Skip to main content

Infrastructure

The architecture, in the open

Four sites, one private backbone, six layers of defence. This page sets out the exact topology, the hardware deployed, the contractual commitments and the measurements taken. Nothing here is simplified for the brochure.

Topology

A four-site mesh with no single point of failure

The four data centres are meshed in a dual ring by a private 400 Gbit/s backbone. Losing one site or two links does not degrade the service: traffic moves over in under a second.

Isengard Computing network topologyFour data centres — ORT-1 in Normandy, ORT-2 in Île-de-France, ORT-3 in Grand Est and ORT-4 in the south — are linked in a dual ring by a private 400 Gbit/s backbone, with two diagonal links in addition. Incoming traffic first crosses an edge layer providing filtering and volumetric mitigation before it reaches the internal network. Losing one site or two links does not degrade the service: routing convergence is measured at 780 milliseconds.
Private backbone
400 Gbit/s, dual ring, leased fibre on physically separate routes
Edge
Filtering and volumetric mitigation applied before traffic enters the internal network
Replication
Synchronous within a site, asynchronous between sites — contractual RPO of 15 min
Failover
Routing convergence measured at 780 ms on total loss of a site

Sites

Four data centres, all in France

Every site is operated by our own teams. No hosting is subcontracted and no site sits outside French territory.

The four Isengard Computing data centres: code, region, year in service, IT floor area, power and role
CodeRegionIn serviceIT floorPowerRole
ORT-1Normandy20151,400 m²4.2 MWProduction · bare metal
ORT-2Île-de-France20172,100 m²6.0 MWProduction · cloud · peering
ORT-3Grand Est20201,800 m²5.4 MWProduction · GPU · R&D
ORT-4Provence-Alpes-Côte d’Azur20231,200 m²3.6 MWRecovery · immutable archives

All four sites are operated to our internal “Cadre Souverain Européen, level 2” framework, audited annually by an independent third party. The report is shared under a confidentiality agreement.

Hardware

A standardised, replaceable, measured fleet

Three server profiles, no more. That standardisation is what lets us hold a two-hour replacement time and guarantee reproducible performance.

The three server profiles deployed: use, processor, memory, storage and network
ProfileUseProcessorMemoryStorageNetwork
F-SeriesHigh frequency8 to 16 cores, 5.2 GHz turbo64 – 256 GB DDR5 ECC2 × 3.84 TB NVMe U.22 × 10 Gbit/s
D-SeriesDensity and cloud64 to 128 cores512 GB – 2 TB DDR5 ECC8 × 7.68 TB NVMe2 × 25 Gbit/s
G-SeriesGPU compute2 × 64 cores1 – 2 TB DDR5 ECC4 × 7.68 TB NVMe + parallel FS2 × 100 Gbit/s + 200 Gbit/s RDMA

Service life in production: 5 years, then refurbishment. Spare stock sized at 8% of the fleet in every suite.

Security

Six layers, none assuming the one before it held

  1. L1ACL at the edge

    Network edge

    ACL filtering and anti-spoofing applied on the edge routers, before anything reaches the internal network.

  2. L26 Tbit/s · 30 s

    Volumetric mitigation

    Detection by flow analysis, automatic diversion and scrubbing. Total capacity of 6 Tbit/s spread across the four sites.

  3. L3VXLAN isolation

    Segmentation

    L2 isolation per client, with no lateral traffic possible between two clients. Optional micro-segmentation within a project.

  4. L4Rules maintained in house

    Application firewall

    Managed WAF, rule sets maintained by our R&D team, learning mode first and blocking once validated with your teams.

  5. L5On-demand, traced access

    System hardening

    Hardened images, verified boot, volume encryption at rest, automatic secret rotation, privilege elevation on demand and for a bounded period.

  6. L624/7/365 · 15 min

    SOC correlation

    Central collection, SIEM correlation, behavioural detection and analysts on duty. A severity 1 is taken up within 15 minutes.

Administrative logs kept for 24 months in write-once storage. Two external penetration testing campaigns a year, entrusted to two different providers. GDPR-compliant processing, an in-house data protection officer, and all operations carried out by Isengard Computing employees.

SLA

Commitments and penalties

Penalties are calculated automatically from our own readings and credited on the following invoice. No claim is required from you.

Service level commitments: indicator, commitment, measurement method and applicable penalty
IndicatorCommitmentMeasurementPenalty
Monthly availability99.99%External probes, 3 measurement points10% below 99.99%
Network availability100%Edge to edge, excluding announced maintenance5% per 30 min
DDoS mitigation< 30 sDetection / neutralisation timestamps5% beyond
Severity 1 pickup< 15 minTicketing system timestamps5% beyond
Hardware replacement< 2 hIncident opened to service restored10% beyond
Disaster recovery RTO< 30 minSix-monthly failover test20% if missed in test

Cumulative cap: 50% of the monthly fee concerned. These values are our contractual floor; they can be strengthened, never revised downwards mid-contract.

Environment

Energy efficiency

Average PUE

1.12

Annual average across the four sites, measured at the meter.

Free cooling

82%

Share of the year cooled by outside air alone.

Service life

5years

Then refurbishment and resale. Nothing destroyed early.

Renewable electricity

100%

Supply contracted across all four sites.

Heat from the ORT-3 site feeds a district heating network. An energy report is published quarterly and is binding under contract.

Technical audit on site

Clients under contract visit the suites with 24 hours’ notice. Prospects in qualification are received with their technical team, diagrams and readings to hand.