Every query carries the tenant ID. The database enforces isolation, not your application code. A misrouted query returns zero rows, not someone else’s data. Auditable. Defensible.
For UK founders going from seed to Series A. A B2B SaaS without multi-tenancy is a tool with login. We build the SaaS spine your next engineer inherits without apology — and your acquirer’s diligence team walks through without flinching.
Her HR-tech SaaS was doing £1.2M ARR. The £14M acquirer pulled the offer after their CTO found a single-tenant database, an auth layer bolted on for eighteen months, and no audit log of who touched what data. The SaaS worked. It just couldn’t survive due-diligence, and nine months of rebuild was too late.
“The architecture brief was the document that closed our Series A. Their CTO read it twice and stopped asking us for things.”
Multi-tenant SaaS platforms shipped since 2019, FTSE-100 to pre-seed.
Row-level security leaks in production across all 84 platforms.
Series A & acquisition diligence reviews passed in 2025 alone.
Every B2B SaaS we’ve shipped since 2019 has the same six load-bearing decisions made on day one. Each one is hard to retrofit. Each one closes a question on Tuesday’s diligence call. Open any row.
Every query carries the tenant ID. The database enforces isolation, not your application code. A misrouted query returns zero rows, not someone else’s data. Auditable. Defensible.
Users belong to workspaces. Workspaces own data. Roles are workspace-scoped. The data model your enterprise customer asks about in week one is the data model you wrote on day one.
Subscriptions, seats, usage, trials, dunning, proration, GBP and USD invoices, VAT. Webhooks idempotent. Tax handled. Your finance team thanks you in month three.
Owner, admin, member, viewer. Every action that touches data is logged with actor + tenant + IP + timestamp. Exportable. Searchable. SOC-2 stops being a panic project.
Auth.js or Clerk with the SAML / OIDC paths stubbed. When your first enterprise customer demands SSO, it’s a one-day switch, not a one-month rebuild.
One-click tenant suspend. One-click full data export per workspace in CSV + JSON. The two things every DPA and every cancellation flow needs. We wire them in week two.
The same six rungs on every custom SaaS we’ve shipped since 2019. Each rung locks before we climb the next. Click to open.
Sign-up, workspace creation, invite, role assignment. The shape every B2B SaaS shares. Week 2.
The thing the product actually does. Tested against RLS. Auditable from day one. Weeks 3-5.
Stripe checkout + subscription + invoice + dunning + GBP/USD/EUR. Tax handled. Weeks 6-7.
Internal admin to suspend tenants, refund, impersonate (audit-logged). Sentry, PostHog, Logtail. Week 8.
The 60 seconds between sign-up and first “aha”, where most SaaS lose half their trials. Weeks 9-10.
SAML/OIDC, exportable audit log, signed DPA, security questionnaire answers. Weeks 11-12.
Every SaaS founder who emails us is fighting one of these eight things. Each one is impossible to fix cheaply once the codebase is live. Each one is a single architectural decision made on day one of our build.
“We can’t add multi-tenancy now without rebuilding everything from scratch.”
Row-level security from commit one. Postgres RLS enforces tenant isolation at the database. Customer 1 and customer 1,000 use the same hot path. No retrofit. No nine-month rebuild.
“Our biggest enterprise prospect wants SSO and our auth library can’t do it.”
Clerk / Auth.js with SAML + OIDC stubbed. One-day switch from email/password to SSO when your first enterprise customer demands it. You flip a flag. You don’t lose the deal.
“Stripe is a mess. Subscriptions don’t sync, taxes wrong, refunds break invoices.”
Idempotent billing module + reconciler. Webhook reconciler verifies every Stripe event against our DB. Stripe Tax handles VAT. Idempotency keys prevent double-charges.
“We have no audit log. SOC-2 is six months of panic engineering, not paperwork.”
Append-only audit log on every mutation. Every write is logged: actor, tenant, IP, timestamp, before-value, after-value. SOC-2 readiness is 8-12 weeks of paperwork, not 6 months of rebuild.
“Our acquirer’s CTO flagged the single-tenant DB and the offer is on hold.”
Multi-tenant first, single-tenant never. The architectural brief + ADRs we ship are the documents the diligence team asks for. Three 2025 clients passed acquirer reviews on first walkthrough.
“Every new customer takes us two hours of manual setup. We can’t scale onboarding.”
Self-serve workspace provisioning. Workspace + invite + billing is one flow from day one. Customer signs up at 11pm Sunday and is paying you by Monday morning. No founder in the loop.
“We broke at 4,000 concurrent users on Black Friday. We can’t survive a real spike.”
Edge + serverless Postgres + idempotent writes. Vercel edge for reads, Neon serverless for the connection pool, Inngest queues for writes. Load-tested to 5× expected peak before handover.
“We don’t know which customer is costing us money or which feature is burning the bill.”
Per-tenant cost attribution from week one. Every paid event is logged with tenant ID. Live dashboard shows cost per customer, per feature, per day. Pricing decisions become data, not guesses.
Eighty-four B2B SaaS platforms have stress-tested these picks. Tier 1 runs every SaaS. Tier 2 is what we reach for when the brief needs it. Tier 3 scales it to Series B without a rebuild.
Helena’s SaaS, in real numbers. Single-tenant rebuilt multi-tenant in 14 weeks behind a flag, cut over one tenant per weekend. Zero data loss, zero downtime, new term sheet 11 weeks after handover.
We don’t publish prices on a page. Every SaaS scope is different. Pick the shape that fits and Mohit will send your real number inside 24 hours.
One week, fixed cost. We strip the brief, pick the stack, write the architecture, hand you a signed scope.
10-16 weeks of fixed-scope, fixed-GBP shipping. Same four seniors all the way. Architecture brief + DPA pack at handover.
After handover. Monthly retainer for a senior engineer + architectural advisory. Most clients run this 6-14 months while in-house catches up.
“The architecture brief was the document that closed our Series A. Their CTO read it twice and stopped asking us for things.”
— Helena F., founder, UK HR-tech SaaSPain-first, soft-second. The questions every founder asks after their third bad agency experience.
We don’t price by salesperson mood. The audit week is fixed at £8K. After that, every custom SaaS build is line-itemed into the scope document: workspace + auth, billing, core flows, admin tool, observability, handover pack. You see the cost of each piece, and you can cut any piece. Most multi-tenant SaaS builds we sign land between £65K and £120K, on a 10-to-16 week fixed-price sprint. If we can’t hit your budget, we tell you in week one and you walk away with the audit brief, no commitment.
Your code lives in your GitHub org from commit one. IP assigns on commit, not on final payment. Every dependency is open source or owned by you. Architecture decisions are documented in ADRs so any senior engineer can pick up the codebase in week one. If Empyreal vanished tomorrow, you’d have a working repo, a runbook, and six ADRs explaining every meaningful call. Nothing about your B2B SaaS engineering work is locked inside our walls.
Three things make this hard to fake. First, the 30-day walk-away clause goes both ways and refunds the unused portion. Second, payments are milestoned: 25% on signed scope, 25% on staging up, 25% on production live, 25% on handover. You never pay more than 25% ahead of working software. Third, we’ve been shipping since 2019 with 100+ projects under our name, listed on Companies House, with UK VAT registered. You can check us before you sign.
This is the single biggest risk with a small studio, and the reason we run our process the way we do. Every project has two senior engineers paired, not one. Every decision is written into an ADR the same day. Every commit goes through Mohit’s review. If one engineer leaves, the other has full context the next morning. In seven years, two engineers have left mid-project. Both handovers were inside 48 hours. Neither client noticed in their sprint.
Fair question. Three ways. One, the four engineers on your project are named on the page and on every Slack you join. Two, the audit week is run by those same four, not a bench team you never meet. Three, every senior on our team has shipped at least 12 production projects across SaaS, fintech, healthcare, or AI. We’ll send you their commit history on a recent project before you sign if you ask. No juniors. No bench. No bait-and-switch.
We ship every custom SaaS on the MERN stack (MongoDB, Express, React + Next.js, Node.js) with AWS for infra. As of 2026, that’s the biggest hiring pool in the UK and globally. London alone has 14,000+ Node engineers on LinkedIn. Any senior frontend or full-stack developer your future CTO interviews will be fluent in your stack on day one. Boring on purpose, hireable on purpose.
Yes, with 14 days’ notice. The engineers move to other projects, your repo stays where it is, your spend pauses. Pick it back up with 14 days’ notice and we pick up at the same sprint board, same engineers. No cancellation fee, no restart fee. We’ve done this six times in 2025. Two clients paused for four months. Both came back. Both shipped.
You walk away cleanly. The handover pack includes architecture brief, ADRs, runbook, on-call playbook, DPA, and a 30-minute video tour of the codebase for your next engineer. We offer an optional £5K/month advisory retainer if you want a senior voice on your weekly engineering calls. It’s cancellable with 30 days’ notice, any month. Most clients run it for the first six to nine months while their in-house lead settles in, then end it without ceremony. No lock-in. No surprise renewals.
Tenancy, billing, roles and audit logs designed in from day one — not retrofitted at Series A.

Tell us where you are, how many customers, and what your next 12 months looks like. Mohit reads every first email and replies inside 24 hours: a clear yes, a clear no, or the one question that decides it.
Yes, no, or the deciding question. Straight to your inbox, not a team thread.
We draw the multi-tenant spine, write the trade-offs, hand you a signed scope.
Multi-tenant, billed, audited, with the brief your acquirer’s CTO reads cold.