---
title: How Secret Isolation Affects Your Data Security Mechanisms
description: When it comes to software, using the central model can ease access control and auditing, tokenization will leverage a central access model.
image: https://insights.comforte.com/hubfs/Secret%20Isolation_v1.5.jpg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![Secret Isolation comforte AG](https://insights.comforte.com/hubfs/Secret%20Isolation_v1.5.jpg)](https://insights.comforte.com/how-secret-isolation-affects-your-data-security-mechanisms)

[Trevor J. Morgan](https://insights.comforte.com/author/trevor-j-morgan) l Jul 14, 2020 l [Data Protection](https://insights.comforte.com/tag/data-protection)

# How Secret Isolation Affects Your Data Security Mechanisms

When it comes to processing sensitive data, enterprises must make sure that they have comprehensive security parameters in place in order to protect personal information from unauthorized access. *Encryption* is a highly touted means of security. While this can be a positive and useful method to secure data, the downside of encryption is that it does not leave you with security completely assured. The reason is that, while the information does not appear in plain text, it is easily decipherable if the associated encryption key is acquired. Quite frankly, these keys can be difficult to keep track of, especially in a working-from-home environment in which encryption keys may be shared on messaging platforms or with people who shouldn’t have access to them.

This is where the concept of secret isolation comes into play. You can leverage secret isolation in two different ways to protect your personal data – a **central access model** and a **shared access model**. Each method is highly dependent on your business needs. In a central access model, the protection system and its secrets are stored in a centralized location. For a non-technical example, think of building security. When protecting a building, a security guard with keys acts as the sole and central enforcer of security, denying third-party access to those who don’t warrant it, and only granting access to those who require it. All access decisions depend entirely on the security guard.

![Secret Isolation_v1.3](https://insights.comforte.com/hs-fs/hubfs/Secret%20Isolation_v1.3.jpg?width=538&name=Secret%20Isolation_v1.3.jpg)

In a shared access model, the protection information is shared and distributed to all the instances that need access to this sensitive information. Extrapolating to the same building analogy as above, the security and keys are distributed to everyone who requires access to the building, not just to the central security guard. In large enterprises, this could quickly rise to thousands of people having keys. As you no doubt have seen in building scenarios like this, people can share physical keys or key fobs in certain situations—“hey, can I use your security card to go to the bathroom?”—even when rules expressly prohibit it. Who can keep track of all those keys?

## Challenges & Opportunities  

Clearly, in the central access model, you can easily administer access and security because only one point of granting access needs to be accounted for, whereas with the shared access mode security is more difficult to manage due to challenges inherent in monitoring who actually has access to these keys and how they are being used and shared. It is much easier for those who do not have permission or access to be granted permission on a case-by-case basis.

That is not to say that the central access model doesn’t have its own challenges. Imagine in our building analogy that the security guard is off sick—well, then, nobody is at the guard desk! Perhaps you’ve walked into a secured building with nobody in attendance in the lobby, and you just stood there alone wondering whom to call? The result is that no one can access the building, even if access is required and permitted. To circumvent this problem with centralized building security, enterprises should and do implement a team of guards who work in shifts, meaning that someone is always available to monitor and control access at any given time: somebody’s always in the lobby. Bringing this back to a data security setting, we can confidently say that allowing predetermined privileged users to act as a conduit to sensitive data is far more secure than simply handing keys to any individual who requests them. In general, the fewer people who have access to sensitive information, the more secure that data will be.

## Select wisely 

When it comes to software, using the central model can ease access control and auditing, but it is also possible to harden the system to make it more secure. In the real world, encryption is known for requiring shared secrets and subsequently necessitating complex key management. [*Tokenization*](https://www.comforte.com/fileadmin/Collateral/SB_Enterprise_Tokenization_with_SecurDPS.pdf), on the other hand, will leverage a central access model. Both methods can be implemented either way. When you’re looking for a data protection solution which addresses your specific business needs, you need to look behind the marketing jargon and understand the properties of each protection model and how it is implemented in order to meet your exact needs. To make an informed decision about your data security investment, you need to gain the necessary understanding of both the benefits and drawbacks of all possible solutions.

What type of “building” is your data environment?

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/how-secret-isolation-affects-your-data-security-mechanisms&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/how-secret-isolation-affects-your-data-security-mechanisms&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/how-secret-isolation-affects-your-data-security-mechanisms&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/how-secret-isolation-affects-your-data-security-mechanisms&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/how-secret-isolation-affects-your-data-security-mechanisms&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Which data protection method fits your use case?

Looking into classic encryption? Hashing? Tokenization? Masking? Click the thumbnail below to learn more about the most common data protection mechanisms, their properties, use cases, and how to implement them.

[![data protection methods](https://no-cache.hubspot.com/cta/default/4026697/062b88a2-940b-42a9-bac4-655fd6e23405.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/062b88a2-940b-42a9-bac4-655fd6e23405)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>