Prima — Physical Security & Access Control · KOM Muscat · A4 · 19pp · Draft v0.2
DRAFT
Draft
Part ofPetroCompute
Internal Policy · Physical Security & Access Control
KOM Oman AI Factory
five-layer access control,
surveillance and audit

Authentication factors at every controlled layer, video-surveillance coverage and retention, and the recertification regime that keeps entitlements current. A controlled internal document, released to counterparties where the engagement protocol requires it.

Document
PRM-SEC-2026-001
Version
0.2 — Draft
Issued
July 2026
Owner
CISO, with the COO
Classification
Internal — controlled
5
Controlled security
layers
2FA min
Independent factors at
every controlled layer
90days
Minimum CCTV
retention, all cameras
24×7
Monitoring and
officer coverage
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  01 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 02 / 19
How to read this document

Sections 01–03 set the scope and the layered model. Section 04 is the substantive access-control specification — the factors required at each layer and the mechanism that enforces them. Sections 05–07 cover the governance around those factors: who may authorise access, how it is provisioned, and how it is re-proved and recorded. Sections 08–09 cover surveillance and evidence retention. Sections 10–11 cover detection, response and audit.

Multi-factor per layer

Every layer that can be entered requires at least two independent factors, and the factor set changes as the layer becomes more sensitive.

Section 04
90+ day retention

All camera streams retained a minimum of 90 days on site, 180 days for critical zones, with access-control events held 24 months.

Section 09
Recertification records

Monthly review of privileged and data-hall access, quarterly review of every badge holder, each with a named attestation retained for audit.

Section 07
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  02 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 03 / 19
Basis of this document

The physical security estate at Knowledge Oasis Muscat is specified, supplied and commissioned from the TKH Security Solutions portfolio — Siqura surveillance, TKH access control and the VDG Sense video management system. The official Siqura distributor appointment for the region is held by AlHudebiya International, a company of the founders' group, so the stack is procured and engineered directly rather than through a reseller chain. The appointment is reproduced at section 02.

This document states what is controlled, how identity is proven at each layer, how long evidence is kept, and how entitlements are re-proved on a schedule. It is written to be audited: every commitment names the record that evidences it.

Status and distributionControlled document
StatusAn internal policy of Prima Artificial Intelligence LLC. It states the standard the Company holds itself to; it is not a marketing document and is not written to a third party’s template.
AuthorityIssued under the Corporate Governance Charter. Owned jointly by the CISO and the COO; material amendment requires the approval of both.
Controlled copiesExecutive Leadership Team; Operations Manager and Shift Leads; Facilities; Information Security; the security service provider under contract.
Release outside PrimaReleased to customers, offtakers, lenders, insurers and certification bodies where an engagement or contractual protocol requires evidence of the Company’s physical-security posture. Release is logged; the document is not published.
Review cycleAnnually, and after any security incident, any change of provider, or any material change to the estate.
NoteCompanion to the Service Level Agreement (PRM-SLA-2026-001): availability, environmental and incident-response commitments are stated there, and security incidents escalate on the same ladder. Version 0.1 is issued for evaluation — design quantities and device selections are indicative and finalised at detailed design.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  03 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 04 / 19
01Scope, boundaries and security objectives

This specification covers the physical security of the KOM Oman AI Factory: the site perimeter, the building envelope, the interior zones, the data halls and the racks and customer cages within them. It covers the systems that control and record entry, and the organisation that operates them.

Logical security of customer workloads — network segmentation, identity for compute resources, encryption — sits outside this document and is governed by the customer's own controls and by the Information Security programme referenced in section 11.

Security objectivesWhat the estate is built to achieve
  1. No unaccompanied presence without an entitlement. Every person inside a controlled layer is either an entitled holder authenticated at that layer, or an escorted visitor recorded against a named host.
  2. Identity proven, not asserted. A single credential never opens a controlled layer. Each controlled layer requires at least two independent factors, and the data hall and rack layers require a biometric factor that cannot be lent or copied.
  3. Every event recorded and reconstructable. Access grants, denials, alarms and video are recorded to a common timeline so any event can be reconstructed from independent sources.
  4. Entitlements decay by default. Access is time-bounded and must be positively re-affirmed by a named manager on a schedule; anything not re-affirmed is withdrawn.
  5. Customer isolation. A customer's cage or rack row is accessible only to that customer's nominated holders and to a defined list of Prima roles, each recorded separately.
Boundaries
In scopeSite perimeter and vehicle access · building envelope and portals · interior and office zones · data hall airlocks and white space · rack rows, cabinets and customer cages · loading bay and delivery handling · plant rooms, electrical rooms and CDU rooms · the access-control, surveillance and intrusion systems themselves.
Out of scopeCustomer logical access to compute · customer-owned network and encryption controls · public road and utility corridors outside the site boundary · third-party premises at handover points.
AccountabilityCISO owns the specification, the recertification regime and the audit programme. COO owns day-to-day operation, officer coverage and alarm response. Procurement owns the vendor agreements. Each controlled layer has a named approving authority under section 05.
PrincipleWhere this specification and a customer's own security requirement differ, the stricter control applies for that customer's cage or rack row, recorded as a variation to the Service Order Form.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  04 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 05 / 19
02Delivery model — TKH Security Solutions / SiquraDirect vendor position

The physical security estate is delivered from the TKH Security Solutions portfolio, a division of the TKH Group. TKH supplies all four disciplines this specification requires — access control, surveillance, intrusion detection and video management — so the estate is built as one integrated system rather than assembled from unrelated vendors.

AlHudebiya International — a company of the founders' group — holds the official distributor appointment for the Siqura portfolio, granted by Siqura B.V. and reproduced overleaf. This is the material point for a customer or lender: the security stack is not bought through a reseller chain. It is specified, procured, commissioned and maintained by a party that holds the vendor relationship directly.

What the position delivers
  • Direct supply — commercial. Equipment procured on distributor terms, with no intermediate margin and no dependency on a third-party integrator's roadmap or stock position.
  • In-house engineering — technical. Design, commissioning and configuration performed by engineers already certified on the portfolio, not learned on this project.
  • Lifecycle continuity — operational. Firmware, spares and support handled on the vendor channel for the life of the asset, escalating into the manufacturer rather than a reseller.
System componentsIndicative selection, finalised at detailed design
DisciplinePlatformRole in this specification
Video managementSection 08 – 09VDG Sense (TKH Security)Recording, retention control per device, video content analysis, failover, evidence export and audit of playback.
Surveillance devicesSection 08Siqura IP cameras and encodersPerimeter, portal, aisle and rack-row coverage; tamper detection and image-quality monitoring.
Access controlSection 04 – 06TKH Security access controlCredential management, factor enforcement per layer, anti-passback, airlock interlocks, event logging.
Intrusion detectionSection 10TKH Security intrusionPerimeter intrusion detection, door and contact monitoring, alarm routing into the NOC.
Officer coverageSection 10Specialist managed service24×7 officers, patrol, visitor handling and first physical response, overseen by the COO.
Capabilities relied onVDG Sense video management system
·Retention time configurable per device, which is how the differential retention in section 09 is enforced.
·Hot-standby failover in under 90 seconds, so recording continues through a server failure.
·Tamper detection and image-quality monitoring — contrast, exposure, focus, field-of-view change.
·Video content analysis including perimeter intrusion detection and plate recognition.
·Operator interface in Arabic and English, for a resident Omani operations team.
EvidenceThe distributor appointment is reproduced on the following page: certificate issued by Siqura B.V. in favour of AlHudebiya International, signed by the Managing Directors of both parties.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  05 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 06 / 19
02Delivery model — appointment evidenceSiqura B.V. certificate

The certificate below is the vendor-side evidence for section 02. It is reproduced so a customer, auditor or lender can verify the channel position without a separate request. The original is held by AlHudebiya International and available for inspection.

Siqura B.V. certificate appointing AlHudebiya International as an official distributor of Siqura products
Certificate of official distributorship — Siqura B.V.Issued 12 June 2016
GrantorSiqura B.V., Gouda, The Netherlands — part of TKH Security Solutions, a division of the TKH Group. Signed by Roger Decker, Managing Director.
AppointeeAlHudebiya International — a company of the founders' group. Countersigned by Taiyab Ali Lashkari, Managing Director.
ScopeOfficial distributor of Siqura products, covering the surveillance and video-management portfolio referenced in section 02.
RelevanceEquipment for this facility is procured on distributor terms and commissioned by engineers certified on the portfolio. Vendor escalation runs to the manufacturer rather than through an integrator.
NoteThe appointment covers the Siqura surveillance and video-management portfolio. Access-control and intrusion products are drawn from the wider TKH Security Solutions range, procured on the same vendor channel.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  06 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 07 / 19
03Layered security modelFive controlled layers

The site is organised into five concentric layers. Each layer is a separate control point with its own credential set, its own approving authority and its own audit trail. Passing one layer confers no rights at the next — entitlements are granted per layer, not per person.

LayerZoneBoundary and controlApproving authority
L1Site perimeterOutermostFence line and vehicle gate. No public access. Perimeter intrusion detection, continuous camera coverage and officer patrol. Vehicles admitted against a booked movement and logged.Security Manager
L2Building envelopeReception and portalsAll external doors and the personnel turnstile. Card and PIN, plus officer visual verification at reception during staffed hours. Anti-passback enforced.Operations Manager
L3Interior zoneOffice, NOC, plant roomsInternal doors segregating office, control room, electrical and mechanical plant. Card and PIN, with the NOC and plant rooms on a separate entitlement to general office space.Function head
L4Data hall airlockWhite space entryInterlocked airlock into each data hall. Card and biometric, single-occupancy interlock, anti-passback, and a mandatory reason code recorded against the entry.CISO, with the COO
L5Rack, cabinet, cageInnermostElectronic cabinet locks and customer cage doors. Card and biometric with per-cabinet entitlement; customer cages additionally require dual authorisation where the customer elects it.CISO + customer
Design consequences of the model
Independence of factors

The credential used at L2 is not sufficient at L4. The biometric enrolment required for the data hall is held separately from the badge credential, so a lost or lent badge cannot reach white space.

Enforced in the access platform
Least privilege by role

Entitlements are attached to roles, not individuals. A shift engineer holds L1–L5 for the halls on their rotation; a finance user holds L1–L3 office only and cannot be granted L4 without CISO approval.

Role-based, reviewed quarterly
Segregation of the security estate

The access-control and video systems sit on a dedicated, physically separate network with no route to customer compute. Administrative access requires hardware-token MFA.

Layer 0 — administrative
Fail-secure, life-safe

Controlled doors fail secure on loss of power and release on the fire-alarm signal. Egress is never dependent on a credential; every exit is free-egress and recorded.

Interlocked with fire detection
Layer 0Administrative access to the security systems is treated as a sixth, logical layer: named accounts only, hardware-token MFA, no shared credentials, all configuration changes logged and reviewed monthly by the CISO. A person with L5 physical access does not thereby hold any administrative right over the systems that record them.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  07 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 08 / 19
04Access control — authentication factors per layerTwo factors minimum

Every layer that a person can enter requires at least two independent factors drawn from different categories — something held, something known, something inherent. The factor set strengthens with depth, and the innermost layers require a factor that cannot be transferred between people.

LayerFactors requiredCategory combinationEnforcement
L1Booked movement + officer verificationVehicles and deliveriesAuthorisation + human checkGate, patrol, ANPR
L2Badge + PINPlus officer check when staffedHave + knowTurnstile, anti-passback
L3Badge + PINSeparate entitlement per room classHave + knowDoor controller
L4Badge + biometricPlus reason code at entryHave + areInterlocked airlock
L5Badge + biometric + cabinet releaseDual authorisation on electionHave + are + per-asset grantElectronic cabinet lock
L0Named account + hardware tokenAdministrative accessKnow + have (FIDO2)Privileged access platform
Rules that apply to every layer
  1. No credential sharing. Badges are issued to a named individual, carry a photograph, and are void on transfer. A biometric enrolment cannot be delegated. Sharing is a disciplinary matter and a reportable security event.
  2. Anti-passback. A credential presented for entry cannot be presented again for entry without an intervening exit. Tailgating attempts are alarmed at L2 and L4 and reviewed against video.
  3. Single occupancy at the airlock. The L4 interlock admits one authenticated person per cycle. Equipment movements use the loading route under escort, not the personnel airlock.
  4. Reason code at L4. Data hall entry records a reason — maintenance, installation, incident, customer visit, audit — selected at the reader and reconciled against the ticket record monthly.
  5. Time-bounding. Every entitlement carries an expiry. Permanent staff entitlements expire at the next recertification cycle; contractor and visitor entitlements expire at the end of the booked window and cannot be extended at the reader.
  6. Denial handling. Three consecutive denials on one credential locks it and raises an alarm to the NOC. Unlock requires identity verification by the Security Manager, recorded.
  7. Duress. A duress PIN variant is available at L2 and L3 and raises a silent alarm to the NOC and the officer post.
Customer electionA customer may elect dual authorisation at L5 for its own cage — any entry requires two entitled holders authenticating within a short window, at least one of whom may be required to be a customer nominee. Where elected, the requirement is recorded in the Service Order Form and enforced in the platform.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  08 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 09 / 19
05Access control — authorisation and provisioningRequest · approve · issue · revoke

Access is granted through a single request path with a named approver per layer. There is no informal route — an entitlement that does not exist in the access platform does not exist, and a door that opens without a matching record is a reportable incident.

StageRequirementRecord produced
01 RequestRaised by the line manager or, for customers, by an authorised customer contact. Names the individual, the layers sought, the business reason and the required end date.Access request ticket
02 ScreeningIdentity verification against government photo identification; background screening to the standard applicable to the layers sought; signed acceptance of the site security rules and confidentiality undertaking.Screening record, signed undertaking
03 ApprovalApproved by the authority for each layer under section 03. L4 and L5 require CISO approval; a customer cage additionally requires the customer's authorised contact.Named approval, timestamped
04 EnrolmentBadge issued with photograph; PIN set by the holder; biometric enrolled in person for L4 and L5. Enrolment is witnessed and the witness recorded.Enrolment record
05 ActivationEntitlements activated with the approved expiry. Activation is never retrospective and never broader than approved.Platform entitlement record
06 RevocationOn leaving, on role change, on expiry, or on instruction. Badge recovered, biometric template deleted, entitlements withdrawn.Revocation record
Revocation timeframesCommitted, measured monthly
Termination or dismissal
4 business hours
All layers withdrawn from notification by HR or the customer contact.
Role change
2 business days
Entitlements re-based to the new role; nothing carried across by default.
Contractor or visitor
Automatic
Expires at the end of the booked window with no manual step required.
Standing constraints
  • Separation of duties. The person who approves an entitlement may not be the person who provisions it. Approval sits with the layer authority; provisioning sits with the security administration function.
  • No standing privileged access. Administrative access to the access-control and video platforms is granted per task and expires; there are no permanent administrator sessions.
  • Emergency access. A break-glass entitlement exists for life-safety and critical-incident response. Use is alarmed in real time, reviewed by the CISO within one business day, and reported to the affected customer where a cage was entered.
  • Customer nominees. Each customer maintains a nominee list with Prima. Changes take effect only on written instruction from an authorised contact and are confirmed back in writing.
  • Lost credentials. Reported immediately; the credential is voided on report, not on replacement. A replacement requires re-verification of identity.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  09 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 10 / 19
06Visitor, contractor and escort controlEscorted at all times beyond L3

No visitor holds an unescorted entitlement beyond the interior zone. A visitor inside a data hall is at all times within sight of a named escort who holds an entitlement for that layer and who remains accountable for the visitor's actions.

Visitor classes
ClassMax layerConditions
Business visitorMeetings, toursL3, or L4 escortedPre-booked, photo ID verified, badge issued for the day, escorted at all times beyond reception, confidentiality undertaking signed at first visit.
Customer nomineeOwn cage onlyL5 — own assetsScreened and enrolled as a holder under section 05; unescorted within own cage where the customer elects it; no entitlement to any other cage or row.
Contractor — routineOEM maintenance, cleaningL3, or L4 escortedCompany screened, individuals screened, work order raised in advance, entitlement bounded to the work window, tools and media declared on entry.
Contractor — criticalElectrical, cooling, fireL4 escortedAs routine, plus a permit to work approved by the Facilities Manager and a Prima escort present for the duration of the intervention.
Auditor or regulatorAssurance visitsAs required, escortedIdentity and mandate verified, escorted by the CISO or delegate, scope of access recorded, customer notified where a cage is entered.
Escort obligations
  1. One escort, bounded party. An escort may accompany no more than four visitors within a data hall. Larger parties require additional escorts, recorded individually.
  2. Line of sight. The escort maintains continuous line of sight. Loss of sight of an escorted visitor is a reportable security event and is reviewed against video.
  3. No credential lending. The escort authenticates for the party at each layer. A visitor never holds a credential that opens L4 or L5.
  4. Media and equipment. Cameras, removable media and tooling are declared on entry and reconciled on exit. Photography inside white space requires prior written approval and, where another customer's assets are in view, that customer's consent.
  5. Accountability. The escort is recorded as accountable for the visit and signs the visit record on exit. The record names both parties and the areas entered.
RecordVisitor records — identity verified, host, escort, layers entered, entry and exit times, declared equipment — are retained for 24 months and are available to a customer for any visit that touched its cage or rack row.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  10 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 11 / 19
07Access recertification and recordsPositive re-affirmation

Entitlements are not permanent. Every holder's access is re-proved on a schedule by a named manager who must positively confirm it is still required. Anything not confirmed within the cycle is withdrawn automatically — the default outcome of silence is revocation. Contractor and vendor entitlements are additionally confirmed monthly by Procurement and Facilities.

Recertification cyclesCommitted frequencies
CyclePopulation reviewedReviewer and required actionNon-response
MonthlyL4 / L5 holders and Layer 0 accountsLine manager confirms each holder line by line; CISO counter-signs the L4/L5 list and reviews every administrative account and its last use.Suspended
QuarterlyEvery badge holder, all layersLine manager attests to the entitlement set for each direct report; function head attests to the aggregate.Suspended
QuarterlyCustomer nominee lists, per customerPrima issues the current nominee and entitlement list; the customer's authorised contact confirms or amends in writing.Escalated, then suspended
AnnualFull entitlement audit, independentInformation Security reconciles the platform against HR and contract records, samples entitlements to source approvals, reports exceptions to the COO.Board-reported
The recertification recordRetained and provable · platform-generated
ContentsCycle identifier and period · every holder in scope with entitlements held at review · the named reviewer and attestation · the decision per line — retained, reduced, withdrawn · every change with its timestamp · exceptions and disposition · the reviewer's electronic signature.
Retention24 months minimum, or the term of the relevant Service Order Form plus 24 months, whichever is longer.
ImmutabilityA closed cycle record cannot be edited. Corrections are made by a superseding entry that references the original; both remain retrievable.
VisibilityA customer may request the record for the population holding access to its own cage or rack row, for any cycle within retention, at no charge — and so may its auditor, a lender's technical adviser or a regulator, under the confidentiality terms of the Master Services Agreement.
Continuous controls between cycles
  • Dormancy. A credential unused for 60 days at L4 or L5 is suspended automatically and requires manager re-approval to restore.
  • Anomaly review. Out-of-pattern access — unusual hours, unusual hall, high frequency — is flagged weekly to the CISO and reconciled against tickets.
  • Leaver reconciliation. HR leaver and contract-end feeds are reconciled against live entitlements weekly, independent of the review cycles.
CommitmentThe recertification completion rate and entitlements withdrawn are reported monthly; a cycle closing with outstanding attestations is an exception, with those entitlements already suspended.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  11 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 12 / 19
08Video surveillance — coverage and systemContinuous, 24×7

Surveillance is continuous rather than motion-triggered, so the record is complete and a gap is detectable. Coverage is specified so that any route from the perimeter to a rack can be reconstructed end to end from overlapping fields of view, with no unobserved segment.

Coverage specification
LayerZoneCoverage requirementClassification
L1Perimeter and vehicle gateContinuous coverage of the full fence line with overlapping fields of view; gate coverage capable of identifying vehicle, plate and occupants.Critical
L2Portals and receptionEvery external door and the turnstile, at a resolution sufficient for facial identification at the point of credential presentation.Critical
L3Interior circulation and plantCorridors, stairwells, electrical and mechanical plant rooms, CDU rooms and the loading bay.Standard
L4Data hall airlockBoth faces of each airlock, capable of establishing single occupancy and identifying the person authenticating.Critical
L5Aisles, rack rows and cagesEvery cold and hot aisle along its full length, and each customer cage door, at a resolution sufficient to establish which cabinet was opened.Critical
System characteristicsVDG Sense · Siqura devices
Recording continuity

Continuous 24×7 recording on all cameras. Hot-standby failover assumes recording in under 90 seconds on a server failure, and recording resumes automatically after a power interruption without operator action.

Gap detection alarmed to the NOC
Tamper and quality monitoring

Devices report tamper, obstruction, defocus, exposure loss and field-of-view change. A camera that stops delivering a usable image raises an alarm rather than failing silently.

Alarmed, not merely logged
Analytics

Perimeter intrusion detection at L1, plate recognition at the vehicle gate, and loitering and direction analytics at portals. Detections drive predefined macro actions — record, reposition, present to the operator.

Event-driven response
Isolation and resilience

The surveillance estate runs on a dedicated network segregated from customer compute, on protected power with the same N+1 provisioning as the critical load, with storage sized for the full retention period.

No route to customer networks
Monitoring
  • Continuously staffed. Surveillance is monitored 24×7 from the Network Operations Centre alongside the officer post; there is no unattended period.
  • Camera health as a service metric. The proportion of cameras delivering a usable image is measured and reported monthly; a critical-zone camera out of service for more than 24 hours is a reportable exception.
  • Correlated timeline. Video, access-control events and intrusion alarms share a synchronised clock, so an access grant and the corresponding footage align without manual reconciliation.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  12 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 13 / 19
09Video surveillance — retention, integrity and disclosure90 days minimum

Retention is committed, not best-effort: storage is sized for the full period at the specified resolution and frame rate, so the window cannot be silently shortened by capacity pressure. Retention is enforced per device — which is how critical zones are held longer than standard zones on one system.

Retention scheduleCommitted minimums
Record classScopeRetention
Video — standard zones (L3)All cameras, continuous recording90 days
Video — critical zones (L1, L2, L4, L5)Perimeter, portals, airlocks, aisles, rack rows and cage doors180 days
Access-control eventsEvery read at every layer, including denials and duress24 months
Intrusion and alarm eventsDetection, acknowledgement, response and closure24 months
Visitor and escort recordsIdentity verified, host, escort, layers entered, equipment declared24 months
Recertification recordsCycle attestations and entitlement changes24 months +
Under legal or contractual holdAny record subject to a hold notice, investigation or disputeUntil released
Integrity of the record
  1. No early deletion. Footage cannot be deleted before its retention expiry. There is no operator function to purge a period, and no administrative account holds that right unilaterally.
  2. Export under dual control. Evidence export requires two authorised persons, one being the CISO or delegate. Each export is logged with requester, reason, period and cameras.
  3. Playback is audited. Every playback session is logged with the operator, the period viewed and the cameras accessed. Reviewing footage is itself an auditable act.
  4. Verifiable copies and custody. Exported evidence carries a cryptographic hash and manifest so a recipient can establish it has not been altered; external releases are recorded on a custody register naming recipient, authority and date.
  5. Gap accountability. Any interruption in recording is alarmed, ticketed and reported monthly with cause and duration — treated as a security event, not a technical footnote.
Disclosure to customers and third parties
  • Customer request. Footage and access records relating to its own cage or rack row, for any period within retention — answered within 5 business days at no charge.
  • Third-party privacy. Where a request would expose another customer's assets or personnel the export is masked or the frame restricted; no customer receives footage revealing another's operations.
  • Legal and regulatory. Disclosure to authorities only on lawful instruction, recorded on the custody register and notified to any affected customer unless notification is itself prohibited.
PrivacySurveillance is operated for facility security only: no cameras in areas with a reasonable expectation of privacy, no use for performance management, and a published notice consistent with Omani data-protection requirements.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  13 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 14 / 19
10Media sanitisation and destructionNIST SP 800-88 Rev. 1

Storage media is the one asset class that can carry customer data out of the facility in a pocket. The controlling rule is short: no storage medium leaves the site in a readable state, and no medium is treated as sanitised without a record that proves it.

Scope covers customer media inside GPU nodes and the storage tier; Prima's own media in the access-control, surveillance, BMS and EPMS systems; and transient media — spares, RMA returns, removable devices and printed material.

Method by media typeClear · Purge · Destroy
MediumClearPurgeDestroy
Magnetic HDDSATA, SASSingle-pass overwrite, verifiedDegauss to NSA/CSS-listed field strengthDisintegration to ≤ 25 mm, or degauss then deform
Flash SSD / NVMeNode and storage tierNot relied on aloneCryptographic erase, or the ATA / NVMe sanitize command, verifiedDisintegration to a nominal 2 mm particle
Self-encrypting driveCryptographic erase by destruction of the media encryption keyAs flash
LTO tapeOverwriteDegaussShred or incinerate
Removable flashUSB, SDOverwriteCryptographic erase where supportedDisintegration to 2 mm
Surveillance and BMS recordersOverwriteBy underlying media typeAs underlying media
Printed material, badges, labelsCross-cut shred, on-site bins under seal
NoteOverwrite is not sanitisation on flash. NIST 800-88 does not accept a Clear-class overwrite as sufficient for SSD or NVMe, because wear levelling and over-provisioning leave blocks the host cannot address. Prima's default for all flash is Purge by cryptographic erase, and Destroy on device failure or on customer instruction.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  14 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 15 / 19
10Media sanitisation — continued
Which action applies
Failure in servicePurge where the device still responds to command; Destroy where it does not. A failed drive holding customer data is never returned under RMA — the warranty claim is settled on a destruction certificate.
Technology refreshPurge, verified, before re-use within the same customer's estate. Re-use across customers requires Destroy.
Decommission or contract endCustomer election: Destroy on site as the default, Purge and return, or physical return unsanitised under the customer's own chain of custody.
Customer instructionExecuted within 5 business days of written instruction from an authorised contact, with certificates issued on completion.
Suspected compromiseDestroy, with the medium held under evidential hold until the investigation closes.
Chain of custody and verificationOn site — media does not leave the perimeter
  1. Removal. Logged against rack and serial, with reason and ticket reference. Removal from L5 is on video.
  2. Secure holding. Sanitisation-pending media is held in a locked cage inside L4, itself under camera, with a signed register entry per movement.
  3. Execution on site. Where a third party performs destruction it is performed on site, under Prima escort and on camera. Media is not transported off the perimeter for destruction.
  4. Verification. Purge verified by read-back sampling; Destroy verified by inspection of particle size against the specification above.
  5. Certificate. A certificate of sanitisation or destruction is issued per medium, naming method, operator, witness, date and serial.
  6. Reconciliation. Certificates are reconciled monthly against the removal log. An unreconciled serial is a reportable security event.
Customer rightsA customer may witness destruction of media from its own estate, in person or on live video, on 5 business days notice; may set Destroy as the standing default for all of its media; and receives certificates for its serials with the monthly security report. Certificates are retained for the contract term plus 24 months.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  15 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 16 / 19
11Law-enforcement access and customer notificationCompelled · logged · notified

Prima operates in the Sultanate of Oman and complies with lawful instruction. The position is stated in advance and is deliberately narrow: lawful authority is met, nothing is volunteered, scope is held to what the instrument compels, and the affected customer is told — unless telling is itself prohibited.

Standing principles
  1. Written instrument required. Access to records, to the facility beyond the interior zone, or to a customer's equipment requires a warrant, court order or statutory demand identifying its legal basis. A verbal request is logged and declined.
  2. No voluntary disclosure. Prima discloses no customer data, record or equipment to any authority absent a compelling instrument, and grants no informal access.
  3. Legal review before compliance. Every instrument is reviewed by the General Counsel — or external counsel out of hours — for validity and scope before anything is produced.
  4. Narrowest scope. Production is limited to what the instrument names. Where an instrument is drawn more broadly than its stated purpose requires, Prima seeks to narrow it.
  5. Customer first where lawful. The affected customer is notified before compliance wherever the instrument permits, so that it can exercise its own legal rights.
  6. Everything logged. Instrument, reviewer, decision, what was produced, to whom and when — recorded on the disclosure register and retained.
By request type
RequestPrima's responseCustomer notified
Access and video recordsProduced to the named scope only; export logged on the custody register under section 09.Before compliance where lawful, else within 24 h
Entry to common areasL1–L3Identification and purpose recorded; escorted throughout; logged as a visitor event.If a customer's assets are approached
Entry to a data hallL4Written instrument or life-safety emergency; escorted by the CISO or delegate; video placed under hold; inventory of anything touched.Within 4 hours
Entry to a cage or rackL5Instrument must name the customer. The customer's own lock is not defeated absent that instrument. Full video hold.Before compliance where lawful, else within 4 h
Seizure of equipmentWarrant naming the equipment; inventory and photographs before release; officer's receipt obtained.Immediately · in writing within 24 h
Emergency respondersFire, medicalLife safety prevails — admitted immediately, escorted where practicable, video retained under hold.Within 4 hours where its zone was entered
Regulatory inspectionMandate verified; escorted by the CISO; scope and findings recorded.Where it touches its assets
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  16 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 17 / 19
11Law-enforcement access — continued
Seizure of customer equipment
  • Inventory before release. Each item photographed in situ and after removal; serials and rack positions recorded; the officer's receipt copied to the customer.
  • No assistance with extraction. Prima produces the physical asset the instrument names. It does not decrypt, image or otherwise assist in accessing customer data absent a separate compelling order.
  • Evidence hold. All video and access records for the event window are placed under hold and survive the retention clock in section 09.
Non-disclosure orders and transparency
  • Where notification is prohibited Prima notifies the customer as soon as the prohibition lapses or is lifted, and challenges or seeks to narrow a non-disclosure order where there are reasonable grounds to do so.
  • Annual statement. Where lawful, Prima reports annually the number of requests received, complied with, and declined or narrowed — without identifying customers.
CommitmentPrima grants no standing, bulk or automated access to any authority, under any arrangement. There is no interface, tap or credential held by a third party. Every disclosure is a discrete event, compelled by a named instrument, logged, and — save where prohibited by law — notified to the customer it affects.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  17 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 18 / 19
12Intrusion detection and alarm responseDetect · verify · respond

Detection is layered in the same way as access. An intrusion attempt should be detected at the perimeter, verified on video within seconds, and met by an officer before it reaches the building envelope. Alarms escalate on the clock without waiting for a human decision.

Detection by layer
LayerDetection methodVerification and first response
L1Perimeter intrusion detectionVideo analytics, fence sensingDetection presents the camera to the operator automatically; officer dispatched to the sector; vehicle gate held.
L2Door contacts, forced and held-openTailgate analytics at the turnstileAlarm at the officer post and the NOC; reception verifies on video; portal locked down on a forced-entry signal.
L3Door contacts on plant and control roomsUnauthorised-attempt alarmsNOC verifies against the entitlement record and video; shift lead attends where no matching authorisation exists.
L4Airlock interlock breach, anti-passbackOccupancy mismatchAirlock held closed, alarm to NOC and officer post, shift lead attends the hall in person.
L5Cabinet lock tamper, cage door held openUnauthorised cabinet releaseImmediate alarm, video preserved automatically for the event window, affected customer notified under section 13.
Response and escalationSame ladder as the SLA
Level 1
NOC Operator
On detection
Level 2
Security Officer
& Shift Lead
+ 5 min
Level 3
Operations Manager
& Security Manager
+ 15 min
Level 4
CISO and COO
+ 30 min

Escalation is time-based and automatic. A security alarm classifies as P1 under the Service Level Agreement where it involves an unauthorised presence beyond L3, a forced entry at any layer, or a tamper at L5 — and inherits the P1 response, update and root-cause obligations set out there.

Standing arrangements
  • Automatic evidence preservation. An alarm at L4 or L5 places the surrounding video window under hold, so the footage survives the retention clock regardless of when the investigation starts.
  • Officer coverage. 24×7 officer presence with documented patrol routes and randomised timing; patrol completion is logged and reviewed weekly.
  • Exercises. Response is exercised quarterly against a scripted scenario, including a tailgate attempt, a forced door and a lost-credential event. Results and corrective actions are recorded.
  • External liaison. Documented liaison with local police and civil defence, including site plans, contact protocol and pre-agreed access arrangements for emergency responders.
  • False alarms. Tracked as a quality metric; a device generating repeated false alarms is remediated rather than tolerated or suppressed.
© 2026 Prima Artificial Intelligence LLC · Sultanate of OmanDraft v0.2 · July 2026  18 / 19
DRAFT
PRIMA
Physical Security & Access ControlKOM Oman AI Factory · 19 / 19
13Compliance, audit and reportingEvidence, not assertion

The controls here are designed to be evidenced against recognised frameworks and tested by a third party — every control names the record that proves it.

Framework alignment
ISO/IEC 27001The physical and environmental security controls of Annex A are the design basis for sections 03–12. Certification of the operating entity is targeted; the control design does not depend on it.
SOC 2Access criteria are the design basis for the provisioning, recertification and audit-logging requirements in sections 05 and 07. A Type 2 report is targeted once the facility has adequate operating history.
Omani requirementsOperated in accordance with applicable Omani law on surveillance, personal data and the protection of critical infrastructure, under a published notice. Where a customer is subject to a sectoral standard, Prima completes that customer's control questionnaire and supports its audit against these controls.
Audit rights
  • Customer audit — annual, at no charge. One on-site security audit per contract year on 15 business days notice, escorted, covering these controls as they apply to the customer's assets.
  • For-cause audit. An additional audit following a security event affecting the customer, on 5 business days notice, without waiting for the annual cycle.
  • Records inspection. Remote inspection of access, visitor and recertification records relating to the customer's assets, at any time within retention.
Monthly security reportingWith the SLA service report
ReportedDetail
Access activityEntries by layer, denials, anti-passback and duress events, break-glass use with disposition.
Entitlement positionHolders by layer, entitlements granted, reduced and withdrawn, recertification completion rate, exceptions.
Surveillance healthProportion of cameras delivering a usable image, recording gaps with cause and duration, tamper events.
Security eventsAll events with classification, response times against the ladder in section 12, root-cause status; and escorted visits touching the customer's assets.
Notification of security events
  • Within 4 hours. Unauthorised access to a customer's cage or rack row, or tamper at L5 on its assets.
  • Within 24 hours. Unauthorised presence beyond L3, forced entry, or a recording gap over one hour in a critical zone.
  • Written report — 5 business days. Timeline, cause, containment and preventive action, with evidence under hold.
CISO, Office of the COO

For questions on this specification, the control design, or to arrange an audit of the estate. Commitments become contractual on incorporation into an executed Master Services Agreement.