Tenant isolation in multi-tenant SaaS: what to ask
On an AI platform, isolation has to hold not only in the database but in the knowledge index — or a competitor's price could come out of your bot. This guide explains tenant isolation in multi-tenant SaaS: seven layers, the AI-specific risk, parent and child accounts, vendor questions, the "secret fact" test and isolation in your integrations.
Short answer
Multi-tenant SaaS means one platform serving many customers (tenants) on the same infrastructure. Tenant isolation means one customer's data, knowledge, keys and logs are never visible to, and never affect, another customer. On an AI platform this matters even more, because isolation has to hold not only in the database but in the AI's knowledge index too: one company's price list must never come up as an answer to another company's customer. As a buyer, ask about seven layers: database, AI knowledge, files and recordings, keys and integrations, logs, webhooks, and AI model training.
What multi-tenant means
Most SaaS platforms do not build a separate server for each customer: all customers share the same application and infrastructure, and their data is separated logically. That lowers cost and speeds up updates. It is also the risk: a mistake in the separation rules can show one company's data to another.
The alternative — a separate environment per customer (single-tenant) — is more expensive and usually chosen only for very large or specially regulated customers. For most companies the question is not "multi-tenant or not?" but "how is isolation built, and how is it checked?"
Seven layers of isolation
- DatabaseEvery query is scoped by tenant ID; one tenant's query cannot return another's record.
- AI knowledge indexKnowledge search runs only among that company's knowledge.
- Files and recordingsCall recordings, PDFs and images are separated per tenant, and links are not opened to others.
- Keys and integrationsOne company's CRM key and webhook address are used only for its own events.
- LogsOne tenant's admin cannot see another tenant's logs.
- Webhooks and notificationsAn event goes only to that tenant's address.
- AI modelCustomer data is not used to train a shared model, and one customer's conversations do not affect another's answers.
An AI-specific risk: knowledge bleed
In an ordinary SaaS, isolation lives mainly in the database. An AI platform has one more place: the vector index where the AI searches for knowledge. If search is not scoped by tenant, one company's bot can find another company's knowledge piece as the "best match" and tell it to a customer. That is both a privacy and a reputational risk: a competitor's price could come out of your bot.
Parent and child accounts
Agencies and multi-brand groups often manage several company accounts from one place. Two questions must be kept apart here: subscription and billing can be shared, but data must stay separate. Brand A's customer base must not be visible to brand B's bot, and an agency employee's access to each brand should be granted separately.
Questions for the vendor
- How is data separated between tenants: database, knowledge index, files?
- Can knowledge search return another customer's knowledge?
- Is our data used to train shared AI models?
- When and how can the vendor's staff access our data, and is it logged?
- How is isolation tested, and when was the last test?
- When the contract ends, how is our data deleted — backups included?
Get the answers in writing — in a security questionnaire.
How to check isolation
A buyer cannot see the vendor's internal tests, but can run simple checks. Open two test accounts — or ask the vendor for two test tenants — and write a unique, invented fact in one: "We open at 07:00 on Saturdays." Then ask the second account's bot about it. The bot should not know. Run the same check across export, search and reports.
Isolation in your integrations
Your own integration can break isolation too: if one webhook address receives events for two brands and does not check which brand an event belongs to, brand A's lead can land in brand B's CRM. A separate key per tenant, or checking the tenant ID on each event, removes this risk. Write it into the security section of the API integration requirements document.
An illustrative example
This is an illustrative example. A marketing agency builds AI chatbots for three client brands and manages them all from one agency account. During testing the agency runs a "secret fact" check between two brands and confirms the bots cannot see each other's knowledge. But in the agency's own integration, one webhook address is shared by all three brands.
The fix: a separate webhook key per brand, and a check of the brand ID on each event. Agency staff access is also split by brand.
Common mistakes
- Asking about isolation only in the database and forgetting the AI knowledge index.
- Settling for the vendor's verbal "everything is separate".
- Everyone in an agency account having access to every brand.
- A shared webhook address in your own integration.
- Not asking how data is deleted when the contract ends.
Limitations
A buyer can check isolation only so far: they cannot see the internal architecture and rely on the vendor's written answers, the contract and, where possible, independent checks. If a certification is required, ask the vendor directly which certifications they do and do not hold. In regulated sectors, agree requirements with legal and security.
Who is responsible
Isolation inside the platform is the vendor's responsibility; your integration and access rights are yours. That split should be written clearly into the contract. Internally, isolation questions belong on the IT or security owner's list — together with access rights, as covered in SSO and role-based access.
Isolation in Vexvon
In Vexvon the knowledge base is separated by company — each company has its own partition in the knowledge index, and search is scoped to that partition. According to the security page, a customer's data is kept separate from other customers' accounts, and uploaded databases, conversations, call recordings and transcripts are not used to train Vexvon's general AI models. For agencies and multi-brand groups there is a parent–child company model: the child company shares the parent's subscription. For large customers we fill in the security questionnaire. More on security.
Next step
Send the six questions to your vendor in writing and run the "secret fact" test yourself. Any question left unanswered is the topic of your next meeting. The general integration layers are covered in enterprise AI integration. More articles are in the enterprise integration section, and we can answer your questions together during a demo.