IOSOR Learn

Partner incident week: isolation break is a freeze, not a shared export

Handle the first partner isolation breach by freezing the tenant export without leaking rail brands or commmingling prepaid balances.

Partner incident week: isolation break is a freeze, not a shared export.

Incident response to tenant isolation breach

The first serious partner incident tests core routing boundaries. When an isolation break occurs in a white-label prepaid CPaaS deployment, platform operators must act fast. Do not panic and do not run a shared raw database dump. A raw export risks leaking underlying carrier metadata or exposing transit paths that must remain hidden from white-label tenants.

Freezing the tenant data stream

Immediate containment requires an absolute freeze on the affected partner tenant. Cut off all inbound and outbound API requests for the compromised space immediately. This stops potential data exfiltration and prevents rogue scripts from churning through remaining USD 20 prepaid floor balances or triggering unauthorized OTP traffic bursts. Maintain system integrity by securing the snapshot locally.

Validating the isolation perimeter

Review audit logs to determine how the breach happened. Check whether tenant boundaries leaked via webhook endpoints, DLR delivery callbacks, or shared HB monitoring paths. Our architecture relies on strict JIT provisioning and prepaid hold mechanisms for numbers, ensuring no physical idle stock pool or shop-stock inventory is ever exposed. Every asset remains strictly scoped to its assigned tenant namespace.

Checking related isolation protocols

For context on how steady-state platform boundaries operate, review our guide on Partner Second Month: Tenant Isolation Persistence on Renewal. It details how stable accounts maintain strict segregation beyond the initial setup window. Additionally, verify that any routine maintenance respects the principles outlined under Partner ledger isolation edge cases to prevent billing bleed between tenants.

Safe data extraction mechanics

When stakeholders demand proof or forensics, never provide a mixed database export. Instead, generate a verified Partner brand-safe export at 02:00 that strips out all underlying carrier footprints and internal routing logic. This keeps your white-label positioning completely intact while satisfying compliance audits and security reviews.

Start with IOSOR

Open the IOSOR console immediately and apply an emergency tenant freeze on the affected partner space to block all inbound and outbound API traffic. Audit active DLR callbacks, webhook endpoints, and heartbeat monitoring paths to verify that boundary leakage has been fully contained. Once the perimeter is verified, schedule a sanitized export using the brand-safe export pipeline instead of running a raw database dump.

IOSOR takeaway

An isolation breach demands an immediate tenant freeze rather than an unverified database dump. Cutting API streams right away prevents exfiltration across shared routing paths and protects neighboring tenant spaces while the perimeter is validated.

Do freeze the compromised tenant space at the gateway level and audit all webhook and DLR delivery paths immediately. Do not execute raw database exports or expose internal routing logic during incident forensics.

Was this guide helpful?

Related guides