April 12, 2025
Tenant Isolation: Why It Matters When Several Clients Share One Platform
A platform serving many firms on shared infrastructure is not automatically a risk, but it does raise a specific question worth a direct answer: what actually keeps one customer's data separate from another's.
What isolation means in practice
At minimum, one customer's records should never be retrievable, even accidentally, through another customer's account or through a shared feature like search or an AI assistant that draws on stored data. A vendor should be able to describe, plainly, the mechanism that enforces this, not just assert that it works.
Questions worth asking before signing
Is data logically separated per customer, or physically separated? Has the isolation model been tested by an independent party, and is a summary of that testing available? What happens to a customer's data, and any AI-generated content built from it, when the contract ends?
A reasonable middle ground
Very few small platforms will have completed a full independent audit. That is not automatically disqualifying, but it does mean asking more specific, harder questions about the underlying architecture before trusting a client's pipeline data to a young platform, rather than accepting a general assurance at face value.
A note on smaller, newer vendors specifically
A smaller platform is not automatically riskier than an established one, but it usually means less has been independently tested, simply because there has not been time or budget for it yet. Asking a young vendor to describe its architecture in plain language, rather than accepting a general assurance, tends to surface whether isolation was designed in from the start or added later as an afterthought.
A short way to document the answers
Keep a one-page internal record of what was asked, what the vendor answered, and when, for every platform touching client or prospect data. This is a small amount of paperwork that pays off the one time a client, or a new hire doing diligence of their own, asks a specific question about how their information is handled.
A short note on how this looks for a very small vendor
A small, early-stage vendor may genuinely have strong isolation built in from day one, simply because the architecture was designed correctly from the start, even without a formal audit yet. Size, alone, is not the signal to look for. Specific, technical answers to specific questions are the signal, regardless of how large or established the vendor is.
A short note on the relationship between security diligence and sales cycles
Asking these questions early in a vendor evaluation, rather than after a contract is largely agreed, avoids the awkward position of raising a serious concern after momentum has already built toward signing. Vendors accustomed to serious buyers generally expect these questions as a normal part of the process and are not put off by them; a vendor that reacts poorly to being asked is itself useful information.
It also gives a firm real standing to negotiate specific contract language on the points that matter most, since asking early, while the deal is still being shaped, is a very different position than asking after the paperwork is essentially finished and the team is eager to start using the tool.
A final word on who inside a firm should own this ongoing relationship
Security diligence works best when one specific person is responsible for maintaining the vendor relationship over time, not just for the initial signing. That person should be the one who gets notified of vendor security updates, who re-runs the short question list annually, and who a colleague can ask when a new client's requirements raise a question the original vendor evaluation did not anticipate.
A short note on what a reasonable timeline looks like
Getting clear answers to these questions from a serious vendor typically takes a few business days, not weeks. A vendor that stalls significantly longer than that, without a clear reason, is itself a data point worth weighing alongside whatever the eventual answers turn out to be.
Key takeaways
- Isolation between customers on shared infrastructure needs a specific, checkable mechanism.
- Ask whether isolation has been independently tested, not just internally asserted.
- Clarify what happens to your data and AI-generated content when a contract ends.
- A newer vendor without independent audits deserves more specific questions, not automatic disqualification.
Questions, answered
What is the short answer on Tenant Isolation: Why It Matters When Several Clients Share One Platform?
Most AI-assisted BD platforms serve many customers on shared infrastructure. Isolation between those customers is the specific thing worth verifying.
What are the key takeaways?
Isolation between customers on shared infrastructure needs a specific, checkable mechanism. Ask whether isolation has been independently tested, not just internally asserted. Clarify what happens to your data and AI-generated content when a contract ends. A newer vendor without independent audits deserves more specific questions, not automatic disqualification.
How does VIPMarketing approach security?
VIPMarketing is a hosted, private workspace. Your documents and records stay yours and never train a model, and every draft is approved by a person before it is sent.