Dexfense

Know your attack surface.Build your defense.

Map your system architecture to MITRE ATT&CK® and get a prioritised, exportable security defense plan — in minutes.

MITRE ATT&CK® mapped 70+ components covered NIST CSF 2.0 Gap Analysis Exportable PDF reports
70+ Security Components
200+ ATT&CK® Techniques
NIST CSF 2.0 Aligned
Free to Use
HomeCommunity LibraryMulti-Tenant SaaS Web Application

Multi-Tenant SaaS Web Application

Dexfense Reviewed

Standard architecture for a cloud-hosted SaaS product with REST APIs, SQL database, CDN, WAF and OAuth/SSO for customer authentication.

Cloud & SaaSWeb ApplicationsEnterprise
13 components·By Dexfense·v1.0 · July 2026

Overview

Represents a typical multi-tenant B2B or B2C SaaS product hosted on a major cloud provider. Includes web application servers, REST APIs, a relational primary database, a caching and session layer, object storage, load balancing, WAF-protected ingress, centralised logging and backup systems. MFA is applied to admin and staff accounts; OAuth 2.0 and OIDC handle customer authentication.

Intended for

Security engineers, DevOps leads and CTOs responsible for securing a cloud-hosted SaaS product.

Architecture Assumptions

This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.

  • Application is internet-facing; all traffic is TLS-encrypted
  • Tenant data is segregated at the application layer
  • Cloud provider manages physical infrastructure and hypervisor security
  • OAuth 2.0/OIDC is the primary authentication mechanism for end users
  • Admin access uses MFA and is restricted by IP or zero-trust policy

Out of Scope

  • Multi-tenancy isolation at the OS and hypervisor level is not modelled
  • Third-party integrations and webhook consumers are not assessed
  • Assumes a single cloud region; multi-region failover is not covered

Architecture Components13 components selected

Web & APIs

Web Servers

Public-facing web application servers

API Services

API endpoints for application integration

CDN

Content Delivery Networks for distributed hosting

Databases

SQL Databases

Relational databases holding structured data

NoSQL Databases

Non-relational databases for unstructured data

Auth & IAM

OAuth/OIDC

Open authorization and identity protocols

Multi-Factor Auth

Additional authentication verification layer

Storage

Cloud Storage

Cloud-based object or file storage

Backup Systems

Data backup and recovery systems

Network

Load Balancers

Traffic distribution systems

WAF

Web Application Firewall

DNS Services

Domain name resolution services

Monitoring

Logging Systems

Centralized log collection and management

Security Preview

Based on this architecture's component selection

Indicative Risk Score

56/100

10 techniques identified

1 Critical · 2 High

Top Attack Techniques

  • CriticalT1486Data Encrypted for Impact
  • HighT1190Exploit Public-Facing Application
  • HighT1070Indicator Removal on Host
  • MediumT1078Valid Accounts
  • MediumT1110Brute Force

Top Recommended Controls

  • 1Implement Web Application Firewall (WAF) and regular security testing
  • 2Focus on Data Protection as your highest priority security initiative

The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.

Use This ArchitectureRemix This Architecture

Remix copies the components so you can add or remove items before generating your assessment.

Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.

Back to Community Library