The accredited boundary, delivered to the site.
Transportable data centers that carry the same control baseline, the same attestation path, and the same telemetry as our fixed facilities. Built for forward sites, disaster response, and programs whose network goes dark for days at a time.
Three reasons the workload cannot wait for the link
Deployable infrastructure is not a smaller version of the platform. It exists because some workloads are created in places where the network is the least reliable thing on site.
Three form factors, one baseline
Every configuration runs the same image, the same attestation path, and the same telemetry agents as a host in one of the twelve facilities. What changes is how much of it fits in the container and how it gets there.
Two-person lift
One sealed host in a shock-mounted transit case, with local storage and the full attestation path intact. It checks as baggage, runs off a wall outlet or a field generator, and gives a small team an enclave that does not depend on a link home. Sized for assessment teams, exercise support, and program pilots.
- Compute
- 1 host, up to 32 cores
- Storage
- Up to 30.72TB NVMe
- Power
- 700W, 100 to 240V
- Transport
- Checked baggage or vehicle
Palletized
Eight rack units of shock-mounted compute with its own switching, power conditioning, and out-of-band management, in a frame rated for air and vehicle movement. Sized for a command post, a mobile operations center, or a program office that needs more than one node and less than a facility.
- Compute
- Up to 4 hosts, 128 cores
- Storage
- Up to 123TB NVMe
- Power
- 3.5kW, single or dual feed
- Transport
- 463L pallet or vehicle
Self-contained
A sealed site in a container: compute, storage, switching, power conditioning, and cooling, with a generator tie-in and an intrusion-monitored shell. It lands on a pad, takes shore power or fuel, and operates as a full extension of the boundary rather than an outpost of it.
- Compute
- Up to 20 hosts, 640 cores
- Storage
- Up to 600TB NVMe
- Power
- 40kW, shore or generator
- Transport
- Road, rail, or sea
Configurations are built to order against a signed scope. Compute, storage, and transit are sized per deployment in the same way as a fixed-site footprint, and the figures above are the current maximums per unit rather than a fixed bill of materials.
What a deployed unit does that a shipped server does not
Anyone can put a server in a case. The work is in what happens to the evidence, the keys, and the state while that case is out of your hands.
Workload memory is encrypted by the processor with keys the hypervisor never holds, exactly as it is in a fixed facility. A deployed unit is not a reduced security tier.
On first power-on at the destination, the unit produces a signed attestation report against the measurement recorded when it was sealed. Verify it before any data is loaded.
Each deployment is scoped with a defined offline window. Within it the unit runs, logs, and enforces policy with no dependency on the control plane at all.
When the link returns, state reconciles in a stated order with conflict rules agreed at scoping time. Nothing is silently merged and nothing is silently dropped.
Units ship under numbered seals with a chain-of-custody record. Seal state is checked and logged at receipt, and a broken seal is an incident before it is an inconvenience.
Key material can be destroyed locally by an authorized operator without a link, rendering stored data unrecoverable and producing the media protection evidence that goes with it.
How the accreditation reaches the site
This is the question an authorizing official asks first, so it is worth answering plainly rather than in a footnote.
A deployable unit is an extension of the ServLogi Inc. boundary, not a separate system. Each configuration is documented in the system security plan as a named deployment pattern with its own control allocation. The pattern is what gets approved, once, rather than each individual shipment.
Your authorizing official approves the pattern
We provide the deployment pattern, the control allocation, and the boundary diagram for review before the first unit ships. Subsequent deployments under the same pattern move on a notification rather than a new authorization package.
Physical security is shared and stated
We cannot control a site we do not operate. Physical and environmental controls at the destination are documented as customer responsibility, with the specific control identifiers listed, so nothing is assumed to be inherited that is not.
Evidence keeps accumulating offline
Audit records, access reviews, and scan results are buffered locally during a disconnected window and delivered on reconnect. Gaps are marked as gaps rather than backfilled, because an assessor will ask.
Impact level travels with the scope
Units supporting IL5 or IL6 work are built, sealed, and handled under the personnel and handling requirements that apply to that level. The unit does not acquire an impact level by being plugged into a network that has one.
From scope to site in six steps
The sequence is the same for a single case and a container. What changes is the lead time on the build.
- Scope and pattern reviewWe agree the configuration, the offline window, the resync rules, and the split of physical controls at the destination. Your authorizing official reviews the deployment pattern and the control allocation that goes with it.
- Build and baselineHardware is procured and staged through our own supply chain, imaged to the same baseline as a fixed-site host, and firmware measured. The launch measurement recorded here is what the unit is checked against on arrival.
- Seal and shipThe unit is sealed under numbered tamper-evident seals and released to the carrier or to your own logistics with a chain-of-custody record that travels with it.
- Receipt and field attestationAt the destination, seals are checked and logged, the unit powers on, and it produces a signed attestation report. Verify the report against the sealed measurement before any data is placed on it.
- Operate, connected or darkThe unit runs under the same policy, telemetry, and incident response plan as the rest of your footprint. Inside the agreed offline window it needs nothing from the control plane to keep enforcing that policy.
- Recover, resync, sanitizeOn return the unit reconciles state in the agreed order, then media is sanitized under NIST SP 800-88 with the certificate filed against the engagement. Nothing goes back into inventory carrying your data.
What the hardware is built to survive
Figures below are the design envelope for the SLD-1 and SLD-8 configurations. Containerized sites are conditioned internally and are specified against the site rather than the enclosure.
- Operating temperature
- 0°C to 40°C ambient
- Non-operating temperature
- -30°C to 60°C
- Relative humidity
- 5% to 90%, non-condensing
- Operating altitude
- Up to 10,000 ft
- Shock and vibration
- Tested against MIL-STD-810H methods 514.8 and 516.8
- Enclosure
- Sealed case, IP54 closed, with pressure relief
- Input power
- 100 to 240V AC, 50/60Hz, generator tolerant
- Transport case
- ATA 300 Category I rated
Test reports for the specific configuration under consideration, including the methods and profiles used, are provided to verified agencies and cleared contractors under a mutual non-disclosure agreement.
Deployments this is built for
Illustrative of fit rather than a customer list. Agency and cleared-contractor engagements restrict public attribution, so we describe the shape of the deployment instead.
Forward and expeditionary sites
Compute at a location with intermittent transit, where the operating picture has to survive the link going down rather than degrade with it.
Disaster response and emergency communications
Standing up dispatch, records, and coordination systems at an incident site when the local facility is offline or unreachable.
Border, port, and inspection
Screening and inspection workloads processed on site, where sending raw capture upstream is neither fast enough nor cheap enough to be viable.
Mobile command posts
A command element that relocates on short notice and needs its enclave to move with it under one continuous authorization.
Exercises and training ranges
Temporary environments that need real controls for the duration and a clean, evidenced teardown at the end of it.
Program surge
Capacity at a program site for a defined period, without adding a facility or restarting an authorization for a footprint that will be gone in a year.
Lead times and allocation
Deployable builds draw on the same hardware supply as the fixed fleet, so they are scoped against the same allocation calendar. Bring us the date you need it on site, not the date you want to order.
Take the next step
Deployable work starts with a site and a date. These are the three most useful things to do with that.
Scope a deployment
A working session on the site, the offline window, the configuration that fits, and the control split your authorizing official will need to see.
Read how the fixed fleet is built
Deployable units run the same baseline as the twelve facilities. The hardware, network, and telemetry behind them are documented in full.
Verify an attestation report yourself
The arrival check on a deployed unit uses the same procedure as any other host. Walk through it before you decide whether it satisfies your reviewers.
CLOUD INFRASTRUCTURE