Skip to content
thatsaas
Services // Enterprise SaaS

Enterprise SaaS development services that pass security review.

Multi-tenant architecture, SSO, role-based access, data residency and audit trails — specified at the start, because these are the requirements that cannot be retrofitted cheaply.

Scope

The requirements procurement asks about last, decided first.

Enterprise SaaS solutions live or die on questions that have nothing to do with features: how tenants are isolated, who can see what, where the data physically sits, and whether every change can be reconstructed.

We settle those in the specification. Tenancy model, identity federation, permission matrix and retention policy are written down and implemented as structure rather than as configuration added under deadline pressure.

Our own platform runs under SOC 2 Type II and PIPEDA-aligned controls in Canadian and US regions, single tenant and never co-mingled; the same discipline is what we build for clients.

  • No card, no trial clock
  • Engineer replies same business day
  • SOC 2 Type II · PIPEDA
  • Your data stays in your region

Who this is for

  • Products moving upmarket into enterprise procurement
  • Companies with regulatory or residency obligations
  • Teams facing security questionnaires they cannot currently answer
  • Organisations consolidating several business units onto one platform
Problems // What we remove

The failures this work is meant to end.

Tenancy that cannot be proven

"Logically separated" rarely survives a security review. Isolation boundaries are explicit, documented and testable.

Access rules nobody can enumerate

Permissions scattered through application code cannot be audited. Roles live in one enforceable model with a readable matrix.

Integration debt at the edges

Enterprise deployments fail at the seams — identity, directory sync, finance systems. Connectors are declarative, reviewable and reversible.

Capabilities // What we build

Engineering scope, stated plainly.

Scalable SaaS architecture

A tenancy and capacity model sized to your largest customer rather than your average one, with per-tenant limits and observability.

  • Shared, schema-per-tenant or isolated deployments as required
  • Regional residency in Canada and the United States
  • Load rehearsal beyond peak, with published results

Identity, SSO and RBAC

Federated login and a permission model that administrators can read, delegate and audit without engineering involvement.

  • SAML and OIDC single sign-on
  • Role-based access with least-privilege defaults
  • Directory-driven provisioning and deprovisioning

SaaS security and audit

Encryption, key control and an immutable record of who changed what, when and from where.

  • Field-level encryption with customer-held key rotation
  • Immutable audit log with point-in-time replay
  • Retention and export policies you set

Enterprise integrations

Bidirectional sync with the systems of record your customers already run, seated one at a time with rollback.

  • ERP, CRM, warehouse, billing and payroll connectors
  • Full-history backfill plus real-time sync
  • Clean unseating with an audit trail
Process // How we work

A sequence, not a discovery phase.

01

Specification

Tenancy, identity, residency and retention decided and priced.

02

Substrate

Environment provisioned, keyed and benchmarked.

03

Coupling

Integrations seated individually with rollback paths.

04

Torque

Load and failure rehearsal, with the graph published.

05

Handover

Runbooks, evidence pack and direct engineer access.

IsolationSingle tenant available
RegionsCanada / United States
IdentitySAML and OIDC SSO
AuditImmutable, replayable
KeysCustomer-held rotation
ExitFull structured export
Questions // Direct

Answered without a call.

Can you deploy in our own cloud account?

Yes, where the engagement calls for it. The deployment target is part of the written specification.

Do you support customer-managed encryption keys?

Yes — field-level encryption with rotation controlled by the customer.

How are security questionnaires handled?

The handover pack documents architecture, controls and data flows, which is what most questionnaires are actually asking for.

Can existing systems stay in place?

Usually. Reversible connectors let you migrate one process at a time rather than in a single cutover.

Related // Adjacent work

Where this connects.

Most engagements combine two or three of these. Start wherever the pressure is highest.

Direct booking · No sales queueCalendar open

Thirty minutes with an engineer, not a rep.

Bring your stack and your numbers. You leave with something useful either way.

  • Your current stack, volumes and failure points — reviewed live
  • An architecture sketch you keep, in your inbox the same day
  • A firm CAD price for your exact specification, no follow-up gate

Free · 30 minutes · Video or phone · Reschedule any time