Since our cloud products utilize a multi-tenant architecture, we can integrate additional security controls into the decoupled application logic. A monolithic application per tenant would typically not introduce further permission checks or rate limitations, for example, in cases of high query or export volumes. The impact of a single zero-day vulnerability is drastically reduced as the scope of services is limited. Additionally, we have incorporated preventive controls into our products, all fully hosted on our legal-i cloud platform. The primary preventive controls include:
Service authentication and authorization
Strong customer isolation
Key management
Data encryption