Knowledge Hub · Sovereign AI

How is access to FirstNet's InfraAI inference endpoints on the FirstCoreAI AI Factory secured?

GPU & Inference · Answered by FirstNet Technology Services

Short answer

Clients authenticate to InfraAI with OAuth2 client credentials and receive short-lived bearer tokens. TLS is terminated at the edge of FirstCoreAI's AI Factory cluster in FirstNet's South African data centre, and OAuth2 proxies validate each request.

In detail

How the security layers fit together:

  • Authentication: the OAuth2 client credentials flow is designed for application-to-application access, and short-lived tokens limit how long a leaked token stays useful.
  • Encryption in transit: TLS terminates at the cluster edge, where HAProxy and a Knative gateway handle incoming traffic.
  • Request validation: OAuth2 proxies check every request before it is served.
  • Management isolation: out-of-band management is segregated from the in-band fabric between nodes.
  • Onboarding: your token endpoint, endpoint URLs and credentials are issued to you at onboarding.

Data protection goes beyond access control. Inference runs on GPUs that FirstCoreAI, FirstNet's AI business unit, owns and operates in South Africa, and FirstCoreAI designs its endpoints, retention and access controls to align with POPIA. Requests stay in the country unless a workload uses optional frontier routing, in which case FirstCoreAI gives notice.

Source: FirstNet GPU & Inference service page →

Didn’t answer your question?

Call