multi-tenancy
Safeguard articles tagged "multi-tenancy" — guides, analysis, and best practices for software supply chain and application security.
21 articles
Permission Models Are Not Designed, They Accumulate
An is_admin boolean, then a role column, then a special case for one customer. Three years later nobody can say what a given user can do without reading the code, and an auditor is asking.
When NULL Tenant Means Global, Forgetting the Tenant Means Disclosure
A nullable tenant_id where NULL means global makes omission the unsafe state, and SQL NULL semantics mean the mistake never raises an error. The admin view looks full and correct while tenant-scoped rows are simply absent.
Cloudbleed (2017): A Parser Bug That Leaked Other Customers Data Into Web Pages
A factual retrospective on Cloudbleed, a 2017 buffer overrun in Cloudflare HTML parsing that leaked adjacent memory, including other customers private data, into responses that search engines then cached.
RBAC vs. ABAC vs. ReBAC: choosing an access-control model for multi-tenant cloud apps
Google's Zanzibar paper (USENIX ATC 2019) showed relationship graphs authorizing access with sub-10ms latency at massive scale — here's when RBAC or ABAC beats it instead.
Running Multiple Custom Controllers Without RBAC or CRD Collisions
Kubernetes CRDs are singletons by group and kind, and RBAC has no tenant concept — two facts that quietly break most multi-controller clusters.
Secure multi-tenant SaaS access control patterns
Broken Access Control has topped OWASP's Top 10 for two straight cycles, found in 100% of tested apps in 2025 — most of that risk starts with one missing tenant_id check.
SaaS Container Security: Protecting Multi-Tenant Workloads
SaaS container security is the set of controls that keep containerized, multi-tenant applications isolated, patched, and hardened from build through runtime. Here is the practical playbook.
Multi-Tenant Isolation for FedRAMP HIGH
How Safeguard achieves hard multi-tenant isolation in a platform that meets FedRAMP HIGH — the boundaries, the proofs, and the trade-offs we accepted.
MCP Server Multi-Tenant Isolation
Practical guidance on isolating tenants on shared Model Context Protocol servers, covering identity, data, compute, and observability boundaries at production scale.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.