
Service 06
Enterprise Platforms
Platforms that have to survive a procurement process, a penetration test and a decade of other people maintaining them.
- Capability 1
- Multi-tenancy
- Capability 2
- Identity
- Capability 3
- Billing
- Capability 4
- Reporting
The approach
An enterprise platform is judged on the things that are invisible in a demo: whether tenants are genuinely isolated, whether every privileged action is logged, whether access can be revoked in one place, whether the data can be exported when the contract ends.
These are architectural decisions made in the first fortnight. Retrofitting tenant isolation onto a system that assumed one customer is close to a rewrite, and every experienced reviewer knows to ask.
We build for the review deliberately: isolation, identity, audit and evidence as first class requirements, with the documentation that a security questionnaire expects.
- 01
Fix the boundaries
Tenancy, identity and audit are settled first, in writing, because they are the decisions that cannot be deferred.
- 02
Build to be reviewed
Development runs with the security questionnaire visible, so evidence accumulates rather than being assembled in a panic.
- 03
Prove operability
Restore from backup, rehearse the rollback, run the load test. A platform is ready when those have happened.
What you get
Deliverables, not a status update.
- 01
Tenant isolation
Enforced at the data layer, not only in application code, and tested adversarially.
- 02
Identity and access
SSO, SCIM provisioning where needed, role and attribute based access, revocable in one place.
- 03
Billing and metering
Usage recorded accurately enough to invoice from and to argue about.
- 04
Reporting
Tenant scoped analytics and exports, so customers can answer their own questions.
- 05
Audit and evidence
Privileged action logging, retention policy and the artefacts a security review asks for.
- 06
Operational readiness
Backups tested by restoring them, capacity modelled, rollback rehearsed.
Questions
Answered straight.
- Do you support FedRAMP or SOC 2 work?
- We build to the controls and produce the evidence. The certification itself runs through your auditor, and we support that process.
- Can you retrofit multi-tenancy?
- Sometimes, and it is always more work than expected. We will assess honestly rather than quote optimistically.
- What about data residency?
- Designed in from the start where it is a requirement, including how it constrains model routing for any AI components.
Start here
Have an enterprise platform problem?
You will speak to an engineer, and you will leave the first conversation with an opinion about your problem whether or not you hire us.