Security / Deployment boundaries
Control begins with a clear boundary.
Where compute runs. Who can reach it. Who is responsible for operating it. Security starts with making each answer explicit.

Define the deployment boundary
Pacific is built for organisations where data governance is non-negotiable. Start by identifying where the workload runs, which data it processes, and which people and systems can reach it. These decisions shape a deployment before hardware arrives.
Single-tenant bare-metal capacity gives the customer a dedicated compute environment. On-premises deployments bring the physical location into that discussion. Neither arrangement removes the need to define network access, administration, and the customer application boundary.
Make access deliberate
Encryption, granular sharing, and tenant separation remain important data-governance concerns. The controls required depend on the application, the data, and the agreed deployment. A physical compute boundary and application-level permission controls solve different parts of the problem.
Identify who manages identity, encryption keys, administrative access, and network policy. Document how access is approved and removed, and how customer workloads stay separated from infrastructure management. Confirm the implemented controls during technical review.
Agree the operating responsibilities
Pacific builds, deploys, and operates its capacity modules through remote operations and contracted regional field service. The site and customer workload introduce additional responsibilities that need to be agreed for each deployment.
Define physical access, change control, incident escalation, audit evidence, and recovery responsibilities together. Establish what activity is logged, who can review it, and how the relevant records are retained. The signed agreement should describe the operating boundary and the responsibilities on each side.
Scope regulated workloads carefully
For a CMMC-related deployment, the discussion is about scope reduction: locating the relevant workload within a defined boundary and documenting its connections and dependencies. Hardware location alone does not determine the scope of an organisation's obligations.
Use a technical review to establish which controls belong to the infrastructure, which belong to the customer, and what evidence is needed. Any export-control or other regulated-workload requirements must be evaluated for the specific deployment with the customer's responsible advisors.
