Secure cluster design
Isolation designed in from the start, from fabric partitioning to management-network separation, then verified once the cluster is live.
For organisations building shared GPU clustersWe design secure multi-tenant GPU clusters and continuously prove that every tenant stays isolated, from the fabric to the firmware.
Now onboarding design partners.
Workloads for banks, governments and AI labs, side by side on the same cliff.
What can one tenant see, reach or change about another?
Every time a node is provisioned or recycled, and on a schedule.
Recent independent testing of GPU cloud providers found tenants able to:
See other tenants' infrastructure
Read across tenant boundaries
Reach management networks
Often through default settings rather than sophisticated attacks.
Configurations drift. Nodes get recycled. A one-off audit is out of date the day after it ends.
Providers need continuous evidence, and their customers increasingly ask for it.
Runs every time a node is provisioned or recycled, and on a schedule.
What can one tenant see, reach or change about another?
InfiniBand partitions and keys, RoCE and Ethernet segmentation.
BMC, IPMI and Redfish reachability.
Operating mode and host access.
Kubernetes and Slurm exposure, network policy, shared control planes.
Per-tenant separation in the backend, not just the dashboard.
Disk wipe, DPU reflash and firmware state between tenants.
Known-vulnerable drivers, container toolkits, runtimes and firmware.
Every time a node is provisioned or recycled, and on a schedule.
Failures raise an alert with the exact fix.
Every fix is followed by a re-test.
Each tenant handoff produces an isolation report the provider can share with that customer.
Isolation designed in from the start, from fabric partitioning to management-network separation, then verified once the cluster is live.
For organisations building shared GPU clustersA full, scoped assessment of an existing cluster, with findings, fixes and a re-test.
Ongoing checks on every node handoff, with per-tenant reports for your customers.
No test runs without a signed, written scope.
Your engineers stay in the loop.
Findings go only to you. Nothing is ever published without your written consent.
Checks run inside your environment, so your data stays in-country.
Alcora Labs was founded by Saad Khan. He has five years of experience in AWS and cloud infrastructure, a background in electrical engineering, and comes from Instec, a cybersecurity firm that has operated across Pakistan and the Gulf since the 1980s.
Named after the razorbill: a seabird that nests in crowded colonies, each pair holding its own ledge.
Now onboarding design partners.