Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should enterprise teams ask for VPC or…
Governance, Ownership & Risk

When should enterprise teams ask for VPC or single-tenant deployment?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Ask when the AI service will handle sensitive data, operate in regulated environments, or need to satisfy strict sovereignty and internal policy requirements. Those deployment modes give buyers stronger control over isolation and data handling than shared defaults.

When VPC or single-tenant deployment is the right control

Ask for it when the deployment boundary itself matters to the security decision. That usually means the service will process sensitive or regulated data, must meet data residency or sovereignty commitments, or must satisfy internal policy that shared infrastructure is too broad for the use case. The value is not just privacy, it is tighter isolation, clearer control boundaries, and better evidence for auditors and internal approvers.

VPC and single-tenant options are most useful when your risk team cares about who can co-reside, where traffic can traverse, and how much of the platform is shared. In practice, those choices can reduce exposure from noisy-neighbor effects, simplify network segmentation, and make it easier to enforce private connectivity, restricted egress, and tenant-specific guardrails. They are deployment controls first, not substitutes for data classification or access control.

They are not automatically required for every AI service. If the workload is low sensitivity and the vendor’s shared model already meets your contractual and technical requirements, a private deployment may add cost and operational overhead without changing the real risk enough to justify it. The decision should be driven by the consequence of a boundary failure, not by a generic preference for more isolation.

Risk and Threat Considerations

Shared deployment can create concentration risk when multiple customers depend on the same control plane, network path, or operational boundary. If the service handles sensitive data or supports regulated workflows, a weakness in tenant isolation, logging, or network segmentation can turn a single control failure into a broader exposure.

Failure mechanism: Inadequate isolation, misconfigured private connectivity, or cross-tenant data handling can expose data to unintended access paths, weaken segregation evidence, or make compliance commitments harder to prove.

Impact: The result can be data exposure, failed audit expectations, sovereignty non-compliance, or a forced redesign after the service is already embedded in a critical workflow.

How to decide whether to require it

Use the deployment model as a compensating control only when it maps to an actual requirement. If your requirement is regulatory, ask whether the vendor can show control over residency, subcontracting, logging, and tenant segregation, not just whether it can say “private.” If your requirement is internal policy, define the specific condition that shared tenancy violates, such as production secrets, restricted datasets, or cross-border processing. When those conditions are absent, the stronger choice may be configuration, encryption, or access governance rather than dedicated infrastructure.

Where the business case is strong, include the deployment requirement early in procurement and architecture review. Retrofitting isolation after integration is harder, more expensive, and often incomplete because dependencies, telemetry, and support processes have already been designed around the shared path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022, GDPR and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyDeployment isolation is a risk treatment decision for sensitive and regulated AI services.
Recommendation — Define when private or single-tenant deployment is required as a risk treatment criterion.
ISO/IEC 27001:2022A.5.15 — Access controlTenant isolation supports stronger control over who can access hosted data and services.
A.8.24 — Use of cryptographyPrivate deployment decisions often sit alongside stronger handling of sensitive data and traffic.
Recommendation — Require documented access and segregation controls for shared versus dedicated deployments. Pair isolation requirements with encryption and key-handling expectations for sensitive workloads.
GDPRArt. 32 — Security of processingDeployment isolation can support appropriate technical measures for regulated personal data.
Recommendation — Assess whether the hosting model provides security of processing appropriate to the data risk.
NIS2Article 21 — Cybersecurity risk-management measuresDedicated deployment can be part of the risk-management measures expected for critical services.
Recommendation — Document when tenant isolation is needed to satisfy risk-management obligations.

Practitioner Guidance

What to verify: Confirm whether the vendor’s VPC or single-tenant offering changes only the network boundary or also the operational boundary, including patching, support access, telemetry retention, and backup handling. Those details determine whether the control actually reduces risk.

Decision rule: If the service will store regulated or highly sensitive data, or if policy requires tenant segregation beyond standard SaaS controls, make deployment isolation a gate in the buying process. If not, require the vendor to justify why shared tenancy still meets the same risk and compliance outcome.

What good looks like: The deployment choice is tied to a documented requirement, the isolation model is explicit, and the vendor can explain how tenant boundaries are enforced in production rather than only in marketing language.

Practitioner takeaway: Ask for VPC or single-tenant deployment when isolation is a requirement, not a preference, and treat it as one part of a broader control set that still needs data classification, access restrictions, and vendor evidence.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org