Understand Encryption and Tenant Isolation
Understand the layered controls used to protect data in transit, at rest, and across tenant and matter boundaries.
Overview
Understand the layered controls used to protect data in transit, at rest, and across tenant and matter boundaries.
Audience
- Admin
- It Security
- Compliance
Product Area
Trust
Prerequisites
- None.
Steps
- Separate identity from authorization
Authentication establishes identity; tenant membership, roles, matter access, and service scopes determine what that identity may access.
- Apply layered isolation
Application checks, tenant-scoped queries, row-level controls where deployed, storage boundaries, and audit logging work together; no single layer replaces the others.
- Validate the deployed controls
Use tenant-specific security evidence, key-management configuration, access reviews, and isolation tests during procurement and production admission.
Expected Result
Security reviewers can map identity, authorization, encryption, key management, tenant isolation, and audit evidence to the deployed environment.
Security and Audit Notes
- Use the least-privileged role that can complete the task.
- Confirm the resulting change or decision appears in the workspace audit trail when the workflow changes customer data or access.
Limits and Preconditions
- Algorithms and key custody depend on deployment configuration and contract.
- Public documentation intentionally excludes secrets, internal network details, and exploit-relevant configuration.
Troubleshooting
- Encryption is treated as an authorization control: Encryption protects data confidentiality; access policy and tenant isolation still require independent enforcement and testing.
Related Articles
Escalation
If the documented result cannot be reached after the checks above, capture the workspace identifier, affected product area, timestamp, and a redacted error message, then use Support. Never include secrets, privileged legal content, or customer documents in the initial report.