INSIGHTEngineering · Safety and security

Fire safety and physical security in modular data centers

Fire safety and physical security in a modular data center are the same disciplines practiced in a conventional facility — detection, suppression, access control, monitoring — resolved inside a shipping-sized enclosure instead of a building. The enclosure wall becomes the fire boundary and the security perimeter at once, which makes both factory design decisions rather than site fit-out decisions. This page covers the standards that apply, the detection and suppression options and their tradeoffs, the access-control layers, environmental sealing, and the questions to settle before any of it is specified.

PUBLISHED LAST VERIFIED BY JOSEF ELIMELECHREVIEWED PODOS AI ENGINEERING

5
Standards doing the work
4
Suppression options compared
8
Questions before design freeze

What you need to know

01

No single code governs it

The authority having jurisdiction applies locally adopted codes, which reach for NFPA 75, 72, and 70 — plus 855 the moment batteries are on the pad.

02

Detection is the hard part

High airflow dilutes smoke before it reaches a spot detector, so serious designs layer detection methods instead of picking one.

03

Suppression has no default

Clean agent, pre-action sprinkler, water mist, and detect-and-de-energize each buy something and cost something.

04

The wall is the perimeter

There is no lobby and no building security desk, so door hardware, tamper sensing, and camera coverage become enclosure design decisions.

Which standards actually apply

Four do most of the work, and a fifth arrives with batteries

No single document governs a compute enclosure. The authority having jurisdiction (AHJ) applies the locally adopted building and fire codes, then reaches for the consensus standards those codes reference. Four do most of the work in an IT space; a fifth appears the moment lithium-ion storage is on the pad. They overlap deliberately — detection is specified in one, the equipment it protects in another, the wiring that powers it in a third.

RefStandardWhat it governsWhy it matters in an enclosure
SS-01NFPA 75Fire protection of IT equipment and the areas containing it — construction, materials, protection, recovery.[1]The primary reference for an IT space. Its 2024 edition moved lithium-ion battery requirements out to NFPA 855.
SS-02NFPA 72Application, installation, performance, inspection, testing, and maintenance of fire alarm and signaling systems.[3]Governs detector selection and spacing — including the air-sampling detection commonly used where airflow dilutes smoke.
SS-03NFPA 2001Design, installation, testing, and maintenance of total-flooding and local application clean agent extinguishing systems.[4]Applies only if a clean agent is chosen. Enclosure volume and door leakage drive agent quantity and hold time.
SS-04NFPA 70 (NEC)Electrical installation requirements, including circuits serving fire protection and emergency functions.[5]Sets how emergency shutoff and suppression circuits are wired and how they survive the event they respond to.
SS-05NFPA 855Installation of stationary energy storage systems — separation, ventilation, explosion control, and commissioning.[2]Applies to on-site battery storage, not to the IT space itself. UL 9540A test data is how a design is evaluated against its limits.[6]

ENG-03Detection first

Detection comes before suppression

The hard problem in a compute space is not extinguishing a fire — it is noticing one early enough that extinguishing is a small job. High airflow works against detection: moving air dilutes smoke before it reaches a ceiling-mounted spot detector, which is why air-sampling detection, drawing a continuous sample through a pipe network to a central detector, is common in IT rooms. NFPA 72 governs how any of these devices are selected, located, and tested.[3]

A serious design layers detection rather than choosing one method. Air sampling catches overheating insulation before visible smoke; conventional spot detection provides the code-recognized alarm and release signal; thermal sensing on busway and terminations catches connection faults that never produce smoke at all; and where battery storage is present, off-gas detection is the earliest available indication of a cell entering thermal runaway — the failure mode UL 9540A exists to characterize.[6] Each layer answers a different question, and none substitutes for the others.

Suppression

Four options, and what each one costs you

There is no default answer here, and any vendor who offers one has skipped the analysis. The choice is a negotiation between the adopted code, the AHJ, equipment value, recovery time, and what the enclosure geometry can physically support.

OptionHow it worksArgues forArgues against
Clean agent (total flooding)Discharges a non-conductive agent to a design concentration held for a specified soak time, per NFPA 2001.[4]No water on energized equipment; fast knockdown.Needs a sealed volume and integrity verification; finite agent inventory; over-pressure venting must be designed in.
Pre-action sprinkler (double interlock)Piping stays dry until both a detection event and a head operate; only heads over the fire discharge.Widely accepted by AHJs; unlimited supply; no wetting from a single fault.Water reaches equipment when it operates; adds pipe, valves, and supervision inside a tight enclosure.
Water mistHigh-pressure fine droplets cool and locally displace oxygen using far less water than a sprinkler.Small water volume; effective in confined volumes.Still water in an energized space; nozzle placement is sensitive to obstruction by racks and containment.
Detect and de-energizeDetection triggers alarm, orderly shutdown, and power removal; manual firefighting handles the remainder.Removes the ignition energy source; nothing discharged inside.Rarely sufficient alone where code requires suppression; total workload loss on every event.

Two enclosure-specific consequences

A gaseous agent depends on the volume staying closed long enough to hold concentration, so door seals, cable penetrations, and cooling-air openings become fire-protection components rather than weather details. And every one of these systems needs power and signal paths that survive the event, which is where NFPA 70's emergency-circuit requirements intersect the power architecture.[5]

Physical security

The enclosure is the perimeter

The control objectives do not change because the building did. NIST SP 800-53's physical and environmental protection family names them plainly: access authorizations, access control, monitoring of physical access, visitor records, emergency shutoff, emergency power and lighting, fire protection, and water damage protection.[7] What changes in a modular unit is that these controls have nowhere to hide. There is no lobby, no shared corridor, no building security desk — the wall of the unit is the outermost layer and often the only one.

That argues for nested layers, each with its own detection and its own log. The site perimeter — fencing, lighting, approach cameras — is usually site scope and varies enormously between a fenced substation yard and an open lot. Enclosure access is the layer the unit owns: hardened door hardware, credentialed entry, door-position and tamper sensing on every opening panel, interior camera coverage. Rack and port access is the innermost layer, where locking cabinets and disabled unused ports keep an authorized visitor from becoming an unauthorized one. Logging binds them: an access event that is not recorded and reviewable did not happen as far as an audit is concerned.

Two failure modes recur, and neither is solved by hardware — the propped door, where a technician blocks a latch through a long maintenance window, and credential sprawl, where contractor badges outlive the contract.

The goal of every system on this page is early detection, limited damage, and safe response — not the elimination of ignition.

PODOS AI Engineering · design posture

Environmental sealing

What an IP or NEMA rating does not promise

An outdoor enclosure has to keep weather, dust, and airborne contaminants away from electronics while still rejecting heat. Two standards measure that. IEC 60529 assigns an IP code whose first digit rates protection against solid ingress and second digit against liquids.[8] NEMA 250 defines enclosure types for indoor, outdoor, and hazardous locations against its own test conditions, so a NEMA type and an IP code are not interchangeable statements.[9] Both are ingress tests under defined conditions. Neither is a fire rating or a security rating, and a rating on the enclosure says nothing about the equipment inside it.

Sealing also has a contamination dimension operators discover late. ASHRAE's thermal guidelines address particulate and gaseous contamination alongside temperature and humidity, because corrosive gases and salt-laden air attack connectors over years rather than hours.[10] Sites near coastlines, agriculture, or heavy industry need that assessed at siting time. Sealing interacts with cooling too: the tighter the enclosure, the more of the heat path has to be liquid — one argument for direct-to-chip liquid cooling in an outdoor unit. That adds a hazard air-cooled rooms never had — a pressurized coolant loop beside energized equipment — so leak detection, isolation valves, and an interlock between leak alarm and load shed belong in this same review.

Design review checklist

The eight questions worth resolving in order

These are the questions worth resolving in order, before anyone specifies a detector or a lock. Most disputes late in a project trace back to one of them being answered by assumption.

#QuestionWhat settles itConsequence if deferred
01Who is the AHJ, and which code editions has the jurisdiction adopted?The local fire marshal or building official, in writing, before design freeze.A factory-built unit arrives on site with a suppression design the jurisdiction will not accept.
02Is stationary battery storage in scope on this pad?The site power design. If yes, NFPA 855 applies with separation, ventilation, and explosion control.[2]Setbacks and ventilation appear late and consume site area already allocated.
03Which detection layers, and where does each one alarm?A matrix mapping every sensor to alarm, release, and shutdown actions per NFPA 72.[3]Detection exists but nothing acts on it, or one sensor triggers a discharge nobody wanted.
04Suppression method, and does the enclosure hold agent long enough?Enclosure-integrity assessment for gaseous agents; drainage and equipment exposure for water-based.[4]An agent system that vents its concentration through cable penetrations in seconds.
05How does suppression interact with cooling and power?A written sequence of operations: alarm, fan and pump shutdown, load shed, power removal, discharge.[5]Cooling fans keep running during discharge and blow the agent out of the space.
06Who holds credentials, what is logged, and who reviews it?A named access-authorization owner, revocation tied to contract end dates, and a stated retention period.[7]Contractor badges outlive the contract, and the evidence window rolls over before an incident is reviewed.
07What ingress and contamination environment is the site actually in?IP/NEMA target set from real site conditions, plus a contamination assessment.[8]Connector corrosion appears in year two and is diagnosed as random hardware failure.
08Who responds, and have they walked the unit?A pre-incident plan agreed with the responding fire department, including isolation points.[1]Responders arrive at a sealed enclosure with energized equipment and no plan for either.

HONEST LIMITS

Honest limitations: what a modular enclosure does not solve

Factory integration removes variance from safety and security systems. It does not remove risk, and it does not remove obligations.

  • Fire is never impossible. Energized equipment, batteries, and combustible materials are present; the goal of every system above is early detection, limited damage, and safe response — not the elimination of ignition.
  • No certification is implied. PODOS publishes no listing, certification, or test-result claims for safety or security systems. Approvals are project-specific and granted by the AHJ against locally adopted codes; nothing here should be read as a claim that any approval has been obtained.
  • The AHJ has the final word. A unit engineered against consensus standards can still require modification for a specific jurisdiction. Early engagement changes the cost of that, not the authority.
  • Site responsibilities do not travel with the unit. Perimeter fencing, approach lighting, guard response, water supply, and fire-department access are site scope; a well-secured enclosure in an unsecured yard is a partial control.
  • Procedure is the weakest link, and it belongs to the operator. Propped doors, stale credentials, silenced alarms, and untested shutdown sequences defeat correctly specified hardware — and Uptime Institute's 2025 survey of 800+ operators still finds impactful outages widespread.[11]
  • Suppression is not recovery. A successful discharge means the fire stopped, not that the workload survived or the hardware is undamaged.

In the product

How PODOS approaches this

PODOS treats safety and security as enclosure design rather than site fit-out. Each PODOS Pod is designed as a standardized 1 MW building block and designed for 128 GPUs, so the detection layout, access hardware, sealing details, and shutdown sequence are properties of a repeated product rather than decisions re-made for every site. That repetition is the point: one review is inherited by every unit instead of being re-litigated on each build.

It is also what makes the schedule credible. PODOS targets a 90-day window from order to commissioning for a standard unit, and a schedule like that only holds if safety systems are installed and tested in a factory rather than discovered on a pad — the same logic behind the deployment model and the wider modular platform. What does not travel with the unit is jurisdiction: AHJ engagement, site perimeter, and responder planning remain project work every time. For the broader comparison see modular vs traditional AI data centers, and for the vocabulary used above, the AI infrastructure glossary.

QUESTIONS

Frequently asked questions

Which fire code applies to a modular data center?

There is no single code. The authority having jurisdiction applies the locally adopted building and fire codes, which typically reference NFPA 75 for IT equipment areas, NFPA 72 for detection and alarm, NFPA 70 for electrical installation, and NFPA 855 where stationary battery storage is present. A modular enclosure escapes none of these; it changes how they are satisfied and who does the work.

Is a clean-agent suppression system required in a data center?

Not universally. Clean agent systems designed to NFPA 2001 are one option among several — pre-action sprinkler, water mist, and detect-and-de-energize strategies are all used in practice. The answer depends on the occupancy classification, the value and recoverability of the equipment, the adopted code, and what the AHJ will accept.

Does liquid cooling increase fire risk?

It changes the risk profile rather than simply raising or lowering it. Water-based coolant is not a fuel, but a closed loop adds a leak hazard near energized equipment. That is why leak detection, isolation valves, and a rehearsed shutdown sequence belong in the same design review as detection and suppression.

How is physical security different in a modular unit?

The control objectives match NIST SP 800-53's physical and environmental protection family — authorized access, monitoring, visitor records, tamper evidence, emergency shutoff. What changes is the boundary: the enclosure wall is the security perimeter, so door hardware, intrusion sensing, and camera coverage become enclosure design decisions rather than building fit-out decisions.

Bring the safety review to your jurisdiction

Send the site, the AHJ, and the battery question. Engineering will tell you what the detection, suppression, and access design looks like there.

Size your deploymentSee the deployment model