Frequently asked questions.
The questions federal agencies, cleared contractors, and regulated enterprise teams ask us most often, answered plainly. If something here is not covered, our federal operations team will answer it directly.
Accreditation and compliance
FedRAMP High, DoD SRG IL5/IL6, NIST SP 800-53 Rev. 5, FIPS 140-3, HIPAA/HITECH, SEC Rule 17a-4, SOC 2 Type II, ITAR/EAR, CJIS Security Policy, IRAP PROTECTED, CMMC 2.0 Level 3, IRS Publication 1075, and StateRAMP. See the full breakdown on our compliance page.
The controls that apply to the hosting layer, including boundary protection, account management, system monitoring, backup, and media handling, are already assessed at the platform level. Your assessment covers your application and the controls that remain yours. It does not need to re-examine the infrastructure underneath. Which controls fall on each side is set out in a shared responsibility matrix during onboarding.
Yes. Inheriting the hosting baseline shortens your package considerably, but your system still requires its own authorization. What changes is scope: you are evidencing your application rather than the platform. Our compliance engineers answer assessor questions about the hosting boundary directly.
Through the Client Portal, on a continuous cadence rather than as a point-in-time package assembled for an audit window. Audit reports, control narratives, and attestation records are available to authorized users on your account. See the Trust Center for what is published and what requires portal access.
No. All hosting, processing, and support operations remain in U.S. jurisdiction across twelve United States facilities. Support personnel working federal engagements are United States persons.
Capacity and availability
Yes, for federal agencies, direct government clients, and cleared federal contractors. 2026 hosting capacity is 100% sold out, so those engagements are scoped against 2027 to 2029 allocations. Scoping and control mapping normally run well ahead of the allocation year. See the capacity update.
Most of the 2026 hosting floor is held under multi-year government agreements running to 2029. Because every host is single-tenant, capacity cannot be oversubscribed and released later. Once a footprint is allocated, it is unavailable to anyone else for the term.
Consumer cloud represents 5% of revenue and is closed to new accounts. Existing consumer customers are unaffected and continue to be supported under their current terms. Government cloud is 89% of revenue and remains open to federal and cleared-contractor intake.
A 99.99% monthly availability commitment, backed by a defined service-credit schedule rather than a best-effort target. The measurement method and the credit schedule are set out in the master services agreement. See the service terms.
Yes. Multi-year allocations are the normal arrangement for government programs, and our committed contract horizon currently runs to 2029. A written allocation confirms your footprint and your commercial position for the term.
Platform and security
Every host is dedicated, single-tenant bare metal in a biometric-access facility, not a virtual slice of shared hardware. There is no noisy-neighbor effect on performance, and no other tenant's workload runs on the same physical machine as yours.
By the processor. AMD SEV-SNP encrypts workload memory with keys the hypervisor never holds, so a host operator cannot read guest memory in the clear. Isolation is a property of the hardware rather than a configuration someone has to maintain correctly. See our engineering note on hardware attestation.
Yes, and we would encourage it. Every enclave produces a signed launch measurement on each boot that your team can validate independently. The verification procedure is published, so the check does not depend on trusting our assertion.
Yes. Dedicated bare-metal capacity supports compute-intensive AI and data workloads without the resource contention that comes with shared, multi-tenant hosting, which means throughput you can plan a training or inference schedule around.
A 24/7 security operations centre monitors platform telemetry, and notification paths and escalation ownership between your team and ours are agreed before go-live rather than during an event. See the incident response reference and our disclosure policy.
Through the coordinated disclosure process on our security page, which sets out scope, expected response times, and how findings are handled.
Commercial and contracting
Pricing is issued per engagement in a briefing rather than off a commercial rate card. Dedicated hardware, cleared support, transition engineering, and an inherited FedRAMP High baseline are priced as one line. Build a configuration on the pricing page to see the reference band for your footprint.
Because a single-tenant footprint is not a unit that prices uniformly. Facility, region, transit profile, storage class, and support model all move the number, and most engagements are multi-year. A briefing produces a figure that reflects the actual configuration rather than an average.
Federal agencies, direct government clients, cleared federal contractors, and regulated enterprises in health, financial services, and critical infrastructure. Consumer cloud is closed to new accounts.
Yes. Integrators and managed service providers in our partner program can carry the contract and the implementation, which is often the simpler route where a program already has a prime relationship in place.
Named references are available under NDA during a briefing. Publicly we identify customers by role and sector only, because most agency and cleared-contractor engagements restrict attribution and we do not name a customer without written authorization. See our case studies.
Onboarding and support
The Transition Program pairs your engineers with ServLogi platform and compliance specialists across four phases, from scoping to handover. The work is scoped into the engagement rather than quoted as a separate services line.
Most transitions run 8 to 16 weeks from scoping to handover. The variable is rarely the infrastructure. It is how quickly control ownership can be agreed and how much application change the move requires. We commit to a date at the end of scoping.
A working session covering your workload, its data classifications, the controls you would inherit, and the allocation years available to you. The agenda and what to bring are written up in what to expect in an onboarding briefing.
A named support team, agreed escalation paths, and continuous evidence delivery through the Client Portal. Escalation arrangements settled during transition stay in force after handover. See the support and escalation reference.
Yes. Deployment guides, control mappings, and the provisioning API reference are open to read before you speak to anyone. Start at the documentation index.
Still have a question?
Our federal operations team answers directly, and a briefing is the fastest way to get specifics about your own workload rather than general answers.
Request a briefing
A working session with federal operations and compliance engineering, covering your workload, the controls you would inherit, and the allocation years available to you.
Check the Trust Center
Audit reports, published control coverage, and live platform status, for the questions that are faster to answer by looking than by asking.
CLOUD INFRASTRUCTURE