Data center security: tenant separation you can show
Data center security in a shared facility has two jobs: keep tenants apart, and show an auditor that they’re apart. QS-WAN gives each tenant its own gateway and network segments, draws every permitted link on one map, and keeps the record of who can reach what. Physical security, the cages and badges, stays with you.
QS-WAN answers all three from the network it runs, not from a spreadsheet.
Shared power, shared switches, separate promises
A multi-tenant data center sells something nobody can see. Tenants share the power, the cooling, the fibre and usually the switching fabric, and every contract still says each tenant’s network is theirs alone.
Keeping that true is ordinary work. Showing it is where it hurts. An auditor can walk up to a cage and rattle the door. Nobody can rattle a VLAN. Logical separation lives in configuration spread across switches, firewalls and hypervisors, written by different people over the years.
So the usual proof is screenshots and a spreadsheet of VLAN IDs, exported the week before the audit.
Every tenant brings an auditor
ISO/IEC 27001 has a control for segregation of networks. If segmentation keeps systems out of PCI DSS v4.0 scope, it has to be penetration tested every year, or every six months for service providers. NIS2 puts data center service providers in its digital infrastructure sector.
Separation drifts
A migration needs a temporary link. A tenant leaves and their address range gets reused. Each change makes sense on the day. The auditor sees the sum of all of them.
Your own people cross every line
Remote hands and on-call engineers work across tenants, and they’re supposed to. The question is whether you can list exactly which tenants each of them can reach today.
A gateway per tenant, and every link on one map
QS-WAN runs a private network from one console, and QNova Client connects each person’s device to it. In a shared facility, that comes down to three things.
A gateway for each tenant
Each tenant’s segment sits behind its own gateway, a hardware box or software on hosts you already run, with its own VLANs, address space and firewall rules. It goes in next to your existing switching, not instead of it.
Links you can see, and switch off
In the Network Map, a connection between two segments is an edge you switch on or off. Between two VLANs, the change applies both ways. A VLAN set to zero trust stays default-deny, whatever tunnel mode it uses.
A certificate for each way in
A device holds a separate certificate for each gateway it belongs to. An engineer who looks after three tenants has three memberships, and revoking one leaves the other two alone. When a device enrols, what it says about itself is treated as a claim, not a fact.
Post-quantum by default
Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design.
Runs where you decide
License QS-WAN onto your own hardware, take a gateway we ship configured, or let us host it. Licensed in-house, the console for every tenant’s segments stays on your side of the wall.
What the auditor asks, and where the answer already lives
Data center security standards word it differently and keep coming back to four questions. Here’s where QS-WAN keeps each one, so audit week goes on reading, not rebuilding.
Which segments belong to this tenant?
The tenant’s gateway, its VLANs and LANs, and the address space reserved for them, all drawn in the Network Map.
Can anything reach them from outside the tenancy?
The edges on that map, each one-way, two-way, disabled or zero trust, plus the firewall rules set per gateway and per user.
Who can get in, and from which device?
Each user profile, its devices and one certificate per gateway membership, with a CSV export for the auditor’s file.
Is it checked, or only configured?
Automated assessments on each gateway return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators. More on staying ready for the audit.
Before you show anyone a screen. A green confirmation means the change was recorded. A gateway that was offline applies it when it reconnects, so check they’re all online before calling the record current.
What stays outside the console
Most data center security solutions cover the building or the network. This one covers the network, and here’s where it stops.
The building
Physical data center security systems, like badges, cages, cameras and visitor logs, aren’t what this does. They stay with your facilities team.
Networks it doesn't run
QS-WAN shows the separation it enforces. A VLAN on a switch or hypervisor it doesn’t manage is outside its view, so it can’t vouch for it.
The verdict
The platform produces evidence. Your auditor decides whether it’s enough, and a segmentation penetration test is still done by a tester, not a console.
Watching your tenants
Nobody at QuantumNova looks at tenant traffic or sits in your NOC. The console is yours, and so is everything it records.
Bring the questions from your last tenant audit
The demo is free. Show us what the last auditor asked, and we’ll walk through where each answer lives in the console.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.