Industries · Multi-tenant facilities

Data center security: tenant separation you can show

Data center security in a shared facility has two jobs: keep tenants apart, and show an auditor that they’re apart. QS-WAN gives each tenant its own gateway and network segments, draws every permitted link on one map, and keeps the record of who can reach what. Physical security, the cages and badges, stays with you.

What a tenant's auditor asks first
Q1
Which segments are the tenant's?
Q2
Can the tenant next door reach them?
Q3
Who holds a way in, and on which device?

QS-WAN answers all three from the network it runs, not from a spreadsheet.

The constraint

Shared power, shared switches, separate promises

A multi-tenant data center sells something nobody can see. Tenants share the power, the cooling, the fibre and usually the switching fabric, and every contract still says each tenant’s network is theirs alone.

Keeping that true is ordinary work. Showing it is where it hurts. An auditor can walk up to a cage and rattle the door. Nobody can rattle a VLAN. Logical separation lives in configuration spread across switches, firewalls and hypervisors, written by different people over the years.

So the usual proof is screenshots and a spreadsheet of VLAN IDs, exported the week before the audit.

A spreadsheet of VLAN IDs proves one thing beyond doubt: that the spreadsheet exists.
Why it's harder in a shared facility
01

Every tenant brings an auditor

ISO/IEC 27001 has a control for segregation of networks. If segmentation keeps systems out of PCI DSS v4.0 scope, it has to be penetration tested every year, or every six months for service providers. NIS2 puts data center service providers in its digital infrastructure sector.

02

Separation drifts

A migration needs a temporary link. A tenant leaves and their address range gets reused. Each change makes sense on the day. The auditor sees the sum of all of them.

03

Your own people cross every line

Remote hands and on-call engineers work across tenants, and they’re supposed to. The question is whether you can list exactly which tenants each of them can reach today.

How QS-WAN keeps tenants apart

A gateway per tenant, and every link on one map

QS-WAN runs a private network from one console, and QNova Client connects each person’s device to it. In a shared facility, that comes down to three things.

01

A gateway for each tenant

Each tenant’s segment sits behind its own gateway, a hardware box or software on hosts you already run, with its own VLANs, address space and firewall rules. It goes in next to your existing switching, not instead of it.

02

Links you can see, and switch off

In the Network Map, a connection between two segments is an edge you switch on or off. Between two VLANs, the change applies both ways. A VLAN set to zero trust stays default-deny, whatever tunnel mode it uses.

03

A certificate for each way in

A device holds a separate certificate for each gateway it belongs to. An engineer who looks after three tenants has three memberships, and revoking one leaves the other two alone. When a device enrols, what it says about itself is treated as a claim, not a fact.

Underneath, the same everywhere

Post-quantum by default

Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design.

Runs where you decide

License QS-WAN onto your own hardware, take a gateway we ship configured, or let us host it. Licensed in-house, the console for every tenant’s segments stays on your side of the wall.

Data center security standards

What the auditor asks, and where the answer already lives

Data center security standards word it differently and keep coming back to four questions. Here’s where QS-WAN keeps each one, so audit week goes on reading, not rebuilding.

Q1

Which segments belong to this tenant?

The tenant’s gateway, its VLANs and LANs, and the address space reserved for them, all drawn in the Network Map.

Q2

Can anything reach them from outside the tenancy?

The edges on that map, each one-way, two-way, disabled or zero trust, plus the firewall rules set per gateway and per user.

Q3

Who can get in, and from which device?

Each user profile, its devices and one certificate per gateway membership, with a CSV export for the auditor’s file.

Q4

Is it checked, or only configured?

Automated assessments on each gateway return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators. More on staying ready for the audit.

Before you show anyone a screen. A green confirmation means the change was recorded. A gateway that was offline applies it when it reconnects, so check they’re all online before calling the record current.

Where it stops

What stays outside the console

Most data center security solutions cover the building or the network. This one covers the network, and here’s where it stops.

The building

Physical data center security systems, like badges, cages, cameras and visitor logs, aren’t what this does. They stay with your facilities team.

Networks it doesn't run

QS-WAN shows the separation it enforces. A VLAN on a switch or hypervisor it doesn’t manage is outside its view, so it can’t vouch for it.

The verdict

The platform produces evidence. Your auditor decides whether it’s enough, and a segmentation penetration test is still done by a tester, not a console.

Watching your tenants

Nobody at QuantumNova looks at tenant traffic or sits in your NOC. The console is yours, and so is everything it records.

Bring the questions from your last tenant audit

The demo is free. Show us what the last auditor asked, and we’ll walk through where each answer lives in the console.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top