Processing...

 Our Datacentre Security

Closed Secure Environments, Inside and Out

Our two subterranean datacentres are run as closed secure environments. They hold our own data and that of our customers, they house our HelpDesk teams, and they host our AI infrastructure. Everything in them is built on a single principle: the default answer to "can data leave here?" is no, and every exception is deliberate, documented and technically enforced. What follows is a description of how our own facilities actually operate, not a specification we sell to others. The general model is set out in What is a Secure Environment.


What is Here, and What is Deliberately Not

The most important security decision we have taken is about what we refuse to put in the building. Only three functions operate inside the secure environment:

  • Data: virtualisation, cloud storage, backups and data lakes, ours and our customers'.
  • HelpDesk: the same engineering teams that build and run the datacentres are the teams that support our customers. There is no separate support department reading from a script, and no layer between the people who answer and the people who know.
  • AI: our GPU clusters, models, training data and inference workloads.

Everything else is somewhere else. GENSoftware development, Administration, Finance, Sales, Marketing, Web design and Social all operate from separate sites, on separate infrastructure, with no route into the secure environment.


This is not an accident of history, it is the design. Those functions need the things a secure environment cannot tolerate: the open Internet, external email, telephones, social platforms, supplier portals, marketing tools, video calls with prospects, and software downloaded from the wider world. Housing them alongside the data would mean punching a hole through every control on this page, and the hole would then exist for everybody. Sales do not need access to customer data to sell, Finance does not need it to raise an invoice, and Marketing certainly does not need it. So they do not have it, and they are not in the building.


The consequence is a very small population inside the secure zone, doing a narrow set of things, with no business reason for a general connection to the outside world. That is what makes the rest of the controls affordable and enforceable rather than aspirational.


The Buildings

  • Subterranean: both facilities are below ground, which removes the entire category of attacks that begin with a window, a wall or a vehicle.
  • Undisclosed locations: we do not publish where they are. Address details are given only to the people and carriers who genuinely require them.
  • No visitors: not escorted, not by appointment, not for tours. Our datacentres are not customer facing and nobody outside the operational teams goes in. A control with an exceptions process is an exceptions process.
  • Electromagnetically shielded: the facilities are screened against EM radiation including solar events, air burst weaponry and NEMP. The same screening substantially frustrates both radio exfiltration and passive emission capture.
  • Independent power: 100% green grid supply, rooftop solar, and the ability to run on backup power for extended periods. Availability is a security property, not merely an operational one.
  • Disparate interconnectivity: the two sites take diverse routes from different carriers, so no single physical path carries our traffic and no single cut isolates a site.

Getting In

  • Zoned: the site is divided into distinct zones, and clearance for one confers nothing on the next. Access to the halls is separate again from access to the operational floor.
  • Facial recognition and biometrics: entry is granted on biometric identity, facial recognition combined with a second biometric factor. Templates are irreversible, held on site, and never in a vendor cloud.
  • Interlocked airlocks: single-occupancy vestibules. One person identified, one person through, outer door closed before the inner door releases, so tailgating is not physically possible.
  • Anti-passback: a credential that has entered cannot enter again until it has properly exited, which ends credential sharing at the door.
  • CCTV held locally: full coverage of approaches, boundaries and circulation, recorded to storage inside the facility, retained under policy and never streamed to a third party platform.
  • Monitored detection: intruder detection to a grading appropriate to the risk, with tamper detection on every device, cabinet and cable route.
  • No contractors, and no cleaners: we employ nobody to come in and do a job. Our own staff are trained to service the hardware, the power distribution, the generators and the solar arrays, for this reason alone. It is an expensive way to change a filter, and it means the list of people who have ever been inside is the list of people who work here.

No Personal Devices, and the Right to Search

The most capable exfiltration device ever built is the modern smartphone: camera, microphone, encrypted storage, an independent radio path out, and a screen its owner is entitled to look at. No amount of network engineering compensates for allowing one inside.

  • Prohibited absolutely: phones, tablets, laptops, smart watches, fitness trackers, wireless earbuds, e-readers, cameras, voice recorders and removable media, personal or company issued alike.
  • Lockers at the boundary: personal items go into individual lockers, RF screened, before the biometric threshold. They are collected on the way out.
  • Search on entry and exit: person, bags and outer clothing, at will and without notice, on the way in and on the way out.
  • Applied to everyone: directors, engineers and HelpDesk staff equally. Exemption by seniority defeats the control entirely, so there is none.
  • Agreed in advance: the search regime is a written condition of working here, accepted before access is granted, so it is never a negotiation at the door. Searches are conducted respectfully, by trained staff, and logged.

Hardware Tokens, Held on Site

Every member of staff is issued a hardware security token, and it is mandatory. Nothing can be logged into without one. There is no password only route, no fallback and no emergency bypass, because a bypass that exists is a bypass that will eventually be used.

  • The token is site property and never leaves the building. It is not taken home, on leave, or between sites.
  • Security holds the tokens and issues each one to its named owner on arrival, after biometric identification, as part of the same boundary process that takes their personal devices into a locker.
  • It is handed back and checked in before the individual leaves. A token not returned is an incident immediately, not at the end of the shift.
  • Tokens are bound to one person, never pooled or shared, and the issue and return log makes any handover visible.
  • The issue and return record is reconciled against the physical access log daily, and a lost or withdrawn token is deregistered centrally at once, whether or not the device is recovered.

The credential and the person are only ever brought together inside the facility, under supervision. A token held on site cannot be stolen from a bag on a train, used from a home network, or quietly borrowed at the weekend.


The Network

  • Stateful firewalling at every boundary: not merely at the perimeter. Each zone boundary and each inter-site link is policed with an explicit allow list, default deny inbound and, critically, default deny outbound.
  • No direct Internet access: no workstation inside the environment has a route to the public Internet. Where an external resource is genuinely needed it is fetched through an inspected, allow-listed proxy into a holding area, and the request is attributable to a person.
  • Egress is the real control: most organisations spend everything on keeping attackers out and leave the door open on the way back. We treat outbound traffic as the primary risk and restrict, log and alert on it accordingly.
  • Cloud messaging and transfer blocked outright: consumer and corporate messaging platforms, webmail, file sync, paste sites, screen sharing and third party remote support tools are blocked by destination, protocol and DNS. Anything capable of moving a byte out is treated as an exfiltration channel, because that is what it is.
  • Internal DNS only: external resolvers, DNS over HTTPS and DNS over TLS to third parties are blocked. An encrypted resolver is a tunnel with a respectable name.
  • Closed WireGuard mesh: the two datacentres, our Service Hubs and authorised customer endpoints are joined by a private mesh with fixed keys, no public entry point and no route out to the open Internet.
  • The mesh is policy based, not merely encrypted: membership is not permission. Every endpoint carries an explicit list of what it may talk to, and in which direction, so a peer that is allowed to receive a connection is not thereby allowed to make one. Posture is checked before an endpoint is admitted, and an endpoint that fails to present the expected state does not join, regardless of whether it holds a valid key.
  • No wireless in the secure zone: wired only, with port security and physical control of patching.
  • Removable storage disabled: USB mass storage and other removable device classes are disabled in the operating system and, where warranted, physically.
  • Cloud services are segmented and separate: the customer facing platform, virtualisation, cloud storage and the services running on it, has its own route to the Internet because it must. That segment cannot bridge onto our internal networks, and our internal networks cannot reach into it. The two are joined by nothing, so a compromise of a hosted workload has nowhere to go, and a foothold inside has no path out through the cloud platform.

Linux Everywhere, Microsoft Nowhere

Every system in our datacentres runs Linux: servers, workstations, firewalls, hypervisors, storage, telephony, GPU nodes and appliances. There is no Microsoft software anywhere in the secure estate. No Windows, no Active Directory, no Exchange, no Microsoft 365, no Teams, no OneDrive, no Entra.


Microsoft is a threat in its very name. No other vendor has a comparable record: decades of critical vulnerabilities, a monthly patch cycle that has run for a quarter of a century without ever arriving at a secure product, and an architecture so porous that the fixes routinely introduce the next set of holes. It has been described as trying to patch a fishing net with sugar cubes, and the description is fair. The problem is not carelessness with individual bugs, it is that the underlying design is inherently weak, and no volume of patching changes what is underneath.


Then there is single sign-on, sold as convenience and delivered as a single point of catastrophic failure. One identity unlocks the mail, the files, the finance system, the customer records and the administrative console, so when that identity is taken, and it is taken constantly, the attacker inherits the entire company in one step. Companies have lost their livelihoods to precisely this, with the architecture working exactly as designed while it happened. We do the opposite: identity is compartmented, access is granted per system, and no single credential opens everything.


Linux gives us what the environment requires: source that can be inspected, builds we control, machines that do nothing we have not asked for, no dependence on a vendor's cloud for identity or licensing, and stability without forced change. Systems are deployed from hardened standard images, users hold no local administrative rights, and machines are rebuilt rather than repaired.


Workstations With No Disk

There is not a single hard disk in a workstation anywhere in the secure environment. Every machine on the operational floor network boots from a central server and runs entirely in RAM. There is no local storage to write to, no persistent profile, and nowhere for anything to be kept.


Switch a workstation off and back on and it returns to the standard image, exactly as it was built. That is not a limitation we tolerate, it is the point of the design. Nothing accumulates on a desk machine, nothing survives on one, and nothing can be quietly stored on one. Malware that reaches a workstation has a lifespan measured by the next reboot, a machine cannot drift away from its build over time, and a workstation removed from the building is an empty box. It also means recovery from any doubt about a machine is a power cycle rather than an investigation.


A Curated and Limited Toolset

Nobody installs software. There is no application store, no download and no "just this once". The environment carries a deliberately small catalogue, each application assessed, packaged, version-pinned and allow-listed by name and cryptographic signature. Anything not on the list will not execute, including anything a user manages to write into their own home directory. Every candidate is assessed for what it can reach: whether it phones home, whether it syncs, whether it has a cloud tier, whether it embeds a browser, whether it can open a socket to a destination of its own choosing. Updates are staged, tested and deployed from internal repositories, so no machine ever reaches out to a vendor for a package.


How the HelpDesk Talks to You

Support is the obvious tension in a closed environment: the engineers who run the datacentres sit inside it, and those same engineers answer our customers all day. The answer is that they communicate through the boundary rather than across it, on channels we operate ourselves.

  • No email inside: there are no mailboxes in the secure environment. Customer correspondence is received, filtered and rendered at the boundary, and presented to engineers as tickets in the internal system.
  • No telephones inside: no mobiles, and no external telephony on the operational floor. Calls terminate at the boundary and are carried to the engineer over the mesh using SIP-TLS and SRTP.
  • Matrix for internal messaging: all internal messaging runs on our own Matrix homeserver inside the environment, end to end encrypted, federation disabled and no bridges to outside networks.
  • Internal web systems for everything else: ticketing, documentation, monitoring, change records, approvals and reporting are internal web applications served over the mesh, with role based access and full audit trails.
  • Remote support over the mesh: wherever a customer is on the mesh, which is the usual case, engineers reach their systems directly through it and no third party is involved at any point.
  • One chosen tool where the mesh does not reach: for ad-hoc support of machines outside the mesh we use Splashtop SOS, and only Splashtop SOS. It was selected on the vendor's security record, its encryption, and the fact that it offers genuine open source Linux clients, which means we can see what runs on our own machines. Sessions are attended, initiated by the customer, and end when the session ends.
  • Files stay put: documents live in the internal systems and are referenced rather than sent. There is no copy of a customer file circulating in a mailbox, because there are no mailboxes.

The transport itself is described in GENuinely Secure Communications.


Your Data, and Our AI

Customer data stays in our datacentres. It is not replicated to a public cloud, not backed up to a third party service, and not processed by anybody else's platform on its way to anywhere. Backups are taken within the environment, encrypted, and replicated offsite to our other datacentre over the mesh, so a site level loss is survivable without a single byte ever being handed to an outside party. Recovery never depends on anybody else holding either the data or the keys.


Our AI runs on our own GPU clusters in the same facilities, and that is a deliberate and expensive choice. The convenient alternative is to call somebody else's model over the Internet, which means the prompt, the context and whatever customer material went into it all leave the building and land on infrastructure we do not control, under terms that can change. We do not do that. Models are hosted, run and updated internally, inference happens inside the secure environment, and the data used to support it never crosses the boundary. An AI service is only as private as the network path underneath it, and ours does not have one.


People

  • Screened: identity, right to work, employment history, financial probity and criminal record checks, at a depth proportionate to the access held, and repeated periodically rather than once at hire.
  • Least privilege: access is granted to the specific systems a role requires and nothing else. Administrative rights are held on separate accounts from day to day work, and blanket access does not exist.
  • Joiners, movers and leavers: access is provisioned, changed and revoked as one controlled process, so a change of role removes the old access as well as granting the new.
  • Immediate revocation: departure removes credentials, biometric enrolment and mesh keys the same day, and those keys are treated as compromised rather than reissued.
  • Obligations that outlive employment: confidentiality continues after the engagement ends, and staff know the material they handle belongs to customers with contractual and statutory remedies.

Watching Ourselves

Controls that are not observed are assumptions. Everything of consequence is logged inside the environment, correlated, and reviewed by people who know what normal looks like here.

  • Physical access events, biometric decisions, search records and token issue and return are all logged and reconcilable against one another.
  • Authentication, privilege use, data access, transfer requests and print jobs are recorded centrally on write-once storage held within the environment.
  • Behaviour is judged by pattern rather than single event: access at unusual hours, volumes out of keeping with a role, or activity that does not fit the person concerned. Geofencing and pattern analysis catch what a credential check never will.
  • Configuration is managed as code and reviewed before deployment, so drift is detected rather than discovered.
  • We test ourselves: penetration testing of the logical estate, and physical assessment including attempted tailgating, social engineering and unescorted access.

Why We Bother

Because our customers demand it. That is the honest answer, and it is not a marketing position we adopted and then went looking for buyers of. Not everybody hosting with us is running a virtualised web server for an online retail business, where the worst case is an afternoon of downtime. A great many are doing something else entirely: holding a data lake of material they could never place in a public cloud, running AI compute over information that must not leave the country let alone the company, or operating genuinely private cloud and hybrid cloud services where the whole point of the arrangement is that nobody else is in the path.


Those customers ask hard questions before they sign, and they ask them again afterwards. Who can walk into the room where this runs. What can that person carry out with them. Where does the backup go. Whose model processes it. Which third party has a route in, and who audits that. An organisation that has to answer "we are not sure" to any of those has already failed the assessment. We built the environment so that we can answer all of them, specifically, and evidence the answer.


None of it is convenient. It is slower to work in, it constrains how our own people communicate, and it removes tools they are used to at home. We say so plainly rather than pretend otherwise. What it buys is a position we can actually defend: we can state, and demonstrate, exactly what routes exist for a piece of customer information to leave our datacentres, and account for every one of them. Very few organisations that hold your data can say the same.


Not every business needs all of this, and we would say so rather than sell it. But the principles apply to everybody: know what you hold, know every route by which it could leave, close the ones you do not need, and watch the ones you do. What does not work is the half-way house. You are either security aware or you are not, because security is decided by the weakest route left open, not the strongest one you have closed. Controls applied only when convenient are not controls, they are preferences, and an attacker only has to find the day they were inconvenient.

Contact Us