Summary

  • Public identities converge on the same operator. A federal corporate record names a Joinville branch of Centro de Tecnologia Armazem Datacenter LTDA., trading as Armazem, while the company's site names facilities in Joinville and Brusque and the internet registry view assigns AS262978 to the same legal name.
  • The strongest service evidence comes from the customer side. Brazilian Paralympic Committee notices describe a contract for public-cloud hosting, infrastructure management and monitoring, storage, communications links, internet, backup, antivirus and licensing, with annual values close to R$1 million in both 2023 and 2024.
  • AS262978 is an operationally useful anchor, not an uptime certificate. Public network views associate it with IPv4 and IPv6 resources, several observed upstreams, RPKI-authorised routes and exchange connections; those records do not reveal application availability, spare capacity or physical path diversity for a particular customer.
  • Armazém publishes a cloud portal, ticket entry point, service-status link and a 24/7/365 human-support claim. A buyer should turn that visible support surface into a severity model, response and restoration clocks, named escalation authority, recovery tests and an exit procedure before treating proximity as assurance.

Three identities resolve into a coherent operator

A cloud buyer first needs to know who will sign the order, who controls the infrastructure and who can be held to a remedy. Centro de Tecnologia Armazem Datacenter presents a legal name, the public brand Armazém Cloud and the network identity AS262978. The public record joins those names unusually well.

The Brazilian federal transparency record identifies Centro de Tecnologia Armazem Datacenter LTDA., CNPJ 11.214.586/0002-94, with the trading name Armazem. It describes the establishment as a branch opened on February 23, 2021 and gives Rua Dona Francisca 8300 in Joinville, Santa Catarina, as its address. It also publishes a company-domain email, telephone numbers and the names of two individual administrators and one corporate shareholder.

The company's infrastructure page supplies the physical join. It describes two interconnected units, one at the same Joinville address and the other at Rua Atílio Battistoti 199 in Brusque. The page says Joinville has temperature control, backup power and physical security, while Brusque provides direct connectivity to major operators. These are provider statements, but the address match is strong attribution evidence.

The network record completes the chain. bgp.tools identifies AS262978 as Centro de Tecnologia Armazem Datacenter Ltda., links it to the Armazém domain and reproduces a NIC.br record carrying CNPJ 11.214.586/0001-03. The shared CNPJ root and differing establishment suffixes fit the public distinction between a main establishment and the Joinville branch. They should still be written explicitly into the contract. A customer should not have to infer whether the signatory, facility operator, network holder, invoice issuer and data processor are the same establishment or related ones.

This identity chain does not prove ownership of every rack, fibre or software licence. It does make meaningful diligence possible. The order can name the contracting CNPJ, the service schedule can identify the facility, and the incident plan can refer to AS262978 and the company's published technical contacts without relying on a brand name alone.

A public customer record proves a multi-layer service obligation

Armazém's own pages list hosting, colocation, disaster recovery, backup, firewall, website hosting, corporate email and connectivity. A catalogue shows what a provider wants to sell. The more persuasive evidence is a customer-side record showing what the legal entity was actually contracted to supply.

An October 2023 notice in Brazil's official gazette records a contract addendum between the Brazilian Paralympic Committee and the Joinville establishment. The stated scope covers hosting, management and monitoring of public-cloud infrastructure, file storage, data-communications and internet links, backup, antivirus and licensing. The annual value was R$989,618.01. A July 2024 notice records a further 12-month extension of contract 028/2022 at R$985,130.31.

Those records matter because the scope crosses several operating boundaries. Compute, storage, network access, security software, backup, licences and human monitoring appear in one engagement. Centro de Tecnologia Armazem Datacenter was not simply renting an address or advertising an empty cloud label; it was named as counterparty for an integrated service with a material annual value.

The notices do not disclose achieved availability, incident volume, restoration results or customer satisfaction. They also do not show how much of the contract value was consumed, whether every listed component ran in Armazém's own facilities, or which public-cloud environment was used. A contract is proof of obligation and continuity, not proof that every obligation was met. That boundary is especially important here because the service mixes provider-controlled infrastructure with products or platforms that may be supplied by third parties.

For a new customer, the public scope is useful as a map of questions. Which party owns the tenant and master account? Who holds the cloud subscription, antivirus licence and backup credentials? Can the customer see monitoring history and retrieve machine images? Does the communications link terminate in an Armazém facility, a third-party cloud region or both? An integrated supplier can reduce hand-offs during an incident, but only if the contract identifies the person authorised to act at each layer.

Facility claims become useful when their scope is named

Armazém says its Joinville and Brusque units are interconnected. Its infrastructure page describes redundant systems, controlled temperature, backup energy, physical security and connectivity to major operators. The colocation page adds rack and partial-rack options, precision cooling, fire protection and rapid hardware replacement under provider control. Together, these details describe a plausible regional operating surface rather than an abstract cloud brand.

The certification evidence is more delicate. On its certifications page, the company presents a Tier III Facility certification and ISO 27001. The page explains redundant critical systems and maintenance without interruption, and associates Tier III with its data-centre operation. Uptime Institute's public achievements list also surfaces the legal name Centro de Tecnologia Armazém Datacenter Ltda., providing an independent identity signal.

Neither public page, as captured for this assessment, is a complete assurance schedule. The company page does not expose the certificate number, covered street address, certification body for ISO 27001, statement of applicability, issue date, expiry date or surveillance status. The Uptime listing available in the evidence set did not provide enough detail to map the achievement confidently to one unit and one current service. A buyer should request the certificates and verify the precise facility, scope and validity directly with the issuing body.

That is not administrative fussiness. A facility certification can apply to constructed infrastructure without covering a managed-cloud control plane, support operation or customer backup policy. An information-security management certificate can cover one office or process while excluding a particular product. Procurement should preserve the valuable claim by making its boundary explicit: which building, system, operating company and service are inside the certified scope?

AS262978 provides a visible network footprint

The internet-routing evidence is the clearest present-tense signal that Armazém controls infrastructure beyond a sales site. The bgp.tools view of AS262978 describes the network as active and allocated under NIC.br. At capture, it reported 15 IPv4 and four IPv6 prefixes, seven observed upstreams and route entries marked with valid RPKI authorisation. The underlying registry material names several aggregate resources, including 132.255.220.0/22, 143.0.120.0/22, 186.250.184.0/22 and 2804:4d44::/32, under the company identity.

The same view observed connections at Brazilian internet exchanges in São Paulo, Porto Alegre, Florianópolis, Curitiba, Fortaleza and Rio de Janeiro. Its upstream list included regional and international networks such as Grupo Brasil Tecpar, Claro, Seaborn, BR.DIGITAL, Unifique and Algar. PeeringDB's organisation record independently associates Armazém Cloud, AS262978 and facilities in Joinville and Brusque.

These records support three restrained conclusions. First, Centro de Tecnologia Armazem Datacenter has a durable autonomous-system identity dating to May 2012. Second, it originates both IPv4 and IPv6 resources. Third, public routing observers see more than one external relationship. RPKI markers add evidence that the listed origins are authorised, reducing ambiguity about who is meant to announce those routes.

None of that is a customer service-level result. Fifteen route entries are not fifteen independent paths, because aggregate and more-specific announcements can overlap. Several upstream autonomous systems do not prove that fibre enters a building through separate ducts, that circuits have independent power, or that sufficient spare capacity exists during failure. Exchange presence does not state the traffic carried by a customer's workload. RPKI validates intended origin and prefix length, not the complete route, packet delivery or application health.

The ASN gives buyers something concrete to test. A network schedule should name normal and failover paths, hand-off capacity, route policy, distributed-denial-of-service controls and the customer prefixes involved. A controlled exercise can then record convergence time, latency, loss and application behaviour when a link or upstream is withdrawn. The public network record frames that test; it does not replace it.

Automation spans portals, backup tools and human authority

Armazém exposes several control surfaces. The main site links to a cloud portal, a ticket system and a service-status page. Its backup description names Veeam and Acronis as tools for creating and managing copies on premises, in the cloud or both. The Paralympic Committee record adds infrastructure management and monitoring to the service evidence.

That combination is important because enterprise cloud service is not just a place where servers run. It is a sequence of authorised changes: create a virtual machine, allocate an address, attach storage, schedule a backup, detect failure, approve a restore and preserve an audit record. Automation can shorten those steps and reduce routine labour. It can also concentrate power in a portal account or provider administrator.

The public material does not show role definitions, multifactor authentication, approval thresholds, activity-log retention, application interfaces or rollback behaviour. It does not say whether a customer can export monitoring history or whether support staff can enter a tenant without customer approval. The backup page says restoration can be immediate, but it publishes no recovery-point objective, measured recovery-time distribution, immutable-copy design or evidence of a customer-selected restore.

A useful acceptance exercise should therefore follow one change from request to reversal. The customer creates a least-privileged role, submits a capacity change, verifies approval and billing effects, retrieves the activity record, then rolls the change back. A separate recovery test should delete or corrupt a selected workload, restore it to an isolated target and measure data loss and elapsed time. The exercise should identify which actions were automatic, which required Armazém staff, and who had authority to proceed after hours.

Brazilian facilities do not settle every data-location question

Armazém's local case is attractive. Both named facilities are in Santa Catarina, its legal and network records are Brazilian, and the colocation page describes its offer as 100% Brazilian. For organisations that value a domestic counterparty and nearby physical support, those are real advantages.

They do not establish that every customer-data copy remains in Brazil. The public-sector contract explicitly refers to public-cloud infrastructure, which could involve an external platform even when Armazém manages the service. The backup page allows storage within the customer environment, in the cloud or both. Monitoring, antivirus, ticketing, email, telemetry and vendor support can each create additional data paths.

Locality has to be defined by data class and by failure state. Production disks may sit in Joinville while a recovery copy sits in Brusque. Logs may leave both sites for a security service. A support ticket can contain screenshots or personal information. During a major incident, a vendor may receive diagnostic access that is not part of the normal operating path.

The contract should list primary data, replicas, snapshots, backups, logs, account records and support material separately. For each class it should identify the facility or cloud region, processor, subprocessor, privileged-access location, encryption-key controller, retention period and deletion proof. It should also describe the emergency arrangement. A Brazilian address is jurisdictional evidence; a copy-by-copy map is residency evidence.

A visible support surface still needs clocks and owners

The company's website makes support unusually visible. It links to ticket submission and cloud status from the main navigation, publishes telephone and email contacts, and describes human support available 24 hours a day, 365 days a year. The network record also publishes a technical contact at the older armazemdc.com.br domain. These are better accountability signals than an anonymous order form.

They are not performance evidence. The pages do not define whether round-the-clock support means a continuously staffed operations team, an on-call rota or ticket intake. They do not state incident severities, acknowledgement targets, restoration targets, update intervals, escalation levels, maintenance exclusions or credits. A status link is useful, but its mere presence does not establish historical completeness or the time between a fault and public notice.

The local-labour question is also about authority. A first-line agent may acknowledge a ticket while a network engineer, facility technician, backup specialist or third-party cloud administrator holds the power to restore service. In colocation, the customer's own hardware can require remote hands. In managed cloud, Armazém staff may control the hypervisor while the customer controls the guest system. The incident plan has to state who can reboot, replace, reroute, restore and communicate at each boundary.

Before production use, a customer should run an after-hours escalation and a witnessed restore. The result should record the first response, the arrival of a person with the necessary privileges, the decision trail, updates to stakeholders and the restoration time. Over several months, anonymised response and recovery distributions are more informative than a single maximum. Local people become an assurance advantage when their authority, clock and record are visible.

Buy the documented service, not the implication of the name

Centro de Tecnologia Armazem Datacenter has a substantial public footprint. The legal name and brand map to two addresses. A customer-side government record documents a broad, continuing cloud and infrastructure engagement. AS262978 supplies a durable technical identity with dual-stack resources, observed external relationships and authorised route origins. The company's own pages expose facilities, products, a cloud portal and support routes.

That is enough to treat Armazém Cloud as an identifiable Brazilian infrastructure operator, not merely a reassuring name. It is not enough to assume that every service inherits the same facility certification, route diversity, data location, recovery performance or support commitment.

The decisive procurement document is a service map. It should join the exact contracting CNPJ to the facility or public-cloud region, customer tenant, network paths, data copies, software licences, monitoring system and people responsible for recovery. Current certificate copies, route and circuit evidence, a restore result, an after-hours escalation record and a tested export procedure should sit behind it.

Armazém's public evidence gives a buyer a strong starting position: stable identifiers, visible infrastructure and a service obligation with real scope. Operating assurance begins when those signals are converted into customer-specific boundaries and observed results. The name can open the conversation; the service map has to close it.