Lesson 24 / 28

Security and Multi-Tenancy

Isolate tenants and protect data in transit, at rest and in queries.

Enforce isolation where the data is

Embeddings are derived from your documents and can leak information about them, so vectors and payloads deserve the same protection as the source data. Use TLS in transit and encryption at rest; authenticate every client and give least-privilege roles (the ingestion service can write, the search service can only read); keep the database on a private network, never open to the internet; and keep API keys in a secrets manager. For multi-tenancy, enforce the tenant boundary where the data lives: row-level security or a mandatory tenant predicate in PostgreSQL, a collection or namespace per tenant, or an engine feature for tenant isolation; do not rely on application prompts or UI. Test isolation with automated checks that a tenant-A query never returns tenant-B rows. Log queries and administrative actions, and apply retention and deletion rules (deleting a document must delete its vectors and any caches).

Protect it, keep it, pick it

Vectors are as sensitive as their sources; plan backups and migrations, then choose with evidence.

Three tasks: secure, preserve, choose.
Figure 7.1 — Secure, preserve and choose.

Row-level security in PostgreSQL (illustrative)

Every query on the table is automatically restricted to the tenant set for the session. Standard PostgreSQL feature; shown as a pattern, not run here.

ALTER TABLE docs ENABLE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation ON docs
  USING (tenant = current_setting('app.tenant'));

-- in each request, after authenticating the user:
--   SET LOCAL app.tenant = 'acme';
--   SELECT id, body FROM docs ORDER BY embedding <=> :q LIMIT 5;   -- can only see acme's rows

Write a tenant-isolation test

Automatically check that a query as tenant A never returns a row of tenant B, and run it in CI.

Quick check: Where should tenant isolation be enforced?

  • Only in the UI
  • Only in the prompt
  • In the database (row-level security, collections or namespaces), tested automatically
  • Nowhere
Answer

In the database (row-level security, collections or namespaces), tested automatically — Isolation must hold even if application code or prompts are wrong.