A facility that stores other people's websites and customer data is serious about who can get in. Typical measures include perimeter fencing, staffed reception, badge access, biometric or PIN readers at inner doors, cameras with retained footage, mantraps (two-door entry vestibules) and visitor logs. Within the building, cages and locked cabinets limit who can touch which equipment.
Operators of reputable facilities undergo external audits, for example against ISO 27001 or SOC 2, and will usually summarise their certifications on their website. These do not guarantee anything on their own, but their absence in a provider that handles sensitive data is a reason to ask questions.
Security in layers
No single lock is trusted. The design idea is depth: an intruder, or a careless visitor, must pass several independent checks, and each layer is watched. The outermost layer is the site boundary, with fencing, vehicle barriers and lighting. Next comes the building shell, with few doors, no ground-floor windows into the hall and a staffed reception. Then the data hall itself, behind a mantrap. Finally the cage or cabinet, and, for the most sensitive kit, locks on individual racks.
Doors that make people stop
The mantrap earns its place because it defeats tailgating, the habit of walking in behind someone who has opened a door. In a mantrap, the inner door stays locked until the outer door has closed, and some sets use weight sensors or a camera to confirm only one person entered per badge. Add a PIN or a fingerprint reader and a stolen badge is no longer enough on its own.
The weak points are rarely the doors themselves. They are the habits around them: propping a door during a delivery, lending a badge to a colleague, letting a contractor wander without an escort. Good facilities train staff to challenge strangers and log every visitor with a name, a purpose and the time in and out.
Cameras, logs and escorts
Cameras are only as useful as the footage retained and the people who review it. A reasonable operator keeps recordings for weeks or months, covers every entry point and every aisle, and ties door events to badge logs so that "who was in row C at 03:10" has an answer. Visitors are escorted, and visits to cages are booked in advance with the customer's approval.
| Control | What it stops | Where it fails |
|---|---|---|
| Fence and barriers | Casual approach, vehicles | Determined intruders; it only buys time |
| Badge reader | Unregistered visitors | Lent or stolen badges |
| Mantrap | Tailgating | Staff overriding it for convenience |
| Camera | Deters, and records afterwards | Nobody watching or footage overwritten |
| Cage or cabinet lock | Other tenants | Shared keys, weak locks |
What the audits mean
ISO 27001 certifies that an organisation runs an information security management system and that an independent body has checked it against the standard. SOC 2 is an attestation report in which an auditor describes controls and tests them over a period. They answer different questions, and neither says "this building cannot be broken into".
Read the scope. A certificate may cover the head office but not the data centre you are in, or one product line but not another. Many facilities also rely on a landlord's building, so the audit may cover only the operator's own procedures.
Loose ends
Can anyone from the data centre see my files?
Physical access is not the same as logical access, but a technician with the right permissions can reach a disk. Encryption at rest, and a provider that logs staff access, limit the exposure.
Is a certificate a guarantee?
No. It shows a process was checked at a point in time. It is a good sign, not a promise.
Do I need my own cage?
Only for specific compliance rules or very large setups. A locked cabinet in a well-run hall covers most cases.