval-based elevation for sensitive operations where feasible, and reviews privileged access regularly.

9.3 Authentication and secrets. iFrame protects credentials and secrets used within its infrastructure, avoids shared accounts for administrative access, and rotates and revokes credentials on role change or departure.

9.4 Customer access. Customers manage their own users, roles, API keys, and secrets within their account and workloads, and are responsible for enforcing MFA and least privilege for their own users. iFrame provides the controls necessary for customers to do so; the correct configuration of those controls is the customer’s responsibility (Section 3).

10. Vulnerability and patch management

10.1 Scanning. iFrame performs regular vulnerability scanning of its infrastructure and platform components and tracks findings to remediation.

10.2 Patching. iFrame applies security patches and firmware updates to infrastructure it controls on a risk-prioritized schedule, with expedited handling of critical vulnerabilities. Patching of the guest operating system and software within a customer instance is the customer’s responsibility for bare-metal and IaaS offerings (Section 3).

10.3 Penetration testing. iFrame conducts periodic penetration testing of its platform, using qualified internal or independent testers, and remediates validated findings.

10.4 Secure development and change management. Changes to production are made through a controlled change-management process with review, testing, and rollback planning. Software developed by iFrame follows secure-development practices.

11. Logging, monitoring, and audit

11.1 Logging. iFrame centrally logs security-relevant events across its infrastructure, control plane, and management network, and protects log integrity.

11.2 Monitoring and detection. iFrame monitors its environment for security-relevant conditions and anomalies and maintains detection capabilities feeding its incident-response process.

11.3 Retention and audit. Logs are retained for a defined period appropriate to iFrame’s operational and compliance needs and are available to support investigation and audit. Customers are responsible for logging within their own workloads.

12. Incident response and breach notification

12.1 Incident-response process. iFrame maintains a documented incident-response plan covering preparation, detection and analysis, containment, eradication, recovery, and post-incident review, with defined roles and escalation paths.

12.2 Containment capabilities. iFrame can isolate affected hosts, fabric segments, or management paths to contain an incident, leveraging the physical and logical separation described in Section 6.

12.3 Notification. iFrame notifies affected customers of security incidents involving their data or workloads without undue delay, consistent with its contractual commitments and applicable law, and provides information reasonably necessary for the customer to meet its own obligations. Specific notification timeframes are set out in the applicable customer agreement or data-processing terms.

12.4 Cooperation. iFrame cooperates with affected customers and, where required, with regulators and law enforcement, in the investigation and remediation of incidents.

13. Business continuity and disaster recovery

iFrame maintains business-continuity and disaster-recovery arrangements appropriate to the service, including redundancy in power, cooling, network, and critical management infrastructure, and documented recovery procedures. Recovery objectives (RTO/RPO) applicable to a given offering are stated in the applicable service documentation or agreement. Customers are responsible for architecting their own workloads for the resilience they require and for backing up their own data (Section 8.5).

14. Personnel and operational security

14.1 Screening. iFrame conducts background screening of personnel with access to production systems and sensitive data, to the extent permitted by applicable law.

14.2 Training and awareness. iFrame requires security awareness training at onboarding and periodically thereafter, with role-based training for personnel in security-sensitive functions.

14.3 Insider-threat and access hygiene. iFrame applies least privilege, separation of duties for sensitive operations, prompt deprovisioning on departure or role change, and monitoring of privileged activity to manage insider risk.

14.4 Acceptable use and confidentiality. Personnel are bound by acceptable-use and confidentiality obligations governing their handling of iFrame and customer information.

15. Data-center and hardware decommissioning

When hardware or media is retired, iFrame follows a controlled decommissioning process that includes secure data erasure and media sanitization or destruction (Section 8.4), removal from asset inventory, and disposal through authorized channels. Media that cannot be sanitized to standard is destroyed.

16. Compliance, certifications, and attestations

iFrame aligns its controls to leading frameworks (Section 2.1) and pursues third-party validation appropriate to its customers. The following reflects iFrame’s certification roadmap; status and dates are to be maintained by iFrame and confirmed to customers on request:

Framework / attestationScopeStatus
SOC 2 Type IISecurity (and applicable Trust Services Criteria) for iFrame ServicesIn progress — target: ______
ISO/IEC 27001Information security management systemIn progress — target: ______
ISO/IEC 27017 / 27018Cloud security / cloud privacy controlsPlanned — target: ______
PCI DSSIf in scope for the customer baseAs applicable
HIPAAIf handling protected health informationAs applicable
Other (e.g., FedRAMP, sector-specific)As driven by customer requirementsAssess as needed

iFrame makes current attestation reports and certificates available to customers under appropriate confidentiality terms.

Note on completion.As a matter of accuracy, certification claims must reflect iFrame’s actual, current status. iFrame should not represent a certification as held until it has been awarded, and should update this table as milestones are achieved.

17. Interaction with trade compliance

The technical access, isolation, geolocation, and logging controls described in this document also support iFrame’s Trade Compliance Policy — for example, by restricting access from prohibited destinations, controlling access to controlled technology, and maintaining records. Where trade-compliance requirements impose more restrictive controls on access to iFrame Services, those requirements govern. See the iFrame Trade Compliance Policy.

18. Supplier and supply-chain security

Suppliers of hardware, software, and services that form part of iFrame Services are subject to security requirements, including: lawful and authorized sourcing; hardware provenance and integrity (no counterfeit, diverted, or grey-market components); firmware integrity; adherence to iFrame’s security and confidentiality requirements; timely notification of vulnerabilities and incidents affecting supplied products or services; and flow-down of equivalent obligations to their own subcontractors. iFrame assesses material suppliers commensurate with the risk they present and reserves the right to audit compliance with these requirements.

19. Customer security responsibilities (summary)

Consistent with Section 3, customers are responsible for: securing their workloads, data, code, and models; managing their users, roles, keys, secrets, and MFA; hardening and patching guest operating systems and software (for bare-metal and IaaS offerings); classifying and lawfully handling their data; backing up their own data; configuring any customer-controlled network and access controls correctly; and using iFrame Services in accordance with iFrame’s Acceptable Use Policy and Trade Compliance Policy. iFrame provides the controls and information necessary for customers to meet these responsibilities.

20. Governance, review, and disclaimer

20.1 Review. The CISO / Head of Security reviews this document at least annually, and upon material change in iFrame’s architecture, the threat landscape, or applicable regulation, and updates it as needed. Executive management approves material changes.

20.2 Availability. iFrame publishes an external-facing version of this document at www.iframe.ai and makes further detail available to customers under appropriate confidentiality terms.

20.3 Disclaimer and completion. This document describes iFrame’s security protocols and commitments and is provided for information; specific contractual security commitments are those set out in the applicable customer agreement and data-processing terms, which govern in the event of conflict. Before publication, iFrame should confirm that every control and certification statement herein accurately reflects its as-built environment and current status, and complete the bracketed items in Section 16. Descriptions of the technical architecture in this document reflect iFrame’s production platform design and should be kept current as the platform evolves.

21. Approval and signature

Adopted and approved on behalf of iFrame Corporation:

______________________________________

Vladyslav Panin
Chief Executive Officer
iFrame Corporation

Date: ____________________

iFrame Corporation · 101 Jefferson Dr, Menlo Park, CA 94025 · www.iframe.ai
Security Protocols for As-a-Service Delivery · Version 1.0

Legal inquiries: security@iframe.ai