multi-tenancy
Safeguard articles tagged "multi-tenancy" — guides, analysis, and best practices for software supply chain and application security.
21 articles
The Permission You Just Revoked, According to a Replica That Has Not Heard Yet
A user is removed from a project. The write succeeds on the primary immediately. For the next several hundred milliseconds, a read replica still shows them as a member, and if any authorization check reads from it, they can still act.
Your API Returns More Than Your Interface Shows
The interface filters. The API does not. Serialising a model directly makes your API contract your database schema, so a column added for an internal feature is exposed the moment it is added.
Your Application's Hostname Should Not Be an Input
To build a reset link your app needs to know its own hostname, and the convenient place to find it is the Host header. That header is supplied by the client, so a stranger decides what goes in the email you send.
Your Admin Panel Has the Most Access and the Least Review
It can read every customer's data because that is its job, it was built quickly for an audience of colleagues, and it has never been part of a release anyone examined closely.
Domain Verification Is the Root of Trust for Your Enterprise Tier
Claiming a domain routes new signups, enforces sign-on and can absorb existing accounts. Every control that follows inherits whatever confidence that one check produced.
Your Search Index Is a Second Database With None of Your Access Controls
A missing clause in a database query returns too much. A missing clause in a search query returns everything, across every customer, ranked by relevance.
The CSV You Exported Runs on Someone Else's Machine
The value was stored safely, escaped correctly on every page, and never caused a problem. Then an administrator opens the export in a spreadsheet and the cell is not data any more.
Your Application Connects as a User That Can Do Everything
A SQL injection is limited by what the connected user may do, and so is a compromised application process. In most deployments the answer is everything, because that is what the framework quickstart produced.
The Invitation Flow Is an Access Grant Wearing a Growth Feature's Interface
Someone mistypes a colleague's address and a stranger is in that company's tenant, because the invitation worked exactly as designed. It is built early, for frictionlessness, by whoever shipped the collaboration feature.
When the Cache Key Leaks One User's Page to Another
A personalised response cached under a key that does not include the thing that made it personal. One of the few bugs that discloses one customer's data to another with no attacker involved, and it arrives as a confused support ticket.
The Service Template Is the Highest-Leverage Control You Will Build
One security engineer cannot review every service a hundred developers write. What works is deciding things once, in a scaffold, so every service created afterwards starts with those decisions already made.
The Export Button Is the Shortest Path From Account to Your Data on a Laptop
Every other endpoint is paginated. Export deliberately is not. It ships as a feature request, reuses the read permission, and is almost never reviewed as a data egress channel.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.