Multi-Tenant SaaS Web Application
Dexfense ReviewedStandard architecture for a cloud-hosted SaaS product with REST APIs, SQL database, CDN, WAF and OAuth/SSO for customer authentication.
Overview
Represents a typical multi-tenant B2B or B2C SaaS product hosted on a major cloud provider. Includes web application servers, REST APIs, a relational primary database, a caching and session layer, object storage, load balancing, WAF-protected ingress, centralised logging and backup systems. MFA is applied to admin and staff accounts; OAuth 2.0 and OIDC handle customer authentication.
Intended for
Security engineers, DevOps leads and CTOs responsible for securing a cloud-hosted SaaS product.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- Application is internet-facing; all traffic is TLS-encrypted
- Tenant data is segregated at the application layer
- Cloud provider manages physical infrastructure and hypervisor security
- OAuth 2.0/OIDC is the primary authentication mechanism for end users
- Admin access uses MFA and is restricted by IP or zero-trust policy
Out of Scope
- Multi-tenancy isolation at the OS and hypervisor level is not modelled
- Third-party integrations and webhook consumers are not assessed
- Assumes a single cloud region; multi-region failover is not covered
Architecture Components13 components selected
Web & APIs
Web Servers
Public-facing web application servers
API Services
API endpoints for application integration
CDN
Content Delivery Networks for distributed hosting
Databases
SQL Databases
Relational databases holding structured data
NoSQL Databases
Non-relational databases for unstructured data
Auth & IAM
OAuth/OIDC
Open authorization and identity protocols
Multi-Factor Auth
Additional authentication verification layer
Storage
Cloud Storage
Cloud-based object or file storage
Backup Systems
Data backup and recovery systems
Network
Load Balancers
Traffic distribution systems
WAF
Web Application Firewall
DNS Services
Domain name resolution services
Monitoring
Logging Systems
Centralized log collection and management
Security Preview
Based on this architecture's component selection
Indicative Risk Score
56/100
10 techniques identified
1 Critical · 2 High
Top Attack Techniques
- CriticalT1486Data Encrypted for Impact
- HighT1190Exploit Public-Facing Application
- HighT1070Indicator Removal on Host
- MediumT1078Valid Accounts
- MediumT1110Brute Force
Top Recommended Controls
- 1Implement Web Application Firewall (WAF) and regular security testing
- 2Focus on Data Protection as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.