BASTION / POLICIES
Compliance & security
Last updated: October 5, 2026
Scope & service commitments
This page describes the compliance review framework and technical requirements for proposed GPU cloud deployments. It is not a statement that every control is already implemented at every site. The contracting entity, operating site, service model, security controls, responsibilities and evidence must be identified in the executed agreement before production use.
Export controls, sanctions & customer screening
Service eligibility requires review of applicable U.S. export controls and sanctions, and relevant rules in the hosting and customer jurisdictions. Review covers legal entities, beneficial ownership, ultimate end users, intended workloads, equipment classification, deployment location and remote access arrangements. Screen applicable restricted-party lists and ownership rules, including OFAC’s aggregate 50% ownership rule. A foreign incorporation or an offshore data center does not by itself establish eligibility. Required authorizations must be resolved before access or delivery; changes of ownership, location, end use or onward access require renewed review.
Approved access & acceptable use
Customers must accurately identify the actual users and intended uses. Undisclosed resale, account sharing, proxy access to evade restrictions, and circumvention of geographic or technical controls are prohibited. Services must not be used for unlawful surveillance, unauthorized intrusion, malware, infringement or legally prohibited military, intelligence or weapons-related uses. Suspicious activity can trigger additional review or restricted access under the agreement and applicable law. Remote cloud access is assessed separately from physical equipment movement; neither is treated as a blanket exemption.
GPU isolation & network boundaries
Each deployment must specify dedicated bare metal, virtual machines, containers or supported GPU partitioning, with a documented tenant isolation model. GPU partitioning alone is not evidence of complete tenant isolation. Validate host, hypervisor, storage and scheduler permissions; isolate management/BMC networks from tenant networks; and restrict east-west traffic. InfiniBand or RoCE fabrics, RDMA access and GPU peer-to-peer paths require a deployment-specific boundary and test plan. Dedicated hardware is not automatically confidential computing; attestation or encrypted GPU memory must be separately supported and verified.
Identity, encryption & platform hardening
The security schedule should define MFA for privileged access, role-based permissions, time-limited support access, credential rotation and audit logging. Specify encryption for storage, backups and supported network paths, together with key ownership and recovery duties; do not assume RDMA traffic is encrypted. Maintain approved OS, driver, CUDA, GPU firmware, BMC and network firmware versions, vulnerability handling and change windows. Container images and software dependencies require provenance and vulnerability review; signed or verified images should be used where supported.
Data location, privacy & transfers
Before regulated or personal data is uploaded, agree the hosting region, controller/processor roles, processing instructions, subprocessors, support-access countries and retention periods. Where GDPR applies, address processor terms, appropriate security, breach cooperation and any applicable international transfer mechanism. Regional hosting alone does not exclude a cross-border transfer through remote support or backups. Other privacy and sector rules depend on the actual data, parties and jurisdictions. Health, payment or similarly regulated workloads require an explicit readiness review and any necessary contractual terms before onboarding.
Reassignment, deletion & asset lifecycle
Before hardware is reassigned, define and validate cleanup of GPU memory, host RAM, local NVMe, temporary storage, snapshots and credentials. A reboot or ordinary file deletion is not a substitute for a verified sanitization method. The data-return and deletion schedule must distinguish active copies, backups, legal holds and failed-media handling, with retention limits and evidence where agreed. Media sanitization methods should be selected and verified for the device and data sensitivity, using NIST SP 800-88 Rev. 2 as a reference where appropriate. Maintain asset identity and custody records through installation, maintenance, RMA and retirement.
Operations, incidents & shared responsibility
The contract must assign responsibility across Bastion, the facility operator and the customer for physical access, power/cooling, platform maintenance, OS patching, applications, data, backups and recovery. Specify monitoring coverage, audit-log retention, escalation contacts, incident notification duties and recovery objectives. Notification timing must follow applicable law and the agreed roles, rather than a universal website promise. Customers remain responsible for authorized datasets, workload configuration, account users and application security unless expressly included in a managed service.
Evidence, certifications & supplier rights
No ISO 27001, SOC 2, HIPAA, PCI DSS, NVIDIA partner status or other certification is claimed by this page. Any assurance must identify its legal entity, site, service scope, validity period and supporting evidence. GPU hardware ownership does not automatically include software subscriptions, hosting rights or resale permissions. Procurement and service activation must confirm applicable vendor licenses and provider rights. Customer contracts should include an order form, service/SLA schedule, security responsibilities, data terms where applicable and acceptable-use obligations.
Website storage & compliance enquiries
This website uses local browser storage only to remember the selected display language; this site code includes no analytics or advertising trackers. The hosting provider may process technical request logs under its own policies. External LinkedIn links are governed by that service’s policies. Use the contact link for an initial compliance enquiry or to request a secure reporting channel. Do not send credentials, datasets, identity documents or vulnerability exploits through a public social profile. Customer incident contacts and secure reporting routes must be established during onboarding.
Official references
Contact
For initial enquiries, contact Tong Shen to request the appropriate private channel.
Contact via LinkedIn ↗