Siberson
Partnership Contact Request a Demo
Cloud & SaaS

Siberson Veriket SaaS and Multi-Tenant Architecture for Data Classification

Jul 23, 2026 · 15 min read
Back to all articles
S
Siberson Team
Jul 23, 2026 · 15 min read

Corporate data has moved beyond the office. Teams work across different operating systems and cloud applications, and a data-classification tool that merely adds a tag to files is no longer enough.

A modern data-classification platform should deploy quickly, manage many locations centrally, separate policy by organization or business unit, scale with a growing user base, produce reliable context for DLP and other security systems, and reduce the burden of updates and maintenance.

Siberson Veriket Data Classification's SaaS and Enterprise-grade multi-tenant approach turns data classification from a purely end-user function into a scalable data-governance service.

Veriket SaaSCentral classification control planeEndpointsWindows · macOS · LinuxApplicationsOffice · M365 · WorkspaceSecurity systemsDLP · SIEM · Email
Figure 1: In the SaaS model, a central control plane runs classification policy for endpoints, applications and downstream security systems.

Data classification is no longer just a labeling project

In the past, corporate data lived largely on internal file servers, employee computers and central data centers, and security teams could enforce policy inside a relatively well-defined network perimeter.

Today's working model is far more distributed. One employee drafts a contract in Microsoft Word while another uses Microsoft 365 in a browser. Technical teams work on Linux, executives prefer macOS, field teams reach email from many locations. Documents move between SharePoint, OneDrive, Google Workspace, Zimbra, file servers and various business applications.

In this environment, what matters is less where the data is and more how sensitive it is and how it must be handled.

Siberson Veriket Data Classification is an enterprise platform built to identify, classify and label documents, files and emails by sensitivity. It combines manual, policy-based automatic and — in the Enterprise tier — AI-assisted classification, and it applies labels to content as both visual markings and machine-readable, persistent metadata.

With this approach a file is no longer seen only as "contract.docx." It can also be identified as an information asset that is internal, contains personal data, belongs to finance, falls under a specific regulation, or must not leave the organization.

Once a file's security context is visible and machine-readable, DLP, email security, SIEM, access management and audit systems can all make more accurate decisions.

What is SaaS data classification?

SaaS — Software as a Service — means the software is delivered through a cloud environment operated by the provider, rather than installed on the organization's own server infrastructure.

For data classification, the SaaS model means the central management layer is operated on the organization's behalf. Endpoint components and integrations communicate with a cloud-hosted management plane. Policies are defined centrally, distributed to the relevant users or systems, and classification operations are tracked from a management console.

Siberson Veriket Data Classification is offered in two core deployment models:

  • On-Premises: the Veriket server infrastructure runs in the customer's data center or private environment.
  • SaaS: the management platform is operated by Siberson as a cloud service.

In the Veriket SaaS model the need to build server infrastructure is reduced, platform maintenance is handled by Siberson, updates are delivered centrally, and capacity scales with the number of users. The SaaS model is offered on a per-user annual subscription basis.

The strategic difference here is not only where the server runs. The real difference is how the data-classification operation is consumed. In the On-Premises model the organization builds and operates a software stack. In the SaaS model the organization consumes data-classification capability as a managed service.

What does "tenant" mean?

A tenant is an independent customer or organization space inside a SaaS platform.

Think of a business center. The building infrastructure, security system, power and shared technical services can be managed centrally, yet each company's office, staff, permissions, rules and operational data are separate.

The tenant model in SaaS platforms works with similar logic: there is a shared technology platform; each organization uses its allocated space; users and administrators act within their own authority boundaries; policies are managed within the relevant organization's scope; and reporting and operational visibility are handled in that customer's context.

For data classification a tenant is not just a technical customer record. It is also a governance boundary. Each organization's classification levels, personal-data definitions, department structure, visual labels, DLP policies, regulatory scope and reporting expectations can differ. One organization may use "Restricted," another "Confidential" or "Gizli." A financial institution's card-data policies will not be identical to a defense company's policies for project codes and technical documents. The tenant approach lets these differences be managed per organization on a central platform.

What is multi-tenant architecture?

In a single-tenant setup a separate application or infrastructure instance runs for each customer. In a multi-tenant setup multiple customers or organizations use a shared service platform while operating within their own management and policy boundaries.

On the Siberson Veriket product page, the multi-tenant capability is positioned as one of the differentiating features of the Enterprise package. The Enterprise package also includes advanced capabilities such as Linux/Pardus, Google Workspace, Zimbra, granular role-based access, agent hardening, screen watermarking and AI-assisted automatic classification.

Shared Veriket platform (multi-tenant)Tenant AOwn taxonomyOwn policiesOwn adminsOwn reportsTenant BOwn taxonomyOwn policiesOwn adminsOwn reportsTenant COwn taxonomyOwn policiesOwn adminsOwn reports
Figure 2: Multi-tenant architecture — one shared platform, with each organization managed inside its own isolated tenant.

The multi-tenant approach fits the needs of managed security service providers, distributors and service providers, holding companies, groups with multiple subsidiaries, organizations with operations in several countries, independent business units managed by central IT, and MSSPs that deliver data-security services to different customers.

With this model, data classification stops being a product that requires a separate infrastructure project for each customer and becomes a repeatable, scalable and centrally managed service.

How does the Siberson Veriket SaaS architecture work?

In the Veriket SaaS model, endpoint components communicate with a Siberson-operated cloud management layer. The central platform is the control point where classification policies, user and scope definitions, management operations and reporting are run. The overall operational flow can be pictured as follows.

1Tenant2Taxonomy3Deploy4Policy5Label6Improve
Figure 3: The Veriket SaaS deployment flow, from tenant setup to continuous policy improvement.

1. Creating the tenant environment

A tenant is defined for the organization in the SaaS environment. This space forms the management context for the organization's classification operations. The first stage typically covers organization structure, user and group scopes, the classification taxonomy, the visual markings to be used, regulatory requirements, automatic-classification rules, DLP and SIEM integrations, and endpoint platforms.

Siberson provides professional services for SaaS tenant setup, rolling out endpoint agents, directory integration, system validation, and building the classification taxonomy and policy library.

2. Defining the classification taxonomy

Every organization first needs an understandable, applicable classification model. An example structure might be Public, Internal, Confidential and Top Secret. But defining four labels is not enough. For each level you should decide what data it covers, who can use it, whether it can leave the organization, whether encryption is required, how it is marked visually, and which DLP actions it triggers.

Veriket's policy engine supports building taxonomies for areas such as privacy, finance, legal and intellectual property, and targeting policies by user, group, endpoint, region or data surface.

3. Deploying endpoint and application components

Veriket is positioned to cover different working environments including Microsoft Office, Outlook, Microsoft 365, Windows, macOS, Linux/Pardus, Google Workspace, Zimbra, SharePoint, OneDrive, and PDF, image and archive content. This breadth matters for organizations with different technology preferences. Finance may use Windows and Microsoft Office, software teams Linux, executives macOS, remote workers Microsoft 365, one subsidiary Google Workspace and another operation Zimbra. If each platform used a different classification product, labels, policies and reports would drift apart. Veriket's central approach aims to bring different platforms together under one classification model.

4. Distributing policies centrally

Once classification policies are defined in the tenant management layer, they are distributed to the relevant users, groups or endpoints. HR users' files containing personnel data, finance IBAN and financial records, legal contracts, and R&D source code and technical designs can each be handled with different automatic-classification rules. Veriket supports classification through keywords, regular expressions, content context, OCR and fingerprinting; the Enterprise tier adds AI-assisted automatic classification.

5. Persistently labeling the file

Classifying a document does not mean simply showing an on-screen prompt. Veriket can use headers, footers, document watermarks, screen watermarks, the classification level, a unique identifier and machine-readable metadata. Persistent metadata helps preserve the security context as a document moves between corporate systems, and other systems — DLP, SIEM, email security and access governance — can use that classification as a policy input.

6. Central monitoring and improvement

Classification policies should not be set once and left. Over time organizations should monitor over-used classification levels, rules that produce false positives, labels users change frequently, documents left unclassified, and policy differences between departments — and update policy accordingly. One of the key operational advantages of the SaaS model is that this management loop can be sustained from a central platform.

What does the SaaS approach give organizations?

Faster deployment

On-Premises deployments require server procurement, operating-system preparation, database setup, security controls, network configuration, backup and high availability. In the SaaS model the management platform is provided as a ready service, so the organization can focus directly on tenant setup, policy design and endpoint rollout. Siberson's documentation describes the Veriket SaaS model as a managed cloud service that removes the server-infrastructure requirement and shortens time-to-classification.

Lower infrastructure operations

Reliable operation of a classification platform requires more than installing software; the organization must also manage the server OS, database, capacity, backups, updates, monitoring and troubleshooting. In the SaaS model platform maintenance and product updates are handled by the provider, so the IT team can focus on the quality of classification policy rather than product infrastructure. This is especially valuable for mid-size and large organizations with limited security-operations teams.

Scalable user management

A classification project may start in one department and later extend to other units, locations or group companies. The SaaS approach makes it easier to expand capacity as user numbers grow. The Veriket SaaS model is positioned with elastic scalability and a per-user annual subscription.

Faster access to current capabilities

In On-Premises setups, applying new versions depends on the organization's change-management schedule, and updates can be deferred by test, approval and installation processes. In the SaaS model maintenance and feature updates are managed centrally, so time-to-access for new functionality can be shorter.

Central governance for distributed work

In remote and hybrid models not all users are continuously on the corporate network. Veriket endpoint components can keep classifying using encrypted local settings when the central console is unreachable, and synchronize policies and operational data once the connection is restored; communication intervals and endpoint resource limits are configurable. This helps classification remain effective beyond the corporate network.

The strategic value of multi-tenant for MSSPs

One of the strongest use cases for multi-tenant architecture is managed security services. In the traditional model an MSSP may have to build separate server infrastructure, application installs, update processes, monitoring and operations teams for each customer, and complexity and cost grow linearly with customer count. In a multi-tenant model the provider handles customers through a shared management architecture while running each customer's operation in its own tenant context. This gives the MSSP three key advantages.

1. A repeatable service model

Instead of running a completely different project for each customer, the MSSP can build a standard service catalog — for example:

Veriket Classification as a Service — Starter: a basic classification taxonomy, manual classification, Office and email integration, a monthly usage report.

Veriket Classification as a Service — Advanced: automatic-classification policies, OCR and fingerprinting, DLP integration, policy optimization, a monthly review meeting.

Veriket Classification as a Service — Enterprise: multi-platform support, AI-assisted classification, screen watermarking, an advanced role model, continuous policy improvement, multi-tenant operation.

2. More predictable operating cost

Standardized tenant onboarding, policy templates and reporting can reduce the cost of bringing on a new customer, making it easier for the MSSP to offer classification as a recurring monthly or annual revenue service rather than a one-off license sale.

3. A central expertise pool

It can be hard for every customer to keep a data-classification expert in house. In the MSSP model a central expert team can deliver taxonomy development, sensitive-data policy design, false-positive analysis, DLP mapping, user awareness and audit reporting to many customers. Technology investment becomes an expertise-rich managed security service.

Multi-tenant management for holdings and groups

The multi-tenant approach is not only for MSSPs. A holding may have subsidiaries in banking, manufacturing, healthcare, technology and retail, each with different classification needs, terminology and regulations. Fully separate systems lose group-wide visibility; managing all subsidiaries under one policy fails to meet local requirements. A multi-tenant approach can strike a balance: common governance principles at group level, independent policies at subsidiary level, a shared minimum classification standard, organization-specific sensitive-data definitions, local administrator authority and central security operations.

For example, a group-level principle might be set:

All documents containing personal data, trade secrets or financial records must carry a machine-readable, persistent classification label.

Yet how it is applied can vary by subsidiary — customer and card data in the banking subsidiary, patient records in healthcare, technical drawings in manufacturing, source code in technology. Tenant-based management makes it possible to address corporate standardization and operational independence within the same structure.

The link between data classification and DLP

DLP systems control data leaving the organization, but to decide correctly DLP needs to understand what the data is. On an unclassified file, DLP tries to decide from signals such as keywords, personal-data patterns, file type, destination and user behavior. Used alone these signals can produce false positives. For instance, not every document containing an IBAN carries the same risk — a public bank account number and a report with thousands of customers' financial records have very different security contexts.

By adding the classification level to the document as persistent metadata, Veriket gives DLP a stronger decision context. A policy can then be written as:

Files classified "Top Secret" and containing personal data cannot be sent to external email addresses.

This can be clearer and more manageable than a generic rule based only on content matching. In the Siberson product architecture, the ability for the labels produced by Veriket Data Classification to be used by Verikor DLP or third-party security systems is positioned as a core integration value.

VeriketPersistent label + metadataDLPReads context, decidesAllowBlock / encrypt
Figure 4: Classification writes a persistent label; DLP reads that context to make a more precise allow-or-block decision.

How should security be handled in SaaS data classification?

Delivering a data-security product as SaaS naturally raises some critical evaluation topics. During purchase or PoC, organizations should clarify the following.

Data-processing boundary

Which information is sent to the management platform — classification events, user and device details, policy results, file metadata, audit logs, content samples? The organization should assess the data flow against its own risk classification.

Data location

The geographic region where the SaaS service runs and where data is stored should be reviewed, especially for KVKK, GDPR and sector-specific regulations. Public, defense and highly regulated organizations with stricter data-sovereignty or localization requirements may prefer On-Premises; cloud-first organizations wanting fast deployment and lower infrastructure operations may consider SaaS. Siberson supports both models.

Identity and access management

The classification console is a high-value management platform, so controls such as role-based access, separation of duties, limiting administrator privileges, account lifecycle and logging of management actions should be evaluated. The Veriket Enterprise package is positioned with advanced, granular role-based access.

Communication and policy security

Policy communication between the endpoint and the central platform must be secure. The Veriket product page states that clients synchronize policy and classification records in encrypted form and can operate with encrypted local settings when the central console is unreachable.

Audit trail

It should be possible to see who performed which classification action, on which document and when. An audit trail matters not only for security events but also for internal audit, regulatory compliance, policy optimization, user awareness and incident response.

SaaS or On-Premises?

There is no single right deployment model for every organization. The decision should weigh data sovereignty, regulation, existing IT capacity, scale, operating model and deployment goals together.

Evaluation areaSaaSOn-Premises
DeploymentFasterRequires infrastructure preparation
Server managementManaged by SibersonManaged by the organization
UpdatesDelivered centrallyTied to the organization's change schedule
Commercial modelAnnual subscriptionAnnual or perpetual license options
ScalingExpands with user countBound to the organization's infrastructure capacity
Data sovereigntyRequires a cloud risk assessmentFull control within the organization's infrastructure
CustomizationStandardized service approachHigher infrastructure and configuration control
Best fitCloud-first organizations wanting a fast startPublic, defense and strict-localization organizations

An important advantage of Siberson's approach is that it does not force organizations into a single model: Veriket Data Classification can be licensed as either SaaS or On-Premises.

A recommended deployment roadmap for Veriket SaaS

Stage 1: Define the business goal

Clarify the purpose — KVKK or GDPR compliance, improving DLP effectiveness, reducing user-driven data leaks, protecting intellectual property, audit readiness, central group governance, or building an MSSP service.

Stage 2: Scope it down

Rather than covering the whole organization in the first phase, start with high-risk units: HR, Finance, Legal, R&D, Sales and the executive team.

Stage 3: Design the taxonomy

Keep classification levels as clear as possible; too many classes make it harder for users to decide. Prepare example document types and handling rules for each level.

Stage 4: Configure the SaaS tenant and policies

After creating the tenant, define user and group scopes, roles, labels, visual markings, automatic-classification rules and integrations.

Stage 5: A controlled PoC

Run a pilot with real corporate document samples. Siberson offers a time-limited, fully functional evaluation environment aligned to the SaaS-tenant or On-Premises production model. During evaluation you can test automatic and manual classification, the policy engine, visual markings, metadata, OCR, reporting and DLP integration. After a successful evaluation, the policies created can be preserved as you move to a production license.

Stage 6: Gradual rollout

After reviewing pilot results, expand distribution across critical departments, then high-risk users, the general user base, other locations and group companies.

Stage 7: Continuous improvement

In the first 30–60 days, review false positives, user behavior, classification distributions, policy conflicts and DLP events, and optimize policy.

Business outcomes of the SaaS and multi-tenant approach

Data-classification investments should not be judged on technical features alone. A successful SaaS and multi-tenant model supports the following business outcomes.

Shorter time to value

Less time spent on infrastructure preparation; the organization can direct project resources to policy and user adoption.

More predictable cost structure

A subscription model can reduce up-front cost and make it easier to treat classification as an operating-budget item.

Standardization across group companies

Different subsidiaries can be positioned under a common data-security framework.

A managed-service opportunity

Partners and MSSPs can turn data classification into a recurring-revenue security service.

More consistent security policies

Defining policy centrally helps align the classification approach across different devices and applications.

Higher DLP efficiency

When the sensitivity context of files is clear, DLP rules can be applied more precisely.

Stronger audit readiness

Traceable classification actions and policy outcomes give audit teams more concrete evidence.

Conclusion: from a product to a service

Data classification used to be seen mostly as a helper application where users picked a label while saving a document. Today classification forms the core data context for DLP policy, data-discovery work, access controls, cloud security, AI governance, regulatory compliance and data security posture management.

So a classification platform must not only produce the right label but also deliver that capability sustainably across the organization. Siberson Veriket Data Classification's SaaS model lets organizations build a central, scalable classification operation without standing up server infrastructure. Its Enterprise-grade multi-tenant capability takes this a step further, supporting the infrastructure to manage MSSP customers, group companies, organizations in different countries and independent business units on a shared technology platform.

In short, the Veriket SaaS and multi-tenant approach turns data classification from a one-off installation project into a continuously managed, scalable data-security capability that can be delivered as a service.

Frequently asked questions

Can Siberson Veriket be used as SaaS?

Yes. Siberson Veriket Data Classification is offered in both SaaS and On-Premises deployment models. In the SaaS model the management platform is operated by Siberson.

Does using Veriket SaaS require installing a server on-site?

The core purpose of the SaaS model is to reduce the need for central Veriket server infrastructure. Endpoint components and the required application integrations are placed in the organization's environment, while the management platform is provided by Siberson.

Which Veriket package includes the multi-tenant feature?

Multi-tenant is one of the differentiating capabilities offered in the Veriket Data Classification Enterprise package.

Are SaaS and multi-tenant the same thing?

No. SaaS means software delivered as a cloud service. Multi-tenant is an architectural approach that lets multiple organizations or organization spaces be managed on the same service platform.

Can Veriket work offline?

Veriket endpoint components can keep classifying with encrypted local policy settings when the central platform is unreachable, and synchronize once the connection is restored.

Does Veriket support different operating systems?

The Veriket product family is positioned to support Windows, macOS and Linux/Pardus, along with platforms such as Microsoft Office, Microsoft 365, Outlook/OWA, Google Workspace, Zimbra, SharePoint and OneDrive. Package and feature coverage vary by the selected Veriket edition.

Can Veriket integrate with existing DLP systems?

Yes. Veriket can add classification information to content as persistent metadata and share it with Verikor DLP or third-party DLP, SIEM, email-security and access-management systems.

Can a PoC be run in a SaaS environment?

Yes. Siberson can provide a SaaS-tenant or On-Premises evaluation environment aligned to the planned production model.

Cloud & SaaSVeriketData Classification
Share

See how Siberson protects your data end to end.

Request a Demo