Most seat leasing contracts in the Philippines are signed by an operations lead or a finance director evaluating cost per seat and commute distance. IT sees the paperwork after the deposit clears — sometimes after the first employee has already badged in. That sequencing is the root cause of most post-incident surprises in Philippine offshore operations, and it is entirely avoidable.

The problem is not that Philippine facilities are uniformly bad. The problem is that “enterprise-grade” and “biometric access” are sales descriptors, not technical specifications. A shared VLAN means a co-tenant's compromised endpoint is on your network segment. Shared NVR storage means your floor's CCTV footage lives on hardware controlled by the facility — and in a breach investigation or a regulatory subpoena, chain of custody becomes your problem, not theirs. These are not edge cases. They are the default architecture at a significant portion of Philippine seat leasing facilities, including some that carry credible-sounding certifications.

There are six infrastructure questions that separate a compliant seat from a liability. Most IT leads never ask them before the contract is signed.

  • Per-client VLAN with inter-VLAN routing disabled is the minimum network standard — not “dedicated fiber,” which is a bandwidth claim, not a security architecture claim.
  • Biometric access to the building floor is table stakes; per-tenant access logs, exportable and retained for your audit window, are the actual requirement.
  • NVR ownership determines who controls chain of custody for your floor's footage — and most facilities have never been asked who that is.
  • ISO 27001 “in progress” is honest, but it means the ISMS has not been independently audited; you are betting on intent, not evidence.

Network Segmentation: The Question Most Facilities Dodge

A “dedicated internet line” is a bandwidth claim. It tells you your traffic is not throttled by a neighbor streaming video. It says nothing about whether your traffic is isolated from that neighbor's network at layer 2. These are different things, and conflating them is one of the most common misunderstandings in Philippine seat leasing due diligence.

The minimum acceptable standard is a per-client VLAN with inter-VLAN routing disabled by default. When you ask a facility whether they provide this, a vague “yes, we have VLANs” is not an answer. Request the switch configuration diagram. Ask specifically: which VLAN ID is assigned to your tenant, and what ACL rules prevent traffic from crossing into adjacent tenant VLANs? A facility that cannot produce this document either does not have the architecture or does not have the documentation — both are problems.

Firewall placement is a separate question. A firewall at the building edge protects the facility from the internet. A firewall at the tenant boundary protects your environment from other tenants. These are architecturally different risk profiles, and many facilities only have the former. Ask where the firewall sits relative to your VLAN, not just whether one exists.

One more detail that rarely comes up: managed versus unmanaged switches. Unmanaged switches in a shared rack mean any tenant with physical access to that rack can plug in a device. In a co-working-adjacent facility where multiple tenants share infrastructure space, this is not a theoretical risk. Ask whether your network equipment is in a locked, per-tenant cabinet or in a shared rack.

Watch for these phrases in facility brochures: “high-speed fiber connection,” “dedicated bandwidth,” “enterprise network.” None of them confirm segmentation. They are bandwidth and marketing claims.

Physical Security: What “Biometric Access” Actually Covers (and What It Doesn't)

Biometric entry to a floor is the starting point, not the finish line. The questions that matter are what happens after the door opens.

Access logs are only useful if they are per-tenant, exportable on demand, and retained long enough to cover your audit window. If the facility maintains a single building-wide log that you cannot access independently, you cannot produce a clean access record for a compliance audit or an incident investigation. You are dependent on the facility's cooperation at exactly the moment when interests may diverge.

CCTV coverage maps are rarely volunteered. Reception areas and main corridors are almost always covered. Server rooms, printer stations, and secondary access points frequently are not. Ask for the camera coverage map for your specific floor before signing. The gap between “we have CCTV” and “we have coverage of the areas where your data is at risk” is often significant.

NVR ownership is the question most facilities have never been asked. If footage from your floor is stored on a shared NVR managed by the facility, you do not control chain of custody. In a breach investigation, you are asking the facility to produce footage that they own, on a timeline they control, from hardware they manage. For FinTech or HealthTech operations where regulatory bodies may require forensic-quality evidence, this is a material risk.

Visitor management is the last physical layer most IT audits miss. A single building-wide visitor log that you cannot access independently means you cannot reconstruct who was on your floor on a given date without going through the facility. Per-tenant visitor logs, with your own sign-in mechanism, are the correct standard.

The Six-Question Pre-Contract IT Audit

Run these questions before the deposit, not after. Each produces a GREEN, YELLOW, or RED rating. Any RED should be a contract condition — either resolved before signing or explicitly addressed in the lease language.

Dimension Minimum Acceptable RED Flag Demand in the Contract
Q1 — Network
“Provide a network diagram showing per-tenant VLAN assignment and firewall placement.”
Diagram with named VLAN IDs and firewall position No diagram; verbal assurance only VLAN assignment as a signed exhibit
Q2 — Physical access logs
“Are access logs per-tenant, exportable on demand, and retained for at least 12 months?”
Per-tenant export, 12-month retention No export capability Export right and retention period in SLA
Q3 — CCTV / NVR
“Who owns and controls the NVR for footage from our floor, and what is the retention period?”
Per-client NVR or documented client access rights Shared NVR with no client access path Chain-of-custody clause; footage access SLA
Q4 — Incident response
“What is the documented SLA for notifying tenants of a network or physical security incident?”
Written SLA, ≤4 hours for affecting-floor events No documented SLA Notification SLA with penalty clause
Q5 — Third-party audits
“Has the facility completed a third-party physical or network security audit in the last 24 months?”
Report or executive summary available No audit conducted Right to request future audit summaries
Q6 — Data residency
“Where is building management software hosted — on-premises or cloud, and in which jurisdiction?”
On-premises or documented jurisdiction Cloud-hosted, unknown jurisdiction Data processing agreement if personal data involved

What “CCAP Accredited” and “ISO 27001 In Progress” Actually Tell You

CCAP accreditation — from the Contact Center Association of the Philippines — signals industry membership and baseline operational standards. It is not a security certification. It tells you the facility operates within the industry association's code of conduct, which covers workforce practices and service standards, not network architecture or data handling controls. Treat it as a positive signal about operational maturity, not as a substitute for a security audit.

“ISO 27001 in progress” is a more nuanced claim. It is honest — and honesty is worth something. But it means the information security management system has not yet been independently audited and certified. The gap between a facility that has started the ISO 27001 process and one that has completed it can be twelve to eighteen months of remediation work. You are evaluating intent and trajectory, not current state.

If a facility is mid-certification, ask for three things: the gap assessment report, the certification scope (does it include the physical facility or only the management entity?), and the target certification date. A facility that can produce all three is demonstrably further along than one that cannot. A facility that claims ISO 27001 compliance without a certificate number and an issuing body is making a claim it cannot support.

For FinTech or HealthTech operators whose own compliance posture requires documented third-party security controls, “in progress” does not satisfy that requirement today. You need either compensating controls — documented in your own risk register — or a contract clause that ties the lease SLA to a certification milestone and provides an exit right if the milestone is missed.

How to Write Security Requirements Into the Lease Before Your Legal Team Sees It

Standard Philippine seat leasing contracts describe the desk, the bandwidth allocation, and the cleaning schedule. They are silent on incident notification, audit rights, and data handling. That silence is not an oversight — it is the template the facility's sales team uses for every tenant, most of whom never ask.

Three clauses to add before signing:

  1. Audit rights. Your IT team or a designated third party may inspect network configuration documentation and access logs on 48-hour written notice, no more than twice per calendar year.
  2. Incident notification. The facility must notify you within four hours of any network or physical security event affecting your floor or your VLAN, with a written incident report within 48 hours.
  3. Certification milestone. If the facility is ISO 27001 in progress, the contract specifies the target certification date. If the milestone is missed by more than 90 days, you have the right to renegotiate SLA terms or exit without penalty.

On network segmentation specifically: get the VLAN assignment documented as a signed exhibit to the contract, not a verbal commitment from the account manager who may not be there in six months. The exhibit should name the VLAN ID, the firewall rule set reference, and the process for requesting changes.

One area most Philippine facilities have genuinely never encountered: if the facility's access control or visitor management system processes biometric data or personal data of your employees, GDPR obligations (for EU-connected operations) or Australian Privacy Act obligations may require a formal data processing agreement. Ask for one. The facility will likely need to draft it from scratch — which is itself useful information about their data governance maturity.

Philippine BPO infrastructure is maturing fast. The $42 billion export revenue figure for 2026 reflects a sector that has moved well beyond its call-center origins, and the regulated-industry clients driving the next growth phase — FinTech, HealthTech, financial services — will not sign leases with facilities that cannot produce a client audit package on demand. The facilities that invest now in per-tenant network documentation, exportable access logs, and third-party security audits will win those contracts. The ones that compete on price per seat and “enterprise-grade” brochure language will find that segment closed to them.