Skip to main content

Tenant isolation

Tenant isolation is an Enterprise feature. Guest, Free, and Pro use shared infrastructure and do not include a tenant-isolation guarantee.

PlanData environmentTenant isolation
GuestShared demo environmentNot included
FreeShared environmentNot included
ProShared environment with Fleet SDK accessNot included
EnterpriseTenant environment arranged with ConstellationIncluded

Account sign-in and API scopes control access to features and operations. They do not establish a dedicated storage or deployment boundary for Free or Pro accounts.

Enterprise onboarding​

Before connecting a workload that requires isolation, agree the following with Constellation:

  • The tenant's data and deployment boundaries.
  • The environment, region, and API endpoints.
  • Credential ownership, access requirements, and rotation procedures.
  • Any retention, network, or compliance requirements specific to the program.

Use the endpoints and credentials provided for that deployment. A custom hostname alone does not establish an isolation boundary.

Contact us to define your requirements.