Home/Company

About Velyrix

Operators, not resellers

Velyrix designs, builds and runs AI infrastructure — ours and yours. Our own engineers specify the racks, terminate the power, cable the fabric, sign the acceptance tests and answer the phone at 3 a.m. That is the whole company. No resold capacity, no subcontracted crews.

Who we are

An engineer-led company, deliberately narrow

Velyrix was built by data centre, HPC and network engineers who spent years watching general-purpose clouds struggle with 10 kW racks, oversubscribed fabrics and storage that could not keep a GPU fed. We do one thing: get accelerated hardware racked, cooled, cabled, validated and kept alive — to a standard that survives an acceptance test.

Focus is the point. We do not sell general-purpose cloud, we do not resell someone else's capacity, and we do not subcontract the parts that matter. The engineers who design your cluster are the ones who cable it, benchmark it, sign its acceptance report and take the call when a GPU throws an XID error at three in the morning.

We also do not run a hardware resale business. Our flagship model is Bring Your Own GPU: customers buy their NVIDIA systems from whichever authorized OEM or distributor suits them, and Velyrix deploys and operates that hardware for as long as they own it. It keeps us honest about what we recommend, and it makes us a partner rather than a competitor to the manufacturers and resellers we work with.

Headquarters
Diamond Bar, California, USA
Focus
Accelerated AI infrastructure only
Team
Engineer-led — data centre, HPC, network
Model
BYOG-first, vendor neutral
Facilities
Partner Tier III-class data centres
Markets
25 across 18 countries
Deployment scale
1 rack → 4,096 GPUs
Support
24×7 on-call NOC
Languages
EN · ES · FR · PT · AR · HI · ID · ZH
EN · ES · FR · DE · ZH
Where we deploy

25 markets, 18 countries — and what "live" actually means

Velyrix does not own buildings. We deploy into carrier-neutral, independently audited data centres and operate your hardware inside them. Below is exactly where we can deliver today, where we can deliver on request through a partner facility, and where we are still in contracting. We would rather be precise than impressive.

MarketCountryRegion codeFacilityMax rack densityCoolingStatus
Ashburn, VirginiaUnited StatesUS-EAST-1Partner Tier III-classup to 160 kWAir, RDHx, DLCLive — capacity held
Dallas, TexasUnited StatesUS-CENTRAL-1Partner Tier III-classup to 160 kWAir, DLCLive — capacity held
Chicago, IllinoisUnited StatesUS-CENTRAL-2Partner facilityup to 80 kWAir, RDHxOn request
Phoenix, ArizonaUnited StatesUS-WEST-2Partner facilityup to 80 kWAir, RDHxOn request
Santa Clara, CaliforniaUnited StatesUS-WEST-1Partner facilityup to 60 kWAir, RDHxOn request
Montreal, QuebecCanadaCA-EAST-1Partner facilityup to 120 kWAir, DLCOn request
Toronto, OntarioCanadaCA-EAST-2Partner facilityup to 60 kWAir, RDHxOn request
QuerétaroMexicoMX-CENTRAL-1Partner facilityup to 80 kWAir, RDHxOn request
MonterreyMexicoMX-NORTH-1In contractingup to 120 kWAir, DLCPlanned 2027
LondonUnited KingdomEU-WEST-2Partner facilityup to 80 kWAir, RDHxOn request
DublinIrelandEU-WEST-1Partner facilityup to 60 kWAir, RDHxOn request
ParisFranceEU-WEST-3Partner facilityup to 100 kWAir, DLCOn request
FrankfurtGermanyEU-CENTRAL-1Partner facilityup to 120 kWAir, RDHx, DLCOn request
AmsterdamNetherlandsEU-WEST-4Partner facilityup to 60 kWAir, RDHxOn request
MadridSpainEU-SOUTH-1Partner facilityup to 80 kWAir, RDHxOn request
MilanItalyEU-SOUTH-2In contractingup to 80 kWAir, RDHxPlanned 2027
StockholmSwedenEU-NORTH-1In contractingup to 160 kWDLC, heat reusePlanned 2027
HelsinkiFinlandEU-NORTH-3In contractingup to 160 kWDLC, heat reusePlanned 2027
WarsawPolandEU-CENTRAL-2In contractingup to 80 kWAir, RDHxPlanned 2027
TokyoJapanAP-NORTHEAST-1Partner facilityup to 80 kWAir, RDHxOn request
OsakaJapanAP-NORTHEAST-3In contractingup to 120 kWAir, DLCPlanned 2027
SeoulSouth KoreaAP-NORTHEAST-2Partner facilityup to 100 kWAir, DLCOn request
TaipeiTaiwanAP-EAST-2Partner facilityup to 100 kWAir, DLCOn request
SydneyAustraliaAP-SOUTHEAST-2Partner facilityup to 80 kWAir, RDHxOn request
AucklandNew ZealandAP-SOUTHEAST-5In contractingup to 60 kWAir, RDHxPlanned 2027
Live — capacity held

Velyrix holds contracted space and power here today. We can quote a delivery date without a new facility negotiation, and you can tour the site.

On request

We have a commercial relationship with facilities in this market and will contract space against your specific requirement. Expect two to six additional weeks before hardware can be received.

Planned

Under negotiation. We will not take an order against these until space is signed, and we will tell you which category your deal falls into before you commit.

Country selection

Why this list of countries, and not a longer one

Advanced accelerators are controlled items, and where they physically sit is a compliance decision before it is a commercial one. Velyrix will not put capacity somewhere that creates licensing exposure for a customer, for a manufacturer, or for the channel partner who sold the hardware. A shorter map is the point.

Permitted destinations only

Every market we operate in is a destination where the advanced accelerators we deploy may lawfully be supplied and used under US export controls, and under the equivalent EU, UK and local regimes. We do not place capacity in embargoed or sanctioned destinations, or in markets where the licensing position for high-end accelerators is unsettled.

Authorised channel only

Hardware reaches our halls through the manufacturer's authorised channel — OEM, distributor or reseller — with documentation we can show on request. We do not accept grey-market or re-exported equipment into any facility, on any commercial terms.

Screening before delivery

Customers, affiliates and beneficial owners are screened against US, EU, UK and UN restricted-party lists before an order is accepted, and monitored afterwards. End-user and end-use statements are collected for controlled capacity.

Access control by jurisdiction

Remote access to controlled capacity is granted only to authorised users from permitted jurisdictions, with deemed-export controls applied to personnel access. Access patterns inconsistent with the declared end user trigger suspension and review.

Serving customers outside these markets

If your organisation is based somewhere we do not deploy, you can still be a customer — the capacity stays in a permitted jurisdiction and the usual screening applies. What we will not do is move controlled hardware to a location that cannot support it.

The map changes when the rules change

Export control policy moves. We review the market list against current regulation each quarter, and we will decline or unwind a deployment rather than carry regulatory risk into a customer relationship.

This is a summary of internal policy, not legal advice, and it does not describe any third party's position. Customers remain responsible for their own export control and sanctions compliance. Questions: [email protected].

Security & compliance

Three layers of assurance, all of them evidenced

Security at Velyrix is built in three layers: independently audited facilities, our own controls operating and documented today, and an independent assurance programme with dates against it. Everything below is evidence we can put in front of your security team — as a questionnaire response, a site visit, or a document under NDA. We would rather be precise about what we can show you than generous with logos.

1. Facility certifications — held by our data centre partners

Velyrix deploys into carrier-neutral, third-party-audited data centres. Their certifications cover physical security, power, cooling and environmental management for the space your hardware physically occupies. During due diligence we name the operator for your site and pass through their current attestation under NDA.

Control areaOwned byEvidence we can provide
Physical security & access controlFacility operatorOperator's current SOC 2 or ISO 27001 report for that specific site
Power resilience & maintenanceFacility operatorDesign documentation, concurrent maintainability statement, maintenance records
Cooling & environmental managementFacility operatorOperator certification and environmental monitoring data
Fire detection & suppressionFacility operatorInspection and test records
Cage / suite access logsFacility operator + VelyrixPer-visit access log for your footprint

These are the facility operator's certifications, and we label them as such. A security reviewer will want to know exactly which certificate covers which layer of the stack, and an independently audited building is a legitimate control in its own right — provided everyone is clear about who holds what. Layers two and three below are ours.

2. Velyrix's own controls — written down and operating now

These are practices we run today and will evidence in a questionnaire, a site visit or a contract. None of them require a certificate to be real.

🔒

Tenancy & keys

  • Single-tenant physical hosts — no shared GPUs
  • Dedicated VLAN/VRF and fabric partitions
  • Customer-managed encryption keys
  • Velyrix cannot read tenant volumes
👤

People & access

  • SSO with enforced MFA, least privilege
  • Quarterly access review, same-day revocation on departure
  • Background-checked engineers, per-site authorisation
  • NDAs and confidentiality terms for all staff
📝

Process

  • Written information security policy set, reviewed annually
  • Documented change management with customer approval gates
  • Documented incident response with contractual notification times
  • Immutable audit log of console, API and physical access
🗑

Data lifecycle

  • AES-256 at rest, TLS 1.3 in transit
  • NIST SP 800-88 purge on decommission
  • Certificate of sanitisation, or customer-witnessed destruction
  • No customer data used for any secondary purpose, ever

Legal & trade

  • GDPR/UK GDPR data processing agreement and SCCs
  • Record of processing activities maintained
  • Restricted-party screening on every order
  • Export classification before controlled hardware ships
🛠

Engineering discipline

  • Firmware baselines and secure boot on every node
  • 72-hour burn-in and signed acceptance before handover
  • Installation to OEM published procedures
  • Serial-level asset records with photographic evidence

3. Independent assurance programme — dated and tracked

FrameworkWhere we are todayNext milestone
Facility certificationsIn force Inherited from independently audited partner data centresOperator report supplied per site, under NDA
GDPR / UK GDPRIn operation DPA, standard contractual clauses and records of processing available todayMaintained continuously
NIST SP 800-88 sanitisationIn operation Documented procedure; certificate issued on every decommissionMaintained continuously
NIST CSF 2.0 mappingIn operation Self-assessment complete and shareable with your security teamReviewed annually
HIPAA-aligned controlsAvailable Business associate agreement on request, controls mappedReviewed per engagement
ISO/IEC 27001In progress ISMS documented and operating, gap assessment completeStage 1 certification audit — Q3 2027
SOC 2 Type IIn progress Control set defined, evidence collection runningObservation window opens Q1 2027
SOC 2 Type IIScheduled Follows Type I on the same control setReport targeted Q4 2027
Third-party penetration testScheduled Booked ahead of the first enterprise production workloadAnnual thereafter

If a framework matters to your procurement process and is not on this list, tell us. We will commit to a date in writing, or tell you plainly where the boundary is — both answers are more useful to a security reviewer than a badge on a website. Progress against these milestones is reported to customers quarterly.

The honest case

Why buy infrastructure from a company at this stage

You are evaluating a newer provider for something expensive and hard to reverse. That deserves a straight answer rather than a pitch, so here is ours.

  • With BYOG, you hold the asset. This is the real answer to counterparty risk. You buy the servers from an OEM in your own name, under your own warranty. If Velyrix were to disappear tomorrow, you still own every GPU and can move it. No other early-stage vendor risk mitigation comes close.
  • You get the people who build it. Your solutions architect is the engineer who will cable your fabric and sign your acceptance report. There is no account-management layer between you and the work.
  • Commitments in contract, not badges on a website. Availability targets, acceptance criteria, response times and automatic service credits are written into the agreement and enforceable, today, regardless of which audits we have completed.
  • Short terms are available. We will do month-to-month on BYOG hosting and managed operations. If we are not good, you leave. We would rather earn a three-year contract in year two than trap you into one in year one.
  • Disproportionate engineering attention. Every cluster we build is a reference we intend to keep, so each customer gets senior engineering time that a larger provider reserves for its largest accounts. That advantage is real, and it is largest right now.
  • We say no. If your workload would be better on a hyperscaler, on your own floor, or on a competitor's fabric, we will tell you. Our business is long-run operations, not one-off placements.

What we will put in writing

Acceptance criteria

Agreed before the order, tested at handover, remediated at our cost if we miss them.

Service levels

Availability and response targets with automatic credits — no claim process.

Exit rights

Defined notice period, hardware release, data return and assisted migration if you leave.

Named facilities

We tell you exactly which operator and which building your hardware is in.

Escalation path

Named engineers and named executives, with direct phone numbers, in the contract.

Insurance

Current certificates of liability and professional indemnity provided on request.

Trade compliance

Export controls & sanctions

Advanced accelerators are controlled items. Velyrix operates a formal trade compliance programme covering the supply, hosting and remote provision of controlled computing hardware, and will decline business that cannot be supported lawfully.

Applicable regimes

Velyrix complies with the US Export Administration Regulations (EAR) administered by the Bureau of Industry and Security, US sanctions programmes administered by OFAC, and equivalent EU, UK and local regimes in each jurisdiction where we operate.

Controlled items

Advanced GPUs and related computing systems may be classified under export control classification numbers including 3A090 and 4A090 and associated software and technology entries. Classification, licensing requirements and destination eligibility are assessed per transaction.

Customer screening

All customers, affiliates and beneficial owners are screened against US, EU, UK and UN restricted-party lists before onboarding and on an ongoing basis. Transactions involving embargoed or sanctioned destinations and parties are refused.

End-use certification

Customers taking controlled capacity provide end-user and end-use statements. Velyrix prohibits use for weapons of mass destruction, unlawful military end uses, and any application prohibited by applicable law, and reserves the right to audit compliance.

Anti-diversion

Contracts prohibit re-export, transfer, sublicensing or remote provision of controlled capacity to restricted parties or destinations. Velyrix monitors for indicators of diversion, including access patterns inconsistent with the declared end user, and will suspend service where diversion is suspected.

Deemed exports

Access by foreign nationals to controlled technology is managed through nationality screening, access authorisation and, where required, licensing before access is granted.

Data centre access

Physical and logical access to controlled hardware is restricted, logged and reviewed. Remote access to controlled capacity is granted only to authorised users from permitted jurisdictions.

Governance

The programme is owned by a designated trade compliance officer, supported by external counsel, with annual training for sales, operations and deployment personnel and periodic internal audit.

This summary is provided for information and is not legal advice. Customers remain responsible for their own compliance with applicable export control and sanctions laws. Questions: [email protected].

Service levels

What we commit to, and what happens if we miss

ServiceAvailability targetMeasurementCredit at first breach tier
Colocation power (2N / N+1)99.999% / 99.99%Per circuit, monthly5% of monthly recurring charge
Colocation environmentalASHRAE envelope maintainedPer cabinet sensor, monthly5% of MRC
Network — internal fabric99.99%Per cluster, monthly10% of MRC
Network — internet transit100% (dual-homed)Per port, monthly10% of MRC
Dedicated server availability99.9%Per node, monthly10% of MRC
GPU cloud control plane99.9%API success rate, monthly10% of usage charge
Managed LLM endpoint99.9% plus throughput & latency targetsPer endpoint, monthly10% of service fee
Hardware replacement4-hour on-site targetPer incidentPer contract
P1 incident response15 minutesPer ticketPer contract

Credits are applied automatically against the following invoice; no claim process is required. Full definitions, exclusions and escalation tiers are set out in the master services agreement.

Careers

We are hiring engineers who like hard physical problems

Data centre engineers, fabric architects, HPC systems engineers, inference performance engineers, deployment project managers and NOC staff across all regions.

  • Real ownership — you will sign the acceptance test on clusters you built
  • Access to Blackwell-class hardware at scale, not a lab queue
  • Remote-friendly for platform roles, on-site for facility roles
  • Training budget and vendor certification support
Talk to an AI infrastructure architect

Own the GPUs. Let us run them.

Buy your NVIDIA servers from any OEM or distributor you like, ship them to a Velyrix hall, and we handle the rest — deployment, fabric, cooling, monitoring and support. Or rent ours. Either way, you get a plan in one business day.

Frequently asked questions

Is Velyrix a reseller or an operator?

Velyrix is an operator, not a capacity reseller. We contract space and power directly with data centre operators, own and operate the fabric and storage layer, employ the deployment and NOC engineers who do the work, and hold the customer relationship directly. We do not own the buildings themselves - we deploy into independently audited partner facilities and name the operator for your site during due diligence.

Which compliance certifications does Velyrix hold?

Velyrix operates three layers of assurance. In force today: the independently audited certifications of the partner data centres we deploy into, passed through per site under NDA. In operation today: GDPR data processing agreements and standard contractual clauses, HIPAA business associate agreements on request, NIST SP 800-88 sanitisation certificates, a complete NIST CSF 2.0 self-assessment, and documented policies for access control, change management and incident response that we evidence in questionnaires and site visits. On a dated programme: ISO/IEC 27001 stage 1 audit in Q3 2027, SOC 2 Type I observation window opening Q1 2027 and Type II targeted Q4 2027, with an independent penetration test booked ahead of the first enterprise production workload.

How does Velyrix handle export controls on advanced GPUs?

Through a formal trade compliance programme: classification of controlled items, restricted-party screening of customers and beneficial owners, end-user and end-use certification, contractual anti-diversion and re-export prohibitions, deemed-export controls on personnel access, and licensing where required under EAR, OFAC, EU and UK regimes.

Where are your data centres?

We deploy into partner data centres across 25 markets in 18 countries: the United States, Canada and Mexico; the United Kingdom, Ireland, France, Germany, the Netherlands, Spain, Italy, Sweden, Finland and Poland; and Japan, South Korea, Taiwan, Australia and New Zealand. Ashburn and Dallas are live with capacity held today, most other markets are served on request against a specific requirement, and a handful are still in contracting. Every market is a permitted destination for the accelerators we deploy - we do not place capacity anywhere that carries export-control or sanctions risk.