Physical Path Governance for Colocation & Data Centres
Colocation facilities share power, cooling, fibre and management planes across many tenants. One compromised environment can become a launchpad into neighbouring cages. Control removes the shared paths that attackers rely on.

- Shared attack surface between customer cages
- ZeroShared attack surface between customer cages
- Modules governing every physical path
- 9Modules governing every physical path
- Auditable cross-connect and remote-hands activity
- 100%Auditable cross-connect and remote-hands activity
- Tenant isolation evidence for SLA and compliance
- FullTenant isolation evidence for SLA and compliance
Shared infrastructure should not mean shared risk.
Flat Cross-Connects
Legacy cross-connects remain live indefinitely, creating persistent paths between customer environments that bypass normal network controls.
Shared Management Plane
Provider remote hands, out-of-band management and smart hands tools often reach every cage from a single console.
Tenant-to-Tenant Lateral Movement
A breach in one tenant estate can traverse shared infrastructure and reach another customer through a path that should never have existed.
Network Evolution & Rapid Protection (#NEARP)
In a colocation facility, the only thing that should be shared is the building. Power, cooling and physical security are the provider's responsibility. Reachability between tenants is not.
The Scenario
Scenario: a compromised tenant reaches its neighbour
A managed service provider (MSP) tenant in a London colocation facility is compromised through a stolen VPN credential. The attacker discovers live cross-connects left open after a completed data migration six months earlier. They move laterally through the provider's shared switching fabric into the cage of a financial services tenant, exfiltrate customer database backups and encrypt storage arrays before the incident is detected. The provider faces contractual liability, reputational damage and a regulator asking why one tenant could reach another. With Control, the Relay module would have closed the cross-connect at the end of the migration window. The Unlink module would have removed the persistent trust relationship. The Firebreak module would have physically severed the path between the shared fabric and the customer cage, so the attack could not have travelled the cable.
"We thought each cage was isolated because the VLANs were different. Then we discovered a cross-connect had been left live for months. Logical separation is not enough when the physical cable still exists."
Where each Control module is deployed across provider fabric and customer cages.
A colocation facility runs a shared provider edge and switching fabric, then breaks out into individual customer cages. Control puts a physical boundary between the provider fabric and each cage, and between cages, so shared infrastructure never becomes shared risk.
Grounded in ISO 27001 Annex A.13, PCI DSS v4 network segmentation guidance, SOC 2 CC6.1 and ENISA data centre security guidance.
Internet / WAN
External
Untrusted traffic terminates at the provider edge.
Untrusted traffic terminates at the provider edge.
External traffic terminates at the provider edge.
Provider edge
DMZ · trust boundary
Provider-controlled demarcation point.
Provider-controlled demarcation point.
The shared fabric is reached only through controlled points.
Shared fabric
IT
Shared switching. Not a trusted zone for tenants.
Shared switching. Not a trusted zone for tenants.
Tenant A is on its own physical fabric.
Customer cage A
Data
One tenant's environment.
One tenant's environment.
Cross-connects exist only for approved windows.
Customer cage B
Data
Another tenant's environment.
Another tenant's environment.
Customer cage C
Data
A third tenant's environment.
A third tenant's environment.
Provider management
DMZ · trust boundary
Provider access to tenant kit. Named and time-bound.
Provider access to tenant kit. Named and time-bound.
Remote hands access is named and time-bound.
Shared facilities
Field
Building services only. No data path.
Building services only. No data path.
Crown jewels
Off-network
Detail callout · A
Offline Secure Storage
Provider configuration backups, tenant isolation evidence, audit logs and the recovery sets you need after a facility incident.
Offline by design · secure by defaultModules & symbols
Where each module is deployed, and what it does there.
One row per module. Placement on the network, then plain-English purpose at that point.
-

Isolate
Between the shared fabric and every customer cage
Each tenant sits on its own physical fabric. A broadcast storm, misconfigured route or compromised switch in the shared fabric cannot reach a customer cage.
-

Firebreak
On the P0 to P1 link and every P2 to CAGE link
The provider has a real hardware off switch on the internet boundary and on every tenant boundary. An incident can be contained by severing the physical path.
-

Validate
On the P0 to P1 link and every P2 to CAGE link
Inbound traffic and any request to open a tenant path are checked for origin, integrity and authority before they progress.
-

Relay
Between customer cages
Cross-connects between tenants open for the approved window of work and close automatically. No path persists beyond the business need.
-

Transfer
Between customer cages
When data must move between tenant environments, Transfer governs the route, the landing point and the audit trail.
-

Lock
On every P2 to CAGE link and every MGMT to CAGE link
Access to a tenant cage or its equipment ties to a named, verified individual with the right authority. Shared remote-hands credentials are eliminated.
-

Unlink
Between customer cages and on the MGMT to CAGE links
When a project ends or a tenant departs, the cross-connects and remote-hands access rights are removed. Residual trust does not accumulate.
Capabilities
What you get with every deployment
Tenant Isolation at Layer 1
Customer environments are separated by physical path control, not only VLANs or ACLs. No exploit, misconfiguration or insider action can bridge the gap.
Shared Infrastructure Protection
Power, cooling, connectivity and management planes remain shared, but the attack surface is not. The provider's core infrastructure is protected from a single tenant compromise.
Cross-Connect Lifecycle Governance
Cross-connects are requested, approved, opened, audited and automatically closed. No cross-connect lives beyond its approved purpose.
Scheduled Maintenance Windows
Remote hands and engineering access open only during agreed windows, with full identity verification and session logging.
Audit-Ready Isolation Evidence
Every physical path change is recorded immutably, giving providers and tenants defensible evidence for SLAs, SOC 2, ISO 27001 and customer assurance questionnaires.
Offboarding Without Residual Trust
When a tenant leaves or a project ends, Unlink removes the cross-connects, access rights and inherited trust relationships that would otherwise persist for years.
Demo to Live
Adoption Guide
Cross-Connect Inventory
Catalogue every live cross-connect, remote-hands access path and management-plane route between the provider fabric and customer cages.
Tenant Isolation Architecture
Map Control modules to the provider's physical topology, designing isolated fabrics per cage while preserving shared power, cooling and building security.
Pilot with One Hall
Deploy Control in a single data hall or cage row, validating cross-connect lifecycle governance without disrupting existing tenants.
Facility-Wide Go-Live
Extend physical path governance across all halls, activate tenant-facing isolation reports, and integrate audit logs into the provider's compliance workflow.
Cross-Connect Inventory
Catalogue every live cross-connect, remote-hands access path and management-plane route between the provider fabric and customer cages.
Tenant Isolation Architecture
Map Control modules to the provider's physical topology, designing isolated fabrics per cage while preserving shared power, cooling and building security.
Pilot with One Hall
Deploy Control in a single data hall or cage row, validating cross-connect lifecycle governance without disrupting existing tenants.
Facility-Wide Go-Live
Extend physical path governance across all halls, activate tenant-facing isolation reports, and integrate audit logs into the provider's compliance workflow.
Relevant Control Blueprints
Deployment patterns that apply here
Enforce Physical Segmentation
Segmentation should not just be logical. It should be physically enforceable.
View blueprintControl Third-Party Access
Give third parties access without giving them a permanent doorway.
View blueprintContain Active Breaches
When prevention fails, containment must be physical, immediate and provable.
View blueprintProve Compliance Through Control
Compliance becomes stronger when control can be demonstrated, not just documented.
View blueprintExplore More
Control for IT Networks
Policy-enforced path control across IT infrastructure.
Learn more about Control for IT NetworksControl for Critical Infrastructure
National-grade security for essential services.
Learn more about Control for Critical InfrastructureFirevault Bunkers
Carefully selected colocation facilities for offline secure storage.
Learn more about Firevault BunkersQuestions


