App context security and tenant isolation guidance

Case in point, I’ve just followed up on How to retrieve the actual Jira instance I am in? - #11 by sopel with another option based on the GraphQL Gateway’s tenantContexts query, which incidentally treats the cloudId as, well, the tenant context, suggesting it to be “guaranteed to be secure” for tenant isolation?