Passbeam

Is one client's data separated from another's?

Yes, and it is the thing the product is built around rather than a setting. Every client gets its own certificate authority, its own directory connection and its own log, and a certificate issued for one client is not accepted on another's network. There is nothing to configure to keep it that way and nothing to switch off by accident.

It is enforced in the data layer rather than remembered in each query, and there is a test that fails the build if a new table is added without being covered — because "we were careful" is not a security control.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.