Your data lives in your tenant.
Each firm’s matters live in an isolated Cosmos DB partition with per-firm encryption keys. The supervisor pattern enforces tenant boundaries at the orchestration layer — sub-agents cannot reach across firms. Cross-tenant traffic does not exist by construction; it is not a policy, it is an architecture.