Single-tenant vs multi-tenant CPaaS: which isolation model fits
Which isolation model does a CPaaS account actually need?
Single-tenant isolation means your workloads run on an instance of the communications platform dedicated to your account — no other customer's traffic, data, or agents share it. Multi-tenant isolation means a shared platform where every account's data and traffic is separated by enforced boundaries, which is how nearly every CPaaS — including Orbit by Devotel — is architected. The evaluation splits on five questions: how strong the isolation boundary is, whether the account's SLA can be carved per tenant, how precisely data residency is pinned, how much control you keep over upgrade cadence, and how clean the audit scope is. On Orbit the shared platform separates every account's calls, messages, contacts, and agents, carries one published uptime SLA (99.0% on Pay-as-you-Go up to 99.99%+ on Enterprise, with service credits if it is missed), and puts residency, consent, and send-window controls in the account owner's hands — so multi-tenant delivers committed isolation without the dedicated-instance price tag. A single-tenant deployment still makes sense when a regulator or an internal risk policy demands a dedicated instance, and the trade is paying dedicated-instance cost to harden a boundary a well-built shared platform already enforces.
The one SLA test this checklist recommends — a published per-account uptime guarantee — is publicly checkable on Orbit: every plan carries a single uptime SLA across the whole surface, from 99.0% on Pay-as-you-Go up to 99.99%+ on Enterprise, with service credits if it is missed (SLA terms last updated March 9, 2026), covering voice, SMS and MMS, WhatsApp, RCS, email, video, and AI agents under one commitment. See the full SLA terms.
What to verify in either model
| Check | What to verify |
|---|---|
| Ask for the isolation boundary in writing | Whether the platform is shared or dedicated, the vendor should be able to state exactly what separates one account's calls, messages, contacts, and agents from every other account — logically, physically, or both — and put that statement in the contract, not just the sales deck. |
| Demand a published per-account SLA | A shared-platform vendor that publishes one uptime SLA per account — with service credits when it is missed — has solved the noisy-neighbour risk contractually. A dedicated-instance vendor whose SLA hides behind professional-services engagement has not. |
| Pin residency at the account level | If your regulator names a region, the residency control must be configurable and auditable per account on the shared platform — a promise to run your own instance later is not a residency control. |
| Price the upgrade cadence | Freeze-upgrade windows on a dedicated instance mean every feature release and security patch waits for your maintenance slot. On a shared platform the provider ships continuously and you get the fix the day it lands — put a price on that delay. |
| Scope the audit before you sign | On a shared platform your auditors examine your account's own records, so the evidence set shrinks. On a dedicated instance they examine the whole deployment. Pick the model whose evidence set your compliance team can actually produce. |
Multi-tenant sharing vs single-tenant isolation
| Criterion | Multi-tenant sharing | Single-tenant isolation | Orbit |
|---|---|---|---|
| Tenant isolation | |||
| Boundaries between accounts enforced in architecture | |||
| Noisy-neighbour traffic spikes contained per account | |||
| Isolation level reviewable in the contract | |||
| Per-tenant SLA carving | |||
| Published uptime SLA per account, not blended fleet-wide | |||
| Service credits when the SLA is missed | |||
| Data residency pins | |||
| Residency region configurable per account | |||
| Upgrade cadence | |||
| Provider ships continuously; no customer maintenance window | |||
| Freeze-upgrade control for change-managed environments | |||
| Audit scope | |||
| Audit evidence limited to your own account's records | |||
Posture matrix as of September 2026. Columns describe the abstract postures — multi-tenant sharing vs single-tenant isolation — without asserting any vendor's internal architecture; the Orbit column is Orbit's own shipped posture. Yes Partial No
Scenario-based decision guide
Regulated healthcare or financial services
Leans single-tenant
When a regulator or an internal risk policy demands a dedicated instance — some healthcare and financial buyers are contractually bound to one — a single-tenant deployment is the honest answer, and the provider's shared platform, however well-isolated, does not satisfy the clause. Verify the clause actually requires a dedicated instance before paying for one: many compliance teams accept a shared platform whose isolation boundary, per-account SLA, residency pin, and audit evidence set are stated in the contract.
Fast-growing SaaS or product team
Multi-tenant
A team shipping weekly cannot wait on a maintenance window for every provider release. A well-built shared platform hands you committed isolation, continuous upgrades, and pay-as-you-go economics — the dedicated-instance premium buys isolation the shared architecture already enforces, and the freeze-upgrade control costs you every security patch in the interim.
Agency or white-label reseller
Multi-tenant with isolated sub-accounts
Running communications for many downstream customers is itself a tenancy problem nested inside yours: Orbit's white-label model gives each customer its own isolated sub-account, a branded dashboard on your own domain, and per-account spend caps — committed isolation per end-customer without a dedicated instance per logo.
Single vs multi-tenant — frequently asked
- What is the difference between single-tenant and multi-tenant CPaaS?
- A single-tenant CPaaS deployment dedicates a platform instance to one customer; a multi-tenant platform shares one instance across customers behind enforced isolation boundaries. Orbit runs a multi-tenant shared platform where every account's calls, messages, contacts, and agents are separated — committed isolation without the dedicated-instance price tag.
- When does single-tenant isolation actually pay off?
- When a regulator or an internal risk policy contractually demands a dedicated instance — the honest case is a compliance clause the provider's shared isolation boundary cannot satisfy. Outside that clause, single-tenant mostly buys peace of mind at dedicated-instance cost: the money hardens a boundary a well-built shared platform already enforces.
- How does Orbit isolate tenants on its shared multi-tenant platform?
- Every account's calls, messages, contacts, and AI agents are separated by enforced account boundaries, voice traffic terminates on Devotel's own carrier-of-record softswitch, and the published uptime SLA applies per account. The account owner — not the platform mandate — controls residency, consent, and send-window settings, so the isolation boundary is contractual, not promotional.
- Can a multi-tenant platform satisfy data-residency requirements?
- Yes, when residency is pinned per account and auditable. The deciding question is whether the provider's residency control is configurable at the account level — a promise to run your own instance later is not a residency control. On Orbit, residency and related compliance controls are the account owner's to set, which keeps the answer tenant-owned rather than platform-mandated.
- Does a dedicated instance give better uptime than a shared platform?
- Not by default. Uptime tracks the SLA the provider publishes and honours, not the tenancy label. Orbit publishes one per-account SLA on its shared platform — 99.0% on Pay-as-you-Go up to 99.99%+ on Enterprise, with service credits if it is missed — which out-ranks a dedicated instance whose availability hides behind a professional-services engagement.
- What should a regulated buyer verify before choosing multi-tenant?
- Four things, in this order: the isolation boundary stated in the contract; a published per-account SLA with service credits; residency pinned at the account level; and an audit evidence set limited to your own account's records. A shared platform that clears all four usually satisfies the compliance clause without a dedicated instance — which is exactly Orbit's shipped posture.
Explore more
Committed isolation without the dedicated-instance price tag
Orbit's shared platform carries one published per-account SLA, puts residency and consent controls in the account owner's hands, and ships continuously. Start free, or talk to our team about your isolation requirements.