Sealed workspaces: why one client should never see another
When you keep several clients in one tool, the first question that matters isn't features — it's isolation. Here's how TinyHub keeps every client's data sealed from the others, and why we host it in the EU.
If you’re going to keep five clients in one home base, there’s a question you should ask before anything about features: can one client ever see another? Because the day Acme catches a glimpse of Studio North’s name — in a stray notification, a shared list, a leaky export — is the day you lose both.
For anyone who works across unrelated clients, isolation isn’t a security checkbox. It’s the whole basis of the trust your business runs on. So it’s the first thing we designed, not the last.
The risk of putting clients under one roof
Consolidation is exactly what you want for yourself — one place, one login, one view of the day. But it introduces a risk that separate tools didn’t have: everything now lives together, and “together” is one bug away from “visible to each other.”
The failure modes are mundane, which is what makes them dangerous:
- A cross-client search that returns results it shouldn’t.
- An aggregated view that accidentally shows another client’s task in the wrong place.
- An export or share link that carries more than the client it was meant for.
None of these are exotic attacks. They’re ordinary leaks — and they’re what a multi-client tool has to make structurally impossible, not merely unlikely.
What “sealed” means here
In TinyHub, every client is its own sealed workspace. Concretely:
- Isolation is enforced on the server, not the screen. A request for Acme’s data is authorised against your membership of Acme — hiding data in the interface is not the same as refusing to serve it, and we do the latter. A query scoped to one client cannot return another’s rows, period.
- The aggregated “My Day” is a curated exception, and it’s yours alone. The one place that deliberately spans clients only ever assembles your view of your own work. It surfaces your tasks and deadlines; it never introduces one client to another. The seams stay sealed even in the view designed to cross them.
- Sharing is explicit and scoped. Nothing leaves a workspace unless you deliberately send it, and what you send carries only that workspace’s data.
The guarantee we’re aiming for is simple to state: Acme can never see Studio North, and neither can see your other work. Everything else is downstream of that.
Why the EU, by default
Where your data lives matters as much as who can see it. TinyHub is hosted in the EU, end to end. For a lot of our users that’s not a preference — their own clients require it, and “where is this processed?” is a question on every vendor form they fill out.
Building EU hosting and GDPR alignment in from day one means we’re not asking you to file a data-processing exception to use us. Data-subject rights, storage location, and deletion aren’t a premium add-on or a roadmap item — they’re the default posture. When your client asks where their data sits, the answer is boring, and boring is exactly what you want.
Trust is a feature you notice only when it’s missing
Nobody switches to a tool because it kept clients sealed — you only ever notice isolation when it fails, and by then it’s too late. So we’d rather over-invest here and have it feel invisible.
If you’re weighing whether to bring your clients under one roof, isolation is the right first question to ask any tool — including ours. See how TinyHub answers it: sealed per-client workspaces, EU-hosted, free while in beta.
Follow the build
Occasional notes on building TinyHub in the open — what shipped, what's next. No spam, ever.
You're in. Next build note lands in your inbox.