# Alcora Labs > Continuous tenant-isolation verification for GPU clusters. Alcora Labs designs secure multi-tenant GPU clusters and continuously proves that every tenant stays isolated, from the fabric to the firmware. Now onboarding design partners. ## The problem Shared GPU clusters run workloads for banks, governments and AI labs side by side. Recent independent testing of GPU cloud providers found tenants able to see other tenants' infrastructure, read across tenant boundaries and reach management networks, often through default settings rather than sophisticated attacks. Configurations drift. Nodes get recycled. A one-off audit is out of date the day after it ends. Providers need continuous evidence, and their customers increasingly ask for it. ## How it works A canary tenant runs from an ordinary customer's position every time a node is provisioned or recycled, and on a schedule. It asks one question: what can one tenant see, reach or change about another? It checks every shared boundary: - Fabric: InfiniBand partitions and keys, RoCE and Ethernet segmentation - Management plane: BMC, IPMI and Redfish reachability - DPUs and SmartNICs: operating mode and host access - Orchestration: Kubernetes and Slurm exposure, network policy, shared control planes - Storage and monitoring: per-tenant separation in the backend, not just the dashboard - Node reuse: disk wipe, DPU reflash and firmware state between tenants - Software: known-vulnerable drivers, container toolkits, runtimes and firmware Failures raise an alert with the exact fix and a re-test. Each tenant handoff produces an isolation report the provider can share with that customer. ## Services - Secure cluster design: for organisations building shared GPU clusters. Isolation designed in from the start, from fabric partitioning to management-network separation, then verified once the cluster is live. - Baseline isolation audit: a full, scoped assessment of an existing cluster, with findings, fixes and a re-test. - Continuous verification: ongoing checks on every node handoff, with per-tenant reports for your customers. Vendor-neutral: NVIDIA and AMD, InfiniBand and Ethernet, Kubernetes and Slurm. ## How we work - No test runs without a signed, written scope. - Your engineers stay in the loop. - Findings go only to you. Nothing is ever published without your written consent. - Checks run inside your environment, so your data stays in-country. ## About Alcora Labs was founded by Saad Khan. He has five years of experience in AWS and cloud infrastructure, a background in electrical engineering, and comes from Instec, a cybersecurity firm that has operated across Pakistan and the Gulf since the 1980s. Named after the razorbill: a seabird that nests in crowded colonies, each pair holding its own ledge. ## Contact - [Book a 20-minute call](https://alcoralabs.com/contact.html) - Email: saad@alcoralabs.com ## Pages - [Home](https://alcoralabs.com/): what Alcora Labs does, how it works, services, approach and founder - [Book a call](https://alcoralabs.com/contact.html): contact form - [Security](https://alcoralabs.com/security.html): vulnerability disclosure policy - [Privacy](https://alcoralabs.com/privacy.html): how this website handles information