
Authentication factors at every controlled layer, video-surveillance coverage and retention, and the recertification regime that keeps entitlements current. A controlled internal document, released to counterparties where the engagement protocol requires it.

Sections 01–03 set the scope and the layered model. Section 04 is the substantive access-control specification — the factors required at each layer and the mechanism that enforces them. Sections 05–07 cover the governance around those factors: who may authorise access, how it is provisioned, and how it is re-proved and recorded. Sections 08–09 cover surveillance and evidence retention. Sections 10–11 cover detection, response and audit.
Every layer that can be entered requires at least two independent factors, and the factor set changes as the layer becomes more sensitive.
All camera streams retained a minimum of 90 days on site, 180 days for critical zones, with access-control events held 24 months.
Monthly review of privileged and data-hall access, quarterly review of every badge holder, each with a named attestation retained for audit.

The physical security estate at Knowledge Oasis Muscat is specified, supplied and commissioned from the TKH Security Solutions portfolio — Siqura surveillance, TKH access control and the VDG Sense video management system. The official Siqura distributor appointment for the region is held by AlHudebiya International, a company of the founders' group, so the stack is procured and engineered directly rather than through a reseller chain. The appointment is reproduced at section 02.
This document states what is controlled, how identity is proven at each layer, how long evidence is kept, and how entitlements are re-proved on a schedule. It is written to be audited: every commitment names the record that evidences it.
| Status | An internal policy of Prima Artificial Intelligence LLC. It states the standard the Company holds itself to; it is not a marketing document and is not written to a third party’s template. |
|---|---|
| Authority | Issued under the Corporate Governance Charter. Owned jointly by the CISO and the COO; material amendment requires the approval of both. |
| Controlled copies | Executive Leadership Team; Operations Manager and Shift Leads; Facilities; Information Security; the security service provider under contract. |
| Release outside Prima | Released to customers, offtakers, lenders, insurers and certification bodies where an engagement or contractual protocol requires evidence of the Company’s physical-security posture. Release is logged; the document is not published. |
| Review cycle | Annually, and after any security incident, any change of provider, or any material change to the estate. |

This specification covers the physical security of the KOM Oman AI Factory: the site perimeter, the building envelope, the interior zones, the data halls and the racks and customer cages within them. It covers the systems that control and record entry, and the organisation that operates them.
Logical security of customer workloads — network segmentation, identity for compute resources, encryption — sits outside this document and is governed by the customer's own controls and by the Information Security programme referenced in section 11.
| In scope | Site perimeter and vehicle access · building envelope and portals · interior and office zones · data hall airlocks and white space · rack rows, cabinets and customer cages · loading bay and delivery handling · plant rooms, electrical rooms and CDU rooms · the access-control, surveillance and intrusion systems themselves. |
|---|---|
| Out of scope | Customer logical access to compute · customer-owned network and encryption controls · public road and utility corridors outside the site boundary · third-party premises at handover points. |
| Accountability | CISO owns the specification, the recertification regime and the audit programme. COO owns day-to-day operation, officer coverage and alarm response. Procurement owns the vendor agreements. Each controlled layer has a named approving authority under section 05. |

The physical security estate is delivered from the TKH Security Solutions portfolio, a division of the TKH Group. TKH supplies all four disciplines this specification requires — access control, surveillance, intrusion detection and video management — so the estate is built as one integrated system rather than assembled from unrelated vendors.
AlHudebiya International — a company of the founders' group — holds the official distributor appointment for the Siqura portfolio, granted by Siqura B.V. and reproduced overleaf. This is the material point for a customer or lender: the security stack is not bought through a reseller chain. It is specified, procured, commissioned and maintained by a party that holds the vendor relationship directly.
| Discipline | Platform | Role in this specification |
|---|---|---|
| Video managementSection 08 – 09 | VDG Sense (TKH Security) | Recording, retention control per device, video content analysis, failover, evidence export and audit of playback. |
| Surveillance devicesSection 08 | Siqura IP cameras and encoders | Perimeter, portal, aisle and rack-row coverage; tamper detection and image-quality monitoring. |
| Access controlSection 04 – 06 | TKH Security access control | Credential management, factor enforcement per layer, anti-passback, airlock interlocks, event logging. |
| Intrusion detectionSection 10 | TKH Security intrusion | Perimeter intrusion detection, door and contact monitoring, alarm routing into the NOC. |
| Officer coverageSection 10 | Specialist managed service | 24×7 officers, patrol, visitor handling and first physical response, overseen by the COO. |

The certificate below is the vendor-side evidence for section 02. It is reproduced so a customer, auditor or lender can verify the channel position without a separate request. The original is held by AlHudebiya International and available for inspection.
| Grantor | Siqura B.V., Gouda, The Netherlands — part of TKH Security Solutions, a division of the TKH Group. Signed by Roger Decker, Managing Director. |
|---|---|
| Appointee | AlHudebiya International — a company of the founders' group. Countersigned by Taiyab Ali Lashkari, Managing Director. |
| Scope | Official distributor of Siqura products, covering the surveillance and video-management portfolio referenced in section 02. |
| Relevance | Equipment for this facility is procured on distributor terms and commissioned by engineers certified on the portfolio. Vendor escalation runs to the manufacturer rather than through an integrator. |

The site is organised into five concentric layers. Each layer is a separate control point with its own credential set, its own approving authority and its own audit trail. Passing one layer confers no rights at the next — entitlements are granted per layer, not per person.
| Layer | Zone | Boundary and control | Approving authority |
|---|---|---|---|
| L1 | Site perimeterOutermost | Fence line and vehicle gate. No public access. Perimeter intrusion detection, continuous camera coverage and officer patrol. Vehicles admitted against a booked movement and logged. | Security Manager |
| L2 | Building envelopeReception and portals | All external doors and the personnel turnstile. Card and PIN, plus officer visual verification at reception during staffed hours. Anti-passback enforced. | Operations Manager |
| L3 | Interior zoneOffice, NOC, plant rooms | Internal doors segregating office, control room, electrical and mechanical plant. Card and PIN, with the NOC and plant rooms on a separate entitlement to general office space. | Function head |
| L4 | Data hall airlockWhite space entry | Interlocked airlock into each data hall. Card and biometric, single-occupancy interlock, anti-passback, and a mandatory reason code recorded against the entry. | CISO, with the COO |
| L5 | Rack, cabinet, cageInnermost | Electronic cabinet locks and customer cage doors. Card and biometric with per-cabinet entitlement; customer cages additionally require dual authorisation where the customer elects it. | CISO + customer |
The credential used at L2 is not sufficient at L4. The biometric enrolment required for the data hall is held separately from the badge credential, so a lost or lent badge cannot reach white space.
Entitlements are attached to roles, not individuals. A shift engineer holds L1–L5 for the halls on their rotation; a finance user holds L1–L3 office only and cannot be granted L4 without CISO approval.
The access-control and video systems sit on a dedicated, physically separate network with no route to customer compute. Administrative access requires hardware-token MFA.
Controlled doors fail secure on loss of power and release on the fire-alarm signal. Egress is never dependent on a credential; every exit is free-egress and recorded.

Every layer that a person can enter requires at least two independent factors drawn from different categories — something held, something known, something inherent. The factor set strengthens with depth, and the innermost layers require a factor that cannot be transferred between people.
| Layer | Factors required | Category combination | Enforcement |
|---|---|---|---|
| L1 | Booked movement + officer verificationVehicles and deliveries | Authorisation + human check | Gate, patrol, ANPR |
| L2 | Badge + PINPlus officer check when staffed | Have + know | Turnstile, anti-passback |
| L3 | Badge + PINSeparate entitlement per room class | Have + know | Door controller |
| L4 | Badge + biometricPlus reason code at entry | Have + are | Interlocked airlock |
| L5 | Badge + biometric + cabinet releaseDual authorisation on election | Have + are + per-asset grant | Electronic cabinet lock |
| L0 | Named account + hardware tokenAdministrative access | Know + have (FIDO2) | Privileged access platform |

Access is granted through a single request path with a named approver per layer. There is no informal route — an entitlement that does not exist in the access platform does not exist, and a door that opens without a matching record is a reportable incident.
| Stage | Requirement | Record produced |
|---|---|---|
| 01 Request | Raised by the line manager or, for customers, by an authorised customer contact. Names the individual, the layers sought, the business reason and the required end date. | Access request ticket |
| 02 Screening | Identity verification against government photo identification; background screening to the standard applicable to the layers sought; signed acceptance of the site security rules and confidentiality undertaking. | Screening record, signed undertaking |
| 03 Approval | Approved by the authority for each layer under section 03. L4 and L5 require CISO approval; a customer cage additionally requires the customer's authorised contact. | Named approval, timestamped |
| 04 Enrolment | Badge issued with photograph; PIN set by the holder; biometric enrolled in person for L4 and L5. Enrolment is witnessed and the witness recorded. | Enrolment record |
| 05 Activation | Entitlements activated with the approved expiry. Activation is never retrospective and never broader than approved. | Platform entitlement record |
| 06 Revocation | On leaving, on role change, on expiry, or on instruction. Badge recovered, biometric template deleted, entitlements withdrawn. | Revocation record |

No visitor holds an unescorted entitlement beyond the interior zone. A visitor inside a data hall is at all times within sight of a named escort who holds an entitlement for that layer and who remains accountable for the visitor's actions.
| Class | Max layer | Conditions |
|---|---|---|
| Business visitorMeetings, tours | L3, or L4 escorted | Pre-booked, photo ID verified, badge issued for the day, escorted at all times beyond reception, confidentiality undertaking signed at first visit. |
| Customer nomineeOwn cage only | L5 — own assets | Screened and enrolled as a holder under section 05; unescorted within own cage where the customer elects it; no entitlement to any other cage or row. |
| Contractor — routineOEM maintenance, cleaning | L3, or L4 escorted | Company screened, individuals screened, work order raised in advance, entitlement bounded to the work window, tools and media declared on entry. |
| Contractor — criticalElectrical, cooling, fire | L4 escorted | As routine, plus a permit to work approved by the Facilities Manager and a Prima escort present for the duration of the intervention. |
| Auditor or regulatorAssurance visits | As required, escorted | Identity and mandate verified, escorted by the CISO or delegate, scope of access recorded, customer notified where a cage is entered. |

Entitlements are not permanent. Every holder's access is re-proved on a schedule by a named manager who must positively confirm it is still required. Anything not confirmed within the cycle is withdrawn automatically — the default outcome of silence is revocation. Contractor and vendor entitlements are additionally confirmed monthly by Procurement and Facilities.
| Cycle | Population reviewed | Reviewer and required action | Non-response |
|---|---|---|---|
| Monthly | L4 / L5 holders and Layer 0 accounts | Line manager confirms each holder line by line; CISO counter-signs the L4/L5 list and reviews every administrative account and its last use. | Suspended |
| Quarterly | Every badge holder, all layers | Line manager attests to the entitlement set for each direct report; function head attests to the aggregate. | Suspended |
| Quarterly | Customer nominee lists, per customer | Prima issues the current nominee and entitlement list; the customer's authorised contact confirms or amends in writing. | Escalated, then suspended |
| Annual | Full entitlement audit, independent | Information Security reconciles the platform against HR and contract records, samples entitlements to source approvals, reports exceptions to the COO. | Board-reported |
| Contents | Cycle identifier and period · every holder in scope with entitlements held at review · the named reviewer and attestation · the decision per line — retained, reduced, withdrawn · every change with its timestamp · exceptions and disposition · the reviewer's electronic signature. |
|---|---|
| Retention | 24 months minimum, or the term of the relevant Service Order Form plus 24 months, whichever is longer. |
| Immutability | A closed cycle record cannot be edited. Corrections are made by a superseding entry that references the original; both remain retrievable. |
| Visibility | A customer may request the record for the population holding access to its own cage or rack row, for any cycle within retention, at no charge — and so may its auditor, a lender's technical adviser or a regulator, under the confidentiality terms of the Master Services Agreement. |

Surveillance is continuous rather than motion-triggered, so the record is complete and a gap is detectable. Coverage is specified so that any route from the perimeter to a rack can be reconstructed end to end from overlapping fields of view, with no unobserved segment.
| Layer | Zone | Coverage requirement | Classification |
|---|---|---|---|
| L1 | Perimeter and vehicle gate | Continuous coverage of the full fence line with overlapping fields of view; gate coverage capable of identifying vehicle, plate and occupants. | Critical |
| L2 | Portals and reception | Every external door and the turnstile, at a resolution sufficient for facial identification at the point of credential presentation. | Critical |
| L3 | Interior circulation and plant | Corridors, stairwells, electrical and mechanical plant rooms, CDU rooms and the loading bay. | Standard |
| L4 | Data hall airlock | Both faces of each airlock, capable of establishing single occupancy and identifying the person authenticating. | Critical |
| L5 | Aisles, rack rows and cages | Every cold and hot aisle along its full length, and each customer cage door, at a resolution sufficient to establish which cabinet was opened. | Critical |
Continuous 24×7 recording on all cameras. Hot-standby failover assumes recording in under 90 seconds on a server failure, and recording resumes automatically after a power interruption without operator action.
Devices report tamper, obstruction, defocus, exposure loss and field-of-view change. A camera that stops delivering a usable image raises an alarm rather than failing silently.
Perimeter intrusion detection at L1, plate recognition at the vehicle gate, and loitering and direction analytics at portals. Detections drive predefined macro actions — record, reposition, present to the operator.
The surveillance estate runs on a dedicated network segregated from customer compute, on protected power with the same N+1 provisioning as the critical load, with storage sized for the full retention period.

Retention is committed, not best-effort: storage is sized for the full period at the specified resolution and frame rate, so the window cannot be silently shortened by capacity pressure. Retention is enforced per device — which is how critical zones are held longer than standard zones on one system.
| Record class | Scope | Retention |
|---|---|---|
| Video — standard zones (L3) | All cameras, continuous recording | 90 days |
| Video — critical zones (L1, L2, L4, L5) | Perimeter, portals, airlocks, aisles, rack rows and cage doors | 180 days |
| Access-control events | Every read at every layer, including denials and duress | 24 months |
| Intrusion and alarm events | Detection, acknowledgement, response and closure | 24 months |
| Visitor and escort records | Identity verified, host, escort, layers entered, equipment declared | 24 months |
| Recertification records | Cycle attestations and entitlement changes | 24 months + |
| Under legal or contractual hold | Any record subject to a hold notice, investigation or dispute | Until released |

Storage media is the one asset class that can carry customer data out of the facility in a pocket. The controlling rule is short: no storage medium leaves the site in a readable state, and no medium is treated as sanitised without a record that proves it.
Scope covers customer media inside GPU nodes and the storage tier; Prima's own media in the access-control, surveillance, BMS and EPMS systems; and transient media — spares, RMA returns, removable devices and printed material.
| Medium | Clear | Purge | Destroy |
|---|---|---|---|
| Magnetic HDDSATA, SAS | Single-pass overwrite, verified | Degauss to NSA/CSS-listed field strength | Disintegration to ≤ 25 mm, or degauss then deform |
| Flash SSD / NVMeNode and storage tier | Not relied on alone | Cryptographic erase, or the ATA / NVMe sanitize command, verified | Disintegration to a nominal 2 mm particle |
| Self-encrypting drive | — | Cryptographic erase by destruction of the media encryption key | As flash |
| LTO tape | Overwrite | Degauss | Shred or incinerate |
| Removable flashUSB, SD | Overwrite | Cryptographic erase where supported | Disintegration to 2 mm |
| Surveillance and BMS recorders | Overwrite | By underlying media type | As underlying media |
| Printed material, badges, labels | — | — | Cross-cut shred, on-site bins under seal |

| Failure in service | Purge where the device still responds to command; Destroy where it does not. A failed drive holding customer data is never returned under RMA — the warranty claim is settled on a destruction certificate. |
|---|---|
| Technology refresh | Purge, verified, before re-use within the same customer's estate. Re-use across customers requires Destroy. |
| Decommission or contract end | Customer election: Destroy on site as the default, Purge and return, or physical return unsanitised under the customer's own chain of custody. |
| Customer instruction | Executed within 5 business days of written instruction from an authorised contact, with certificates issued on completion. |
| Suspected compromise | Destroy, with the medium held under evidential hold until the investigation closes. |

Prima operates in the Sultanate of Oman and complies with lawful instruction. The position is stated in advance and is deliberately narrow: lawful authority is met, nothing is volunteered, scope is held to what the instrument compels, and the affected customer is told — unless telling is itself prohibited.
| Request | Prima's response | Customer notified |
|---|---|---|
| Access and video records | Produced to the named scope only; export logged on the custody register under section 09. | Before compliance where lawful, else within 24 h |
| Entry to common areasL1–L3 | Identification and purpose recorded; escorted throughout; logged as a visitor event. | If a customer's assets are approached |
| Entry to a data hallL4 | Written instrument or life-safety emergency; escorted by the CISO or delegate; video placed under hold; inventory of anything touched. | Within 4 hours |
| Entry to a cage or rackL5 | Instrument must name the customer. The customer's own lock is not defeated absent that instrument. Full video hold. | Before compliance where lawful, else within 4 h |
| Seizure of equipment | Warrant naming the equipment; inventory and photographs before release; officer's receipt obtained. | Immediately · in writing within 24 h |
| Emergency respondersFire, medical | Life safety prevails — admitted immediately, escorted where practicable, video retained under hold. | Within 4 hours where its zone was entered |
| Regulatory inspection | Mandate verified; escorted by the CISO; scope and findings recorded. | Where it touches its assets |


Detection is layered in the same way as access. An intrusion attempt should be detected at the perimeter, verified on video within seconds, and met by an officer before it reaches the building envelope. Alarms escalate on the clock without waiting for a human decision.
| Layer | Detection method | Verification and first response |
|---|---|---|
| L1 | Perimeter intrusion detectionVideo analytics, fence sensing | Detection presents the camera to the operator automatically; officer dispatched to the sector; vehicle gate held. |
| L2 | Door contacts, forced and held-openTailgate analytics at the turnstile | Alarm at the officer post and the NOC; reception verifies on video; portal locked down on a forced-entry signal. |
| L3 | Door contacts on plant and control roomsUnauthorised-attempt alarms | NOC verifies against the entitlement record and video; shift lead attends where no matching authorisation exists. |
| L4 | Airlock interlock breach, anti-passbackOccupancy mismatch | Airlock held closed, alarm to NOC and officer post, shift lead attends the hall in person. |
| L5 | Cabinet lock tamper, cage door held openUnauthorised cabinet release | Immediate alarm, video preserved automatically for the event window, affected customer notified under section 13. |
Escalation is time-based and automatic. A security alarm classifies as P1 under the Service Level Agreement where it involves an unauthorised presence beyond L3, a forced entry at any layer, or a tamper at L5 — and inherits the P1 response, update and root-cause obligations set out there.

The controls here are designed to be evidenced against recognised frameworks and tested by a third party — every control names the record that proves it.
| ISO/IEC 27001 | The physical and environmental security controls of Annex A are the design basis for sections 03–12. Certification of the operating entity is targeted; the control design does not depend on it. |
|---|---|
| SOC 2 | Access criteria are the design basis for the provisioning, recertification and audit-logging requirements in sections 05 and 07. A Type 2 report is targeted once the facility has adequate operating history. |
| Omani requirements | Operated in accordance with applicable Omani law on surveillance, personal data and the protection of critical infrastructure, under a published notice. Where a customer is subject to a sectoral standard, Prima completes that customer's control questionnaire and supports its audit against these controls. |
| Reported | Detail |
|---|---|
| Access activity | Entries by layer, denials, anti-passback and duress events, break-glass use with disposition. |
| Entitlement position | Holders by layer, entitlements granted, reduced and withdrawn, recertification completion rate, exceptions. |
| Surveillance health | Proportion of cameras delivering a usable image, recording gaps with cause and duration, tamper events. |
| Security events | All events with classification, response times against the ladder in section 12, root-cause status; and escorted visits touching the customer's assets. |
For questions on this specification, the control design, or to arrange an audit of the estate. Commitments become contractual on incorporation into an executed Master Services Agreement.