Safeguard
Tag

multi-tenancy

Safeguard articles tagged "multi-tenancy" — guides, analysis, and best practices for software supply chain and application security.

21 articles

Application Security

Permission Models Are Not Designed, They Accumulate

An is_admin boolean, then a role column, then a special case for one customer. Three years later nobody can say what a given user can do without reading the code, and an auditor is asking.

Sep 17, 20266 min read
Application Security

When NULL Tenant Means Global, Forgetting the Tenant Means Disclosure

A nullable tenant_id where NULL means global makes omission the unsafe state, and SQL NULL semantics mean the mistake never raises an error. The admin view looks full and correct while tenant-scoped rows are simply absent.

Sep 17, 20265 min read
Vulnerability Analysis

Cloudbleed (2017): A Parser Bug That Leaked Other Customers Data Into Web Pages

A factual retrospective on Cloudbleed, a 2017 buffer overrun in Cloudflare HTML parsing that leaked adjacent memory, including other customers private data, into responses that search engines then cached.

Sep 17, 20263 min read
Application Security

RBAC vs. ABAC vs. ReBAC: choosing an access-control model for multi-tenant cloud apps

Google's Zanzibar paper (USENIX ATC 2019) showed relationship graphs authorizing access with sub-10ms latency at massive scale — here's when RBAC or ABAC beats it instead.

Jul 15, 20266 min read
Kubernetes Security

Running Multiple Custom Controllers Without RBAC or CRD Collisions

Kubernetes CRDs are singletons by group and kind, and RBAC has no tenant concept — two facts that quietly break most multi-controller clusters.

Jul 11, 20268 min read
Application Security

Secure multi-tenant SaaS access control patterns

Broken Access Control has topped OWASP's Top 10 for two straight cycles, found in 100% of tested apps in 2025 — most of that risk starts with one missing tenant_id check.

Jul 8, 20266 min read
AI Security

SaaS Container Security: Protecting Multi-Tenant Workloads

SaaS container security is the set of controls that keep containerized, multi-tenant applications isolated, patched, and hardened from build through runtime. Here is the practical playbook.

Feb 18, 20266 min read
Architecture

Multi-Tenant Isolation for FedRAMP HIGH

How Safeguard achieves hard multi-tenant isolation in a platform that meets FedRAMP HIGH — the boundaries, the proofs, and the trade-offs we accepted.

Feb 14, 20268 min read
AI Security

MCP Server Multi-Tenant Isolation

Practical guidance on isolating tenants on shared Model Context Protocol servers, covering identity, data, compute, and observability boundaries at production scale.

Feb 8, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.