INSIGHTEngineering · Safety and security
Fire safety and physical security in modular data centers
Fire safety and physical security in a modular data center are the same disciplines practiced in a conventional facility — detection, suppression, access control, monitoring — resolved inside a shipping-sized enclosure instead of a building. The enclosure wall becomes the fire boundary and the security perimeter at once, which makes both factory design decisions rather than site fit-out decisions. This page covers the standards that apply, the detection and suppression options and their tradeoffs, the access-control layers, environmental sealing, and the questions to settle before any of it is specified.
PUBLISHED LAST VERIFIED BY JOSEF ELIMELECHREVIEWED PODOS AI ENGINEERING
- 5
- Standards doing the work
- 4
- Suppression options compared
- 8
- Questions before design freeze
What you need to know
No single code governs it
The authority having jurisdiction applies locally adopted codes, which reach for NFPA 75, 72, and 70 — plus 855 the moment batteries are on the pad.
Detection is the hard part
High airflow dilutes smoke before it reaches a spot detector, so serious designs layer detection methods instead of picking one.
Suppression has no default
Clean agent, pre-action sprinkler, water mist, and detect-and-de-energize each buy something and cost something.
The wall is the perimeter
There is no lobby and no building security desk, so door hardware, tamper sensing, and camera coverage become enclosure design decisions.
Which standards actually apply
Four do most of the work, and a fifth arrives with batteries
No single document governs a compute enclosure. The authority having jurisdiction (AHJ) applies the locally adopted building and fire codes, then reaches for the consensus standards those codes reference. Four do most of the work in an IT space; a fifth appears the moment lithium-ion storage is on the pad. They overlap deliberately — detection is specified in one, the equipment it protects in another, the wiring that powers it in a third.
| Ref | Standard | What it governs | Why it matters in an enclosure |
|---|---|---|---|
| SS-01 | NFPA 75 | Fire protection of IT equipment and the areas containing it — construction, materials, protection, recovery.[1] | The primary reference for an IT space. Its 2024 edition moved lithium-ion battery requirements out to NFPA 855. |
| SS-02 | NFPA 72 | Application, installation, performance, inspection, testing, and maintenance of fire alarm and signaling systems.[3] | Governs detector selection and spacing — including the air-sampling detection commonly used where airflow dilutes smoke. |
| SS-03 | NFPA 2001 | Design, installation, testing, and maintenance of total-flooding and local application clean agent extinguishing systems.[4] | Applies only if a clean agent is chosen. Enclosure volume and door leakage drive agent quantity and hold time. |
| SS-04 | NFPA 70 (NEC) | Electrical installation requirements, including circuits serving fire protection and emergency functions.[5] | Sets how emergency shutoff and suppression circuits are wired and how they survive the event they respond to. |
| SS-05 | NFPA 855 | Installation of stationary energy storage systems — separation, ventilation, explosion control, and commissioning.[2] | Applies to on-site battery storage, not to the IT space itself. UL 9540A test data is how a design is evaluated against its limits.[6] |
ENG-03Detection first
Detection comes before suppression
The hard problem in a compute space is not extinguishing a fire — it is noticing one early enough that extinguishing is a small job. High airflow works against detection: moving air dilutes smoke before it reaches a ceiling-mounted spot detector, which is why air-sampling detection, drawing a continuous sample through a pipe network to a central detector, is common in IT rooms. NFPA 72 governs how any of these devices are selected, located, and tested.[3]
A serious design layers detection rather than choosing one method. Air sampling catches overheating insulation before visible smoke; conventional spot detection provides the code-recognized alarm and release signal; thermal sensing on busway and terminations catches connection faults that never produce smoke at all; and where battery storage is present, off-gas detection is the earliest available indication of a cell entering thermal runaway — the failure mode UL 9540A exists to characterize.[6] Each layer answers a different question, and none substitutes for the others.
Suppression
Four options, and what each one costs you
There is no default answer here, and any vendor who offers one has skipped the analysis. The choice is a negotiation between the adopted code, the AHJ, equipment value, recovery time, and what the enclosure geometry can physically support.
| Option | How it works | Argues for | Argues against |
|---|---|---|---|
| Clean agent (total flooding) | Discharges a non-conductive agent to a design concentration held for a specified soak time, per NFPA 2001.[4] | No water on energized equipment; fast knockdown. | Needs a sealed volume and integrity verification; finite agent inventory; over-pressure venting must be designed in. |
| Pre-action sprinkler (double interlock) | Piping stays dry until both a detection event and a head operate; only heads over the fire discharge. | Widely accepted by AHJs; unlimited supply; no wetting from a single fault. | Water reaches equipment when it operates; adds pipe, valves, and supervision inside a tight enclosure. |
| Water mist | High-pressure fine droplets cool and locally displace oxygen using far less water than a sprinkler. | Small water volume; effective in confined volumes. | Still water in an energized space; nozzle placement is sensitive to obstruction by racks and containment. |
| Detect and de-energize | Detection triggers alarm, orderly shutdown, and power removal; manual firefighting handles the remainder. | Removes the ignition energy source; nothing discharged inside. | Rarely sufficient alone where code requires suppression; total workload loss on every event. |
Two enclosure-specific consequences
A gaseous agent depends on the volume staying closed long enough to hold concentration, so door seals, cable penetrations, and cooling-air openings become fire-protection components rather than weather details. And every one of these systems needs power and signal paths that survive the event, which is where NFPA 70's emergency-circuit requirements intersect the power architecture.[5]
Physical security
The enclosure is the perimeter
The control objectives do not change because the building did. NIST SP 800-53's physical and environmental protection family names them plainly: access authorizations, access control, monitoring of physical access, visitor records, emergency shutoff, emergency power and lighting, fire protection, and water damage protection.[7] What changes in a modular unit is that these controls have nowhere to hide. There is no lobby, no shared corridor, no building security desk — the wall of the unit is the outermost layer and often the only one.
That argues for nested layers, each with its own detection and its own log. The site perimeter — fencing, lighting, approach cameras — is usually site scope and varies enormously between a fenced substation yard and an open lot. Enclosure access is the layer the unit owns: hardened door hardware, credentialed entry, door-position and tamper sensing on every opening panel, interior camera coverage. Rack and port access is the innermost layer, where locking cabinets and disabled unused ports keep an authorized visitor from becoming an unauthorized one. Logging binds them: an access event that is not recorded and reviewable did not happen as far as an audit is concerned.
Two failure modes recur, and neither is solved by hardware — the propped door, where a technician blocks a latch through a long maintenance window, and credential sprawl, where contractor badges outlive the contract.
The goal of every system on this page is early detection, limited damage, and safe response — not the elimination of ignition.
Environmental sealing
What an IP or NEMA rating does not promise
An outdoor enclosure has to keep weather, dust, and airborne contaminants away from electronics while still rejecting heat. Two standards measure that. IEC 60529 assigns an IP code whose first digit rates protection against solid ingress and second digit against liquids.[8] NEMA 250 defines enclosure types for indoor, outdoor, and hazardous locations against its own test conditions, so a NEMA type and an IP code are not interchangeable statements.[9] Both are ingress tests under defined conditions. Neither is a fire rating or a security rating, and a rating on the enclosure says nothing about the equipment inside it.
Sealing also has a contamination dimension operators discover late. ASHRAE's thermal guidelines address particulate and gaseous contamination alongside temperature and humidity, because corrosive gases and salt-laden air attack connectors over years rather than hours.[10] Sites near coastlines, agriculture, or heavy industry need that assessed at siting time. Sealing interacts with cooling too: the tighter the enclosure, the more of the heat path has to be liquid — one argument for direct-to-chip liquid cooling in an outdoor unit. That adds a hazard air-cooled rooms never had — a pressurized coolant loop beside energized equipment — so leak detection, isolation valves, and an interlock between leak alarm and load shed belong in this same review.
Design review checklist
The eight questions worth resolving in order
These are the questions worth resolving in order, before anyone specifies a detector or a lock. Most disputes late in a project trace back to one of them being answered by assumption.
| # | Question | What settles it | Consequence if deferred |
|---|---|---|---|
| 01 | Who is the AHJ, and which code editions has the jurisdiction adopted? | The local fire marshal or building official, in writing, before design freeze. | A factory-built unit arrives on site with a suppression design the jurisdiction will not accept. |
| 02 | Is stationary battery storage in scope on this pad? | The site power design. If yes, NFPA 855 applies with separation, ventilation, and explosion control.[2] | Setbacks and ventilation appear late and consume site area already allocated. |
| 03 | Which detection layers, and where does each one alarm? | A matrix mapping every sensor to alarm, release, and shutdown actions per NFPA 72.[3] | Detection exists but nothing acts on it, or one sensor triggers a discharge nobody wanted. |
| 04 | Suppression method, and does the enclosure hold agent long enough? | Enclosure-integrity assessment for gaseous agents; drainage and equipment exposure for water-based.[4] | An agent system that vents its concentration through cable penetrations in seconds. |
| 05 | How does suppression interact with cooling and power? | A written sequence of operations: alarm, fan and pump shutdown, load shed, power removal, discharge.[5] | Cooling fans keep running during discharge and blow the agent out of the space. |
| 06 | Who holds credentials, what is logged, and who reviews it? | A named access-authorization owner, revocation tied to contract end dates, and a stated retention period.[7] | Contractor badges outlive the contract, and the evidence window rolls over before an incident is reviewed. |
| 07 | What ingress and contamination environment is the site actually in? | IP/NEMA target set from real site conditions, plus a contamination assessment.[8] | Connector corrosion appears in year two and is diagnosed as random hardware failure. |
| 08 | Who responds, and have they walked the unit? | A pre-incident plan agreed with the responding fire department, including isolation points.[1] | Responders arrive at a sealed enclosure with energized equipment and no plan for either. |
HONEST LIMITS
Honest limitations: what a modular enclosure does not solve
Factory integration removes variance from safety and security systems. It does not remove risk, and it does not remove obligations.
- Fire is never impossible. Energized equipment, batteries, and combustible materials are present; the goal of every system above is early detection, limited damage, and safe response — not the elimination of ignition.
- No certification is implied. PODOS publishes no listing, certification, or test-result claims for safety or security systems. Approvals are project-specific and granted by the AHJ against locally adopted codes; nothing here should be read as a claim that any approval has been obtained.
- The AHJ has the final word. A unit engineered against consensus standards can still require modification for a specific jurisdiction. Early engagement changes the cost of that, not the authority.
- Site responsibilities do not travel with the unit. Perimeter fencing, approach lighting, guard response, water supply, and fire-department access are site scope; a well-secured enclosure in an unsecured yard is a partial control.
- Procedure is the weakest link, and it belongs to the operator. Propped doors, stale credentials, silenced alarms, and untested shutdown sequences defeat correctly specified hardware — and Uptime Institute's 2025 survey of 800+ operators still finds impactful outages widespread.[11]
- Suppression is not recovery. A successful discharge means the fire stopped, not that the workload survived or the hardware is undamaged.
In the product
How PODOS approaches this
PODOS treats safety and security as enclosure design rather than site fit-out. Each PODOS Pod is designed as a standardized 1 MW building block and designed for 128 GPUs, so the detection layout, access hardware, sealing details, and shutdown sequence are properties of a repeated product rather than decisions re-made for every site. That repetition is the point: one review is inherited by every unit instead of being re-litigated on each build.
It is also what makes the schedule credible. PODOS targets a 90-day window from order to commissioning for a standard unit, and a schedule like that only holds if safety systems are installed and tested in a factory rather than discovered on a pad — the same logic behind the deployment model and the wider modular platform. What does not travel with the unit is jurisdiction: AHJ engagement, site perimeter, and responder planning remain project work every time. For the broader comparison see modular vs traditional AI data centers, and for the vocabulary used above, the AI infrastructure glossary.
QUESTIONS
Frequently asked questions
Which fire code applies to a modular data center?
There is no single code. The authority having jurisdiction applies the locally adopted building and fire codes, which typically reference NFPA 75 for IT equipment areas, NFPA 72 for detection and alarm, NFPA 70 for electrical installation, and NFPA 855 where stationary battery storage is present. A modular enclosure escapes none of these; it changes how they are satisfied and who does the work.
Is a clean-agent suppression system required in a data center?
Not universally. Clean agent systems designed to NFPA 2001 are one option among several — pre-action sprinkler, water mist, and detect-and-de-energize strategies are all used in practice. The answer depends on the occupancy classification, the value and recoverability of the equipment, the adopted code, and what the AHJ will accept.
Does liquid cooling increase fire risk?
It changes the risk profile rather than simply raising or lowering it. Water-based coolant is not a fuel, but a closed loop adds a leak hazard near energized equipment. That is why leak detection, isolation valves, and a rehearsed shutdown sequence belong in the same design review as detection and suppression.
How is physical security different in a modular unit?
The control objectives match NIST SP 800-53's physical and environmental protection family — authorized access, monitoring, visitor records, tamper evidence, emergency shutoff. What changes is the boundary: the enclosure wall is the security perimeter, so door hardware, intrusion sensing, and camera coverage become enclosure design decisions rather than building fit-out decisions.
Sources
- [1] NFPA 75 — Standard for the Fire Protection of Information Technology Equipment, 2024 ed. (catalog; see also the UL code-authorities explainer) — NFPA, 2024 ed.
- [2] NFPA 855 — Standard for the Installation of Stationary Energy Storage Systems (catalog) — NFPA, current ed.
- [3] NFPA 72 — National Fire Alarm and Signaling Code — NFPA, accessed 2026-08-31
- [4] NFPA 2001 — Standard on Clean Agent Fire Extinguishing Systems (catalog) — NFPA, current ed.
- [5] NFPA 70 — National Electrical Code (catalog) — NFPA, current ed.
- [6] UL 9540A Test Method for Battery Energy Storage Systems — UL Solutions, accessed 2026-08-31
- [7] SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (PE control family) — NIST, accessed 2026-08-31
- [8] IEC 60529 — Degrees of protection provided by enclosures (IP Code) — IEC, accessed 2026-08-31
- [9] NEMA 250 — Enclosures for Electrical Equipment (1000 Volts Maximum) (catalog) — NEMA, current ed.
- [10] Thermal Guidelines for Data Processing Environments, 5th ed. (TC 9.9) — ASHRAE, 2021
- [11] Global Data Center Survey 2025 — Uptime Institute, Jul 2025
Bring the safety review to your jurisdiction
Send the site, the AHJ, and the battery question. Engineering will tell you what the detection, suppression, and access design looks like there.