Partners · Multi-tenant

A multi-tenant firewall console, isolated by default.

Manage many clients from one console, with each client a separate tenant — its own policy, its own boundary, its own logs. One fleet view spans every tenant and every cloud, white-labelled to your own brand, while the tenants stay cleanly apart underneath.

The tenancy model

One console, many clients, cleanly separated

Tenant isolation isn't a feature you bolt on — it's how Enforza is built. Here's what that gives a team running firewalls for more than one client.

  • Isolation by default

    Tenancy isn't an add-on you switch on — it's how Enforza is built. Each client is a separate tenant with its own boundary, so one client's policy, objects and logs never bleed into another's.

  • Per-tenant policy

    Every tenant carries its own policy, its own object manager, and its own compliance packs. Tighten one client's egress without touching another's; run advise mode for one and enforce for the next.

  • One fleet view across tenants

    See and operate every tenant's firewall from one console — deploy, set policy, push self-upgrades with rollback, and watch live logs across the fleet — while each tenant stays cleanly separated underneath.

  • Your brand on every tenant

    Run the console on your own domain (a custom FQDN) with your own branding, so each client sees your firewall and your portal regardless of which tenant they're in.

  • Each tenant's data stays theirs

    Logs stream to each client's own SIEM, never through Enforza's cloud. The firewall runs as a single Linux VM inside the client's own network, with no inbound management port and no admin UI exposed.

  • Flat economics per tenant

    A flat per-firewall licence on every tenant — no per-GB tax, no charge by CPU, instance size, protected IP or protected device. Forecast a known number per client, with volume pricing as the fleet grows.

Who builds on it

The foundation for a firewall service

Multi-tenancy is the layer that turns one firewall into a fleet you can run for many clients. Pick the angle that fits how you go to market.

FAQ

Multi-tenant firewall — common questions

Does Enforza have a multi-tenant firewall console?

Yes. Multi-tenancy is the default: you manage many clients from one console, with each client isolated as its own tenant — its own policy, its own object manager, its own boundary. One fleet view spans every tenant and every cloud, while the tenants stay cleanly separated underneath. It's the foundation for running a firewall service across many clients.

How isolated is each tenant?

Each client is a separate tenant with its own policy and its own boundary, so one tenant's configuration and logs don't cross into another's. The firewall itself runs as a single Linux VM inside each client's own network, and logs go to each client's own SIEM rather than through Enforza's cloud — so isolation holds at both the management layer and the data path.

Can I set different policy per client?

Yes. Policy is per tenant: each client has its own ruleset, object manager and compliance packs. You can run one client in advise mode while another is in enforce, scope egress differently per client, and apply different framework packs (PCI DSS, HIPAA, ISO 27001, NIST and more) tenant by tenant — all from the same console.

Can the multi-tenant console be white-labelled?

Yes — white-label is shipped. Run the console on your own domain (a custom FQDN) with your own branding and theming, so every tenant your clients see carries your name. See the white-label firewall page for exactly what's themable.

Is this for MSSPs and MSPs?

It's the tenancy model that MSSPs, MSPs, resellers and consultancies build a managed firewall line on. If you want the managed-service angle — fleet operations, margin, support — see the MSSP / MSP platform page. This page is about the multi-tenant console itself. Partner access is gated; email partners@enforza.io to get set up.

What does a multi-tenant firewall cost?

Each firewall is a flat per-firewall licence — £179/month per firewall, dropping to £149 from the sixth — plus the VM it runs on, with no per-GB data-processing charge and no charge by CPU, instance size, protected IP or protected device. You forecast a known number per tenant, and volume pricing applies as the fleet grows. At modest egress the flat line is typically 60–80% cheaper than a metered cloud-native firewall stacked with a NAT gateway.

Request access

Request partner access

Partner access is by request. Tell us about your business and the clients you serve and the partner team will be in touch to talk through the multi-tenant console, white-label setup and the commercial terms.

Prefer email? You can also reach the partner team at partners [at] enforza [dot] io .

Many clients, one console.

Run isolated tenants from one place.

Tenant isolation by default, per-tenant policy, one fleet view across every cloud — white-labelled to your brand, with flat per-firewall economics on every tenant. Partner access is by request.