This week All our GPUs are sold at cost price — zero margin on the server. See the cost sheets

This week Every GPU sold at cost price

Trust & security

What we do to keep your server yours.

A dedicated server is a promise about who else can touch it: nobody. This page lists what backs that promise, from the cage door to the erase command, and what we hold about you, which is as little as a host can hold and still bill.

A locked data-centre cage with a biometric reader

In layers

From the building to the bytes.

  • Physical

    Carrier-neutral data centres with 24-hour staffing, CCTV, mantraps and biometric access to the halls. Our racks are in locked cages; only our own engineers hold the keys and every entry is logged by the facility and by us. Escorted access for anyone else, which in practice means the electricians.

  • Hardware isolation

    One tenant per server. No hypervisor, no vGPU profiles, no shared PCIe root. Firmware is reset to our baseline between tenants and the BMC password is regenerated. What you see in nvidia-smi is the whole card because nobody else has a slice of it.

  • Data sanitisation

    When a server is cancelled, every NVMe device is erased with the drive's own secure-erase command (crypto-erase on self-encrypting drives), then verified, before the hardware is reused. GPU memory is cleared by a power cycle. Suspended servers are erased 14 days later unless you resume them.

  • Network

    Each server has its own layer-2 segment; no tenant shares a broadcast domain with another unless they order a private VLAN between their own servers. Spoofed sources are dropped at the edge, volumetric attacks are blackholed upstream, and nothing else is filtered: your firewall is yours.

  • Account

    Passwords hashed with bcrypt, sessions and API tokens stored as SHA-256 hashes, an anti-forgery token on every form, rate limits per address and per account, Turnstile on the anonymous forms, and no password-reset email, because we hold no address we could send one to.

  • Payments

    A fresh deposit address per invoice, generated by the payment processor; we never hold your keys and never see a card. Credits are applied only after network confirmation, once, in a database transaction. Refunds go back to the address the money came from.

Your data

We do not log in. We cannot read it.

We operate the hardware, the network and the platform; the operating system and everything on it are yours. Our monitoring sees power draw, link state, port counters, IPMI health and whether the SSH port answers. There is no agent on your server and no access path from our side that does not go through your own credentials or the IPMI console, whose use is logged in your event log.

If you want the disk unreadable even to someone with physical access, enable LUKS or BitLocker at install; the local NVMe is fast enough that you will not notice.

What we hold about you

An email address and a ledger.

Identity
An email address and a password hash. No name, address, phone, document or card, ever.
Billing
Invoice references, coins, amounts, deposit addresses and the transaction references the processor reports. The ledger of charges and credits.
Technical
IP address and browser at sign-in and at each order, in the event log for twelve months. Sessions 30 days.
Third parties
Cloudflare at the edge and Turnstile on three forms; the payment processor for invoices. No analytics, no pixels, no ad networks.
Legal requests
Only binding orders under the law of the country where the server sits; only what we hold; we tell you unless forbidden.

The privacy policy has the retention table.

Operations

Boring on purpose.

  • Monitoring

    Every server probed every minute from two regions; hardware health from IPMI; the same measurements drive the SLA credits and the status page.

  • Spares and repair

    Cards, drives, memory and power supplies on the shelf in every region. Four-hour target from detection to swap. Data on a failed drive is not recovered; keep backups.

  • Change control

    Firmware and fabric changes are staged on our own nodes first, announced 72 hours ahead, rolled one node at a time, and written up on the status page.

  • Access on our side

    Engineers reach management networks through hardware-key SSH on jump hosts, with per-person accounts and session logs kept for a year. No shared root anywhere.

  • The platform

    The console and the API run on the same principles we ask of you: a strict content-security policy, TLS only, no third-party scripts, hashed secrets, and an event log you can read.

  • Abuse

    Reports are forwarded to the tenant with 24 hours to answer; ongoing harm is stopped by suspension. Everyone on the network benefits from that, including you.

Responsible disclosure

Found something? Tell us first.

Through a ticket in the console, like everything else. Acknowledged within two working days.

If you find a vulnerability in dedigpu.com, the console, the API or our network, report it through a ticket in the console with enough detail to reproduce it. We acknowledge within two working days, keep you informed, and credit you on this page if you wish once it is fixed. We pay for findings that would have let someone read another tenant's data or spend another account's balance; the amount depends on the impact and we say it up front.

In scope: this site, the console, the API, the management network, the provisioning system. Out of scope: tenants' servers (they are not ours to test), denial of service, social engineering of our staff, and anything that needs physical access.

Safe harbour: research done in good faith, without accessing other tenants' data beyond what is needed to demonstrate the issue, and reported to us before anyone else, will not be met with legal action from us.

A server nobody else can touch.

One tenant, the whole card, erased when you leave. At cost.