Datasheet Superclusters.pdf

Superclusters

Security Overview

Single‑tenant by design

Lambda Superclusters are dedicated Single-tenant clusters with no shared components from the perimeter firewall down. Physical and logical isolation eliminates contention and inter‑ tenant risk.

Assurance

Customer-controlled access


Offering models & responsibility

We offer a baseline dedicated cluster with optional managed services. The matrix below clarifies who owns which controls.

Layer / Control Area Bare-metal / Physical-only Support (Self-managed) Managed Superclusters (Co-managed) Managed Kubernetes (Fully-managed)
Tenant isolation Dedicated compute, network and storage hardware; no shared cluster component Same Same
Physical security Dedicated cabinets. DC guard staff, CCTV, multi-factor checkpoints, optional secure cage or dedicated data hall Same Same
Network perimeter Customer-managed firewall (default deny inbound) with VPN/peering options Co-managed change workflows; Lambda proposes, customer approves Integrated with k8s network policies
Management access No standing Lambda logical access; you may grant time-boxed access as needed Lambda retains tightly scoped access for operations, Lambda's access is revocable by the customer at any time Lambda retains exclusive node management access, customer k8s access through SSO via OIDC/SAML with role-based access controls
OS & host hardening Customer owns OS patching, users, keys, and logging Joint: Lambda assists within coordinated maintenance windows; audit logs available Lambda manages cluster and k8s control plane patching
Storage & keying Networked storage encrypted at rest (AES-XTS 256-bit); customer controls access to data Same; Lambda supports ops tasks with customer approval Same
Monitoring & logging Customer-provided tooling Co-managed runbooks; logs and audit trails for Lambda actions Integrated cluster logging and metrics
Support model Break/fix hardware support via ticket system; no autonomous actions by Lambda. Proactive operations per runbook with coordinated maintenance windows Kubernetes and cluster lifecycle managed by Lambda

Physical security

FACILITY & ENCLOSURE

CONTROLS & MONITORING

Data security

Logical security & platform hardening

FIRMWARE & HOST BASELINE

NETWORK ARCHITECTURE

ACCESS OPTIONS - CUSTOMER‑ CONTROLLED


Compliance and assurance

Customer controls & complementary responsibilities

To align with industry frameworks (e.g., SOC 2 CUECs/CSOCs), the following areas typically remain your responsibility unless otherwise scoped in a managed engagement:

Frequently asked assurances