Data center security

Zero-trust physical access control for enterprise data centers

9ID's AI security agent combines automated identity checks with background screening for vendor companies and individuals before granting perimeter access.

Every perimeter access decision is wired to seven checks: four on the company (VAT, UBO, PEP and sanctions, credit) and three on each person (KYC identity, watchlist screening, site briefing).
  • Company checks
  • Individual checks
Aquafin
World Forum The Hague
Alpro
Vopak
AS Watson
TVH
PSA International
Danone
Atlas Copco
Covestro
European Space Agency
FrieslandCampina
Pfizer
Puratos
SABIC
Suntory

How it works

Pre-clear every entity and individual before perimeter entry.

An automated identity verification workflow that keeps physical access security consistent across your sites.

  1. 01

    Start from the blueprint

    Company and personal checks are pre-configured. Adjust to your policy, buildings, and vendor types.

  2. 02

    Vendors register themselves

    Send invitation link. The company registers, gets checked automatically, and adds its people.

  3. 03

    Checks run before anyone travels

    Identity, watchlist screening, and briefing on their phone. Your team only reviews flagged cases.

  4. 04

    Every clearance is logged

    Every check, source, and timestamp linked to the person and company. Exportable in one click for audits.

Threat mitigation

Traditional gate checks leave mission-critical infrastructure exposed.

Manual gate checks miss company-level risk, and they cannot keep up when vendor rotation is high.

  • Individual-only focus

    Vets the person at the gate, ignoring corporate compliance and ownership risk

    Dual-layer pre-clearance

    Company UBO/PEP screening and individual watchlist checks, both completed before travel

  • Surface-level ID check

    Security guards manually check physical badges without verifying authenticity

    KYC identity check

    ID document verified and matched to the person with a live face check

  • Unmonitored third-party risk

    Subcontractors enter high-security zones with zero background visibility

    Mandatory watchlist screening

    Real-time screening against sanctions and PEP watchlists

  • Static access rights

    Badges remain active long after contract termination or security clearance changes

    Compliance-linked clearance

    Access blocked when company status, documents, or screening no longer pass

The datacenter blueprint

Automated checks required before physical access

9ID checks two things: the company you contract, and every person that company sends. Both happen before anyone travels to your site.

01 Company Per VAT number

Company checks

Enter a VAT number. 9ID runs four checks against official sources and keeps monitoring them, so you hear about a change when it happens.

  • VAT database check Registration confirmed at the source
  • UBO check Who owns and controls the company
  • PEP & sanctions watchlist screening Politically exposed persons and sanctions lists, monitored continuously
  • Credit database check Financial health and payment behaviour
02 Individuals Per person

Personal checks

Every person the company sends completes their own checks on their phone before they travel. Nobody enters on a colleague's clearance.

  • KYC identity check ID document verified and matched to the person
  • Watchlist screening Each person screened in their own name
  • Security briefing Your site rules read and confirmed before the first visit

Add checks from the library where your own policy asks for more.

Get Started

Inherited permissions

Automatic access revoking when company status changes

Individual access permissions inherit the compliance status of the employer. If a company fails a compliance check, access for its workforce is paused instantly. You do not cross-reference spreadsheets to find who works for an unverified company. Enforcement happens at the gate.

  • Continuous monitoring of company status and watchlists
  • Access is withdrawn automatically, with no manual check of your badge list
  • Instant alerts with root-cause context, keeping teams in control

Site coverage

Unified security rules across every type of site

Apply the same company and personal pre-clearance across colocation, hyperscale campuses, active builds, and remote edge sites.

  • Colocation

    Multi-tenant facilities

    Different tenants, buildings, and halls can require different checks, applied the same way for every vendor and visitor.

  • Hyperscale

    High-density campuses

    High vendor rotation across multi-building campuses. Clearance follows the verified person and employer, not whoever is holding a badge.

  • Build & expansion

    Active construction sites

    Verify every company tier in a subcontractor chain before trade crews enter live or active build zones.

  • Edge & remote

    Unmanned facilities

    Pre-clear vendors before arrival so unmanned sites never have to decide at the door. Cleared people pass to your existing access hardware, with no on-site reception required.

Eliminate physical security blind spots across your data center footprint.

Deploy the 9ID Data Center Blueprint for uncompromised, automated access control.

FAQ

Discover answers to common questions
about 9ID's AI security agent.

Which checks does 9ID run on a company?

Four, all from one VAT number: the VAT registration is confirmed at the source, ultimate beneficial owners are identified, owners and directors are screened for PEP and sanctions watchlist exposure, and a credit database check shows financial health. After onboarding, 9ID keeps monitoring those results instead of filing them away.

Which checks does every person complete?

An identity check that verifies an ID document and matches it to the person, watchlist screening in their own name, and your security briefing. All three are done on their phone before they travel, so a person who has not completed them never becomes an arrival your team has to turn away.

Does 9ID replace our access control system?

No. Your badge readers, turnstiles and cameras stay as they are. 9ID decides who is allowed to reach them. It holds the verified identity, the check results and the access rules per building, hall and time window, and passes a cleared person to the systems you already have.

Does 9ID integrate with our existing physical access control system?

Yes. 9ID connects to your PACS (badge readers, turnstiles, door controllers, and badge provisioning tools) via APIs and integrations. Screening results and access rules per building, hall, and time window are evaluated in 9ID first; cleared permissions are passed to the systems you already run. Your hardware stays in place.

How does this help with client audits, NIS2, SOC 2, and ISO 27001?

You have to be able to show how people are checked before they get access. 9ID logs what was checked, against which source, when, and how a flagged result was handled, linked to both the person and the company. You can export that record for tenant audits, certification reviews (including access-control evidence for frameworks like NIS2 and SOC 2), and incident investigations. 9ID delivers the workflow and the records; the security programme itself stays yours.

Can the checks differ per building or per type of vendor?

Yes. You assign requirements by role, type of company, building, hall and time window. A cooling contractor working in a plant room and an engineer entering a tenant hall do not need to meet the same requirements.

What if a vendor sends a different technician at short notice?

The replacement completes the checks in their own name first. Companies add and manage their own people, so this usually takes minutes instead of a phone call to your security desk. Someone who has not been checked does not get access.

Are the checks repeated over time?

Yes. Company checks are monitored after onboarding, so a watchlist hit, a change of owner or financial trouble shows up when it happens. Personal documents are tracked to their expiry date and requested again before they expire.

How is personal data handled?

Data is encrypted in transit and at rest, access is role-based, and every action is logged. 9ID is GDPR-compliant and certified to ISO 27001, ISO 27701, and SOC 2 Type II. A Data Processing Agreement is part of onboarding.