How are tenants isolated?

Your organization is a predicate bound into every query, not a filter applied afterwards, so another tenant's row is never a candidate result. It is identical in all four deployment models.

Isolation between tenants is enforced where the data is read. Your organization is a predicate bound into the query itself, so a row from another tenant is never fetched and then filtered away; it is never a candidate result in the first place. Authorization fails closed.

Workspaces are public, private, or personal, and that visibility is the boundary: an administrator role confers nothing inside a personal workspace. Managed, VPC, on-premises, and air-gapped deployments run the same isolation, not a stricter or looser variant per model.

Written for it and security. Last reviewed 2026-09-15.

Still need an answer?

Tell us what you were looking for and we reply within one business day.

Contact the team →

Running a security review?

Documents, controls, and the request form live in the Trust Center.

Open the Trust Center →

Something to report?

Security findings go straight to the people who fix them.

security@context.ai