Security
Our security posture, stated plainly.
We describe how PrivateRack is built and operated, precisely and without absolutes. This page lists the practices we follow. It does not make compliance claims or promise that any system is impossible to compromise.
How we talk about security.
No system is impossible to hack, and we will not tell you otherwise. What we can do is describe the practices we follow and the way the system is designed, so you can evaluate them on their merits.
Practices, not certifications
The list below describes practices we implement. It is not a claim of certification or regulatory compliance. If your business has specific compliance requirements, raise them during the assessment and we will tell you honestly what we can and cannot support.
Security practices
What we implement.
Local processing
Supported workloads run on your hardware, and policy can restrict selected data and workloads from external AI services.
Encryption
Data is encrypted in transit and at rest, including off-site backup copies.
Multi-factor authentication
MFA on access to the system, so a password alone is not enough.
Role-based access
Permissions so people reach only the systems and information they are allowed to.
Device certificates
Certificate-based authentication for devices, not just shared secrets.
Minimal exposed services
A small attack surface: only the services that need to be reachable are.
Audit logging
Records of access and administrative actions for review.
Backup validation
Backups are checked, because a backup you cannot restore is not a backup.
Secure remote management
The rack is managed remotely over authenticated, encrypted channels.
Control-plane separation
We manage the rack without holding your documents.
PrivateRack manages the appliance through a separate control plane. In plain English, that means we can monitor, update, and administer the hardware and software without needing possession of your business documents.
Control plane
Data plane
Request a private AI infrastructure assessment.
We review your data, storage, workloads, and security needs, then size a deployment to your business.