GPUnex
Security

Your Security Is Our Foundation

Every layer of GPUnex is designed to protect your data, your funds, and your infrastructure. From hardware isolation and encrypted storage to financial compliance and incident response — security isn't an afterthought, it's built into everything we do. We protect the platform, the providers, and the renters at every level.

Infrastructure Security

Enterprise-grade infrastructure designed for isolation, performance, and resilience from the ground up.

Container Isolation

Every workload runs in an isolated Docker container with strict resource limits. Containers have no access to the host system, other workloads, or other users' data. We use kernel-level isolation and network segmentation to ensure complete separation.

Automated Benchmarks

Every GPU on our platform undergoes automated performance benchmarking before listing. Regular re-benchmarks verify consistent performance. GPUs that fall below quality thresholds are automatically de-listed until issues are resolved.

EU-Based Servers

Our core infrastructure is hosted in European data centers with enterprise-grade physical security, redundant power, and climate control. European hosting ensures your data is protected under EU data protection laws.

Network Security

All data in transit is encrypted via TLS/SSL. Our internal networks use encrypted tunnels and are segmented to prevent unauthorized access. DDoS protection and firewall rules are monitored 24/7.

Physical Security

Our data center partners maintain the highest standards of physical security, environmental controls, and infrastructure resilience.

Datacenter Classification

All GPUnex infrastructure is hosted in Tier 3 or Tier 4 certified data centers. These facilities guarantee a minimum of 99.982% uptime through redundant capacity components and multiple independent distribution paths.

Access Controls

Data center access is restricted through biometric authentication, multi-factor physical access controls, and personalized key cards. All visitors are logged, escorted, and require pre-approval. Access is limited strictly to authorized personnel.

24/7 Surveillance

Facilities are monitored around the clock with CCTV surveillance systems, on-site security personnel, and perimeter protection including fencing and mantraps. All access events are recorded and retained for audit purposes.

Redundant Infrastructure

Every facility includes uninterruptible power supplies (UPS), diesel backup generators, N+1 redundant cooling systems, and advanced fire suppression. These systems ensure continuous operation even during power grid failures or environmental incidents.

Access Control & Authentication

Multi-layered identity and access management to protect every account and API interaction on the platform.

Multi-Factor Authentication

All GPUnex accounts support multi-factor authentication (MFA) via time-based one-time passwords (TOTP) and hardware security keys. MFA adds a critical second layer of protection beyond passwords, preventing unauthorized access even if credentials are compromised.

Role-Based Access Control

Team and organization accounts benefit from role-based access control (RBAC) with clearly defined permission levels. Administrators can assign granular roles to team members, ensuring each user only has access to the resources and actions they need.

API Key Management

API keys can be securely created, scoped to specific permissions, rotated on schedule, and revoked instantly. All API access is logged and rate-limited. Keys are never stored in plaintext and are hashed at rest for maximum protection.

Session Management

Sessions automatically expire after periods of inactivity. Users can view all active sessions across devices, receive login notifications for new devices, and remotely terminate any session. Suspicious login attempts trigger automatic alerts.

Provider Verification

Every GPU provider on our marketplace undergoes rigorous vetting to ensure hardware quality, identity integrity, and ongoing compliance.

Identity Verification

Every renter and provider completes full KYB (Know Your Business) verification, including government-issued ID validation and business data checks. We verify ownership structures and conduct due diligence to ensure platform integrity and high compliance standards.

Hardware Verification

GPUs undergo automated authenticity checks including model verification, firmware validation, VRAM integrity tests, and performance benchmarks. Only hardware that passes all checks is listed on the marketplace. This prevents counterfeit or misrepresented hardware.

Datacenter Requirements

Providers must meet minimum infrastructure standards including redundant power supply, climate control, network connectivity with SLA guarantees, and physical security measures. Datacenter facilities are evaluated before providers are approved.

Ongoing Compliance

Providers are subject to regular re-audits including performance re-benchmarks, uptime monitoring, and compliance checks. Providers that fail to meet quality standards or violate platform policies are automatically de-listed until issues are resolved.

Financial Security

Your funds are protected at every stage — from deposit through payout — with escrow, compliance, fraud detection, and dispute resolution.

Escrow Billing

All payments on GPUnex are processed through our escrow system. Funds are held securely until services are delivered and verified. This protects both renters and providers, ensuring fair transactions for all parties.

KYB/AML Compliance

Renters and providers on GPUnex complete KYB (Know Your Business) verification to the highest standards. We comply with international anti-money-laundering regulations and work with verified identity verification providers to ensure platform integrity.

Fraud Detection

Our systems monitor transactions in real-time using advanced anomaly detection algorithms. Suspicious patterns — such as unusual transaction volumes, velocity changes, or geographic inconsistencies — are automatically flagged for review before processing.

Dispute Resolution

GPUnex provides a structured dispute resolution process for any transaction disagreements. Our mediation team reviews evidence from both parties, follows defined escalation steps, and ensures fair outcomes. Escrow funds are held until disputes are resolved.

Chargeback Protection

GPU providers are protected against unjustified chargebacks through our escrow system and verified billing process. Usage is metered and logged with tamper-proof records, providing clear evidence of service delivery in case of disputes.

Data Protection

Your data is encrypted in transit and at rest, handled in full compliance with European data protection law, and securely deleted when no longer needed.

SSL/TLS Encryption

All communication between your browser and GPUnex is encrypted with TLS 1.3. API traffic, dashboard access, and file transfers are all protected by end-to-end encryption. We regularly audit our certificate chains and cipher suites.

Encryption at Rest

All stored data — including user information, transaction records, and workload metadata — is encrypted at rest using AES-256 encryption. Encryption keys are managed through a dedicated Key Management Service (KMS) with regular automated key rotation.

GDPR Compliance

GPUnex is fully GDPR compliant. Your personal data is processed in accordance with European data protection regulations. You have the right to access, modify, or delete your data at any time. We never sell user data to third parties.

Secure Data Deletion

When a rental ends, all workload data is cryptographically erased from the GPU provider's infrastructure. We follow certified deletion procedures with defined retention periods. Your right to erasure under GDPR Article 17 is fully supported for all personal data.

Shared Responsibility Model

Security is a shared effort. Here's how responsibility is distributed between GPUnex, GPU providers, and renters.

GPUnex

  • Platform security & availability
  • Escrow & payment processing
  • Identity verification (KYB/AML)
  • Monitoring & incident response
  • Network infrastructure & encryption

GPU Provider

  • Hardware integrity & maintenance
  • Physical security of machines
  • Firmware & driver updates
  • Power supply & cooling
  • Network connectivity & uptime

Renter / User

  • Container contents & code
  • Application-level security
  • Credentials & access keys
  • Uploaded data & models
  • Backup of own workloads

Compliance & Certifications

GPUnex and our datacenter partners adhere to internationally recognized security and compliance standards.

GDPR Compliant

Full compliance with EU General Data Protection Regulation

KYB/AML Verified

Identity verification and anti-money-laundering compliance for renters and providers

EU Data Jurisdiction

All data processed and stored within EU jurisdiction under EU law

Certified Datacenters

Partner facilities hold ISO 27001 certification and Tier 3/4 classification

Incident Response

A structured, transparent approach to security incidents — from detection to resolution and post-incident review.

Severity Classification

All security events are classified into defined severity levels — Critical, High, Medium, and Low — each with fixed response time commitments. Critical incidents are addressed within minutes, with immediate escalation to senior security personnel and executive leadership.

Customer Notification

Affected customers are notified proactively within defined timeframes. For incidents involving personal data, we comply with the GDPR 72-hour notification requirement to supervisory authorities. Our communication includes the nature of the incident, data affected, and remediation steps taken.

Post-Incident Analysis

Every incident is followed by a thorough root cause analysis. We document findings, identify process improvements, and implement corrective measures. Lessons learned are incorporated into our security procedures to prevent recurrence.

Security Contact

Security concerns and vulnerability reports can be sent directly to [email protected]. Our dedicated security team triages all incoming reports and responds within 24 hours. For urgent matters, our 24/7 support team can escalate immediately.

Vulnerability Management

Proactive identification and remediation of security vulnerabilities across our entire technology stack.

Automated Scanning

Our infrastructure and applications undergo continuous automated vulnerability scanning. Identified vulnerabilities are prioritized by severity and remediated within defined SLA windows — critical vulnerabilities within 24 hours, high-severity within 72 hours.

Penetration Testing

Independent third-party security firms conduct penetration tests on our platform at least annually. These tests simulate real-world attack scenarios across our web applications, APIs, and infrastructure. All findings are remediated before the next assessment cycle.

Responsible Disclosure

We welcome responsible security research. Security researchers who discover vulnerabilities can report them to [email protected]. We provide a safe harbor policy — researchers acting in good faith will not face legal action. We acknowledge all valid reports and work with researchers on coordinated disclosure.

Dependency Management

All software dependencies are continuously monitored for known vulnerabilities using automated tools. When a critical vulnerability is disclosed in a dependency, we assess exposure and deploy patches within our defined SLA windows. Our software bill of materials (SBOM) is maintained and reviewed regularly.

Business Continuity & Disaster Recovery

Comprehensive planning and redundancy to ensure platform availability and data integrity, even during the unexpected.

Platform Redundancy

Critical platform components are deployed across geographically distributed systems with automatic failover. There is no single point of failure in our core architecture. Load balancing and health checks ensure traffic is routed to healthy instances at all times.

Backup Strategy

Platform data is backed up regularly with defined Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO). Backups are encrypted, stored in geographically separate locations, and tested periodically to verify integrity and restorability.

Disaster Recovery Testing

We conduct regular disaster recovery exercises and emergency simulations to validate our recovery procedures. These tests cover scenarios including datacenter failures, data corruption, and network outages. Results are documented and used to refine our DR plans.

Incident Communication

During outages or service disruptions, we follow defined escalation paths and communicate through our public status page. Customers receive real-time updates on incident status, expected resolution time, and post-recovery summaries. Transparency is our priority during any service event.

24/7 Monitoring

Round-the-clock surveillance of every system, every metric, every anomaly — backed by a guaranteed uptime SLA.

Our infrastructure and security systems are monitored around the clock. Automated alerts detect anomalies in real-time, and our operations team responds immediately to any security events. We conduct regular security audits and penetration testing to stay ahead of potential threats.

Our 99.9% Uptime SLA covers platform availability including the dashboard, API, and billing systems. In the event of an SLA breach, affected customers are eligible for service credits. Full SLA terms are available in our Terms of Service.

24/7
Security Monitoring
99.9%
Uptime SLA
EU
Data Jurisdiction

Security Tiers

Choose the level of security that matches your workload requirements — from standard marketplace resources to dedicated enterprise infrastructure.

Community

Standard Security

  • Full KYB identity verification
  • Container isolation with resource limits
  • Automated GPU benchmarks
  • Shared infrastructure with network segmentation
  • Standard escrow protection
  • 24/7 platform monitoring
Enterprise

Enhanced Security

  • Everything in Community, plus:
  • ISO 27001 certified datacenter partners
  • Dedicated single-tenant machines
  • Enhanced monitoring & alerting
  • Custom SLA with guaranteed uptime
  • Priority support & dedicated account manager

Confidential Computing

Hardware-level data protection that keeps your models and data secure — even from the underlying infrastructure.

Trusted Execution Environments

NVIDIA's latest GPU architectures — including H100 and Blackwell — support hardware-based Trusted Execution Environments (TEEs). This technology creates an isolated, encrypted space on the GPU where your code and data are protected during processing, even from the host system and GPU provider.

Model & Data Protection

With Confidential Computing, your AI models and training data remain encrypted in memory during execution. Attestation services allow you to verify the integrity of the compute environment before deploying sensitive workloads. This is the highest level of workload security available in GPU computing.

Trust & Transparency

We believe security requires transparency. Here's how we keep you informed about the state of our platform and practices.

Public Status Page

Our public status page provides real-time visibility into platform health, including API availability, dashboard status, and billing systems. During incidents, we post live updates with estimated resolution times. Historical uptime data is available for full transparency.

Subprocessor List

In compliance with GDPR, we maintain and publish a complete list of all third-party data processors (subprocessors) involved in handling your data. This list is kept up-to-date and available upon request, ensuring full transparency about who has access to your information.

Security Documentation

Detailed security whitepapers and technical documentation are available for enterprise customers and security-focused partners. These documents provide in-depth information about our security architecture, controls, and practices. Contact our team to request access.

Continuous Improvement

We regularly publish updates on security improvements, new compliance achievements, and platform enhancements. Our security practices evolve continuously based on threat landscape changes, audit findings, and customer feedback.

Questions About Security?

Our team is happy to discuss our security measures in detail. Contact us for a security review, compliance documentation, or any questions about how we protect your data and infrastructure.