How tenants are separated in storage, compute and configuration, and what guarantees that separation.