← all case studies

Regulated SaaS client · Dittofi

Multi-Tenant SaaS Architecture

Tenant isolation lived in application code, and every new customer or compliance rule became a custom infra project.

How Dittofi works , quick preview

Situation

A regulated SaaS client needed multi-tenant isolation at the infrastructure layer: path-based tenant routing, edge auth, and an API layer that couldn't trust the network between CloudFront and Lambda. Separately, Dittofi needed non-engineers to ship production apps with isolated customer environments, not a shared runtime with a tenant_id column.

Risk or constraint

Application-level isolation alone means one bug exposes every tenant. Manual per-customer provisioning doesn't scale past a few dozen accounts. Compliance reviewers ask where the boundary is, and 'we filter in SQL' isn't an answer.

Diagnosis

Multi-tenancy has to be an infrastructure concern, not a middleware afterthought. Routing, auth, and storage boundaries need to be enforced before requests reach business logic, especially in regulated workloads.

Work completed

  • Architected a multi-tenant backend on Lambda, API Gateway, and Aurora with CloudFront + Lambda@Edge path-based routing
  • Implemented zero-trust edge-to-API authentication so the API never assumes the edge already validated identity
  • Built Dittofi's code-generation pipeline: visual configs → deployable React frontends and Go services with isolated customer environments
  • Added RBAC and secure auth flows to generated apps so tenants ship without a platform engineer per customer
  • Codified tenant provisioning in Terraform and CI so onboarding tenant N matches tenant 1

Measurable result

Edge routing
CloudFront + Lambda@Edge tenant paths
Isolated envs
Per-customer generated deployments
Zero-trust
Auth enforced edge-to-API

Architecture or technologies

  • CloudFront
  • Lambda@Edge
  • API Gateway
  • AWS Lambda
  • Aurora
  • Go
  • React
  • Terraform
  • Cognito

What I would improve next

  • S3 Access Points per tenant for storage-heavy workloads with clearer audit trails
  • Automated tenant isolation tests in CI that fail deploys if cross-tenant data paths appear
  • Self-service tenant admin portal for provisioning, suspension, and data export

Request a tenant architecture assessment

If this pattern matches what you're seeing, describe your situation, not a job spec. I'll reply within 48 hours with an honest read.