Security platforms manage sensitive data for many customers and cannot afford a single compromised query to cross tenant boundaries. A database per tenant or workload makes the boundary physical, encryption per database, and changes auditable.
Isolation per database means a breach of one store is not a breach of all.
Per-database encryption with customer-held keys, plus tokens scoped to a single database.
Change data capture and audit logs make access and changes traceable.
SOC 2 Type II, per-database encryption with customer-held keys, BYOC deployment
Give every tenant and workload a physical boundary in minutes, with encryption and access scoped per database.