Regulated SaaS client · Dittofi
Multi-Tenant SaaS Architecture
Tenant isolation lived in application code, and every new customer or compliance rule became a custom infra project.
Situation
A regulated SaaS client needed multi-tenant isolation at the infrastructure layer: path-based tenant routing, edge auth, and an API layer that couldn't trust the network between CloudFront and Lambda. Separately, Dittofi needed non-engineers to ship production apps with isolated customer environments, not a shared runtime with a tenant_id column.
Risk or constraint
Application-level isolation alone means one bug exposes every tenant. Manual per-customer provisioning doesn't scale past a few dozen accounts. Compliance reviewers ask where the boundary is, and 'we filter in SQL' isn't an answer.
Diagnosis
Multi-tenancy has to be an infrastructure concern, not a middleware afterthought. Routing, auth, and storage boundaries need to be enforced before requests reach business logic, especially in regulated workloads.
Work completed
- Architected a multi-tenant backend on Lambda, API Gateway, and Aurora with CloudFront + Lambda@Edge path-based routing
- Implemented zero-trust edge-to-API authentication so the API never assumes the edge already validated identity
- Built Dittofi's code-generation pipeline: visual configs → deployable React frontends and Go services with isolated customer environments
- Added RBAC and secure auth flows to generated apps so tenants ship without a platform engineer per customer
- Codified tenant provisioning in Terraform and CI so onboarding tenant N matches tenant 1
Measurable result
- Edge routing
- CloudFront + Lambda@Edge tenant paths
- Isolated envs
- Per-customer generated deployments
- Zero-trust
- Auth enforced edge-to-API
Architecture or technologies
- CloudFront
- Lambda@Edge
- API Gateway
- AWS Lambda
- Aurora
- Go
- React
- Terraform
- Cognito
What I would improve next
- S3 Access Points per tenant for storage-heavy workloads with clearer audit trails
- Automated tenant isolation tests in CI that fail deploys if cross-tenant data paths appear
- Self-service tenant admin portal for provisioning, suspension, and data export
Request a tenant architecture assessment
If this pattern matches what you're seeing, describe your situation, not a job spec. I'll reply within 48 hours with an honest read.