Security
Cloud workspace security checklist: what to verify before you buy
A practical security checklist for evaluating cloud workspaces — identity, access, auditability, data location, isolation, and deployment — with the questions to ask any vendor.
DigiEdge Workspace · 29 January 2025 · 6 min read
When you move your people’s desktops and access into a cloud workspace, security stops being about the device in someone’s bag and becomes about how the platform is built. That’s actually good news — done well, it’s more controllable and more auditable than a fleet of individual machines. But only if you can verify it.
This checklist covers the six things that matter most. Use it to evaluate any cloud workspace offering — and to ask harder questions than “is it secure?” (every vendor will say yes to that).
The checklist
1. Identity-based access
What to check: Access should be tied to identity, with single sign-on (SSO), multi-factor authentication (MFA), and role-based access control (RBAC) deciding who can reach what.
Why it matters: If access is based on the network or the device rather than the verified person and their role, you’ve lost the clearest line of control you have.
2. Brokered connections
What to check: Connections should be brokered through the platform, with no exposed endpoints and no open inbound ports to the workspace.
Why it matters: Anything directly reachable from the internet is attack surface. Brokered access means systems are reachable by authorised users without being exposed to everyone else.
3. Full session audit
What to check: The platform should be able to record and log sessions — who accessed what, and when — so activity is reviewable after the fact.
Why it matters: When something needs investigating, or an auditor asks, “prove it was controlled,” a session trail is the difference between an answer and a shrug.
4. Data stays server-side
What to check: The workload should run centrally, with nothing sensitive stored on the endpoint.
Why it matters: If data never lands on the device, a lost or compromised laptop is far less of an incident.
5. Per-workspace isolation
What to check: Each workspace should be isolated from the others.
Why it matters: Isolation contains problems. One workspace shouldn’t be able to reach into another, whether by accident or intent.
6. Deploy in your perimeter
What to check: You should have the option to run workspaces inside your own environment — private or hybrid — when policy or compliance requires it.
Why it matters: Sometimes “secure enough” specifically means “inside our boundary.” The option to deploy there should exist.
How DigiEdge Workspace maps to the checklist
We designed DigiEdge Workspace so a customer’s own team can verify all six: identity-based access with SSO, MFA, and RBAC; brokered connections with no exposed endpoints or open inbound ports; full session recording and audit; data that stays server-side; per-workspace isolation; and the option to deploy in your own private or hybrid environment. You can see how each mechanism works on our security model page.
We’re deliberately specific here — these are the mechanisms we stand behind, not a longer list of claims we can’t back.
Questions to ask any vendor
Whoever you’re evaluating, these questions separate a genuinely secure design from a convenient one:
- How is access authenticated and authorised — is it identity-based with SSO, MFA, and role-based control?
- Are connections brokered, or do they rely on exposing endpoints and opening inbound ports?
- Can every session be recorded and audited?
- Where does data live during a session — on the device, or centrally inside our boundary?
- Is each workspace isolated from the others?
- Can it be deployed inside our own perimeter if we need it to be?
The takeaway
Good cloud workspace security is something you can check, item by item, not something you take on faith. If a vendor can’t let you verify these six things, treat that as a gap — not a detail. For a broader evaluation framework beyond security, see our buyer’s guide, and if you’re planning the move, our migration guide covers the steps.