Most SaaS platforms are multi-tenant: many customer organizations ("tenants") share the same application. Tenant isolation is the set of controls that guarantees each tenant only ever sees and changes its own data — through separate databases or schemas, tenant-scoped queries, separate encryption keys, and checks on every request.
Why it matters
Asset registers contain locations, values, custodians and sometimes sensitive operational details. A failure of isolation would expose one customer's data to another, so it is one of the first things security reviewers ask about.
Questions to ask a vendor
- How is data separated between tenants?
- Are secrets and keys stored per tenant, and where?
- Is data encrypted in transit and at rest?
- Can we export all our data at any time?
In Asetavo
Asetavo enforces strict tenant isolation, encrypts data in transit and at rest, and keeps device secrets AES-encrypted with keys held outside the tenant database. You can export your data at any time. Data-residency options for Enterprise are on the roadmap.