A multi-tenant GRC SaaS provider
AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)
VeUP ran a six-pillar AWS Well-Architected Review for the customer multi-tenant GRC SaaS (~60 customer environments on Amazon EKS/RDS), surfacing 55 risk items (39 High, 16 Medium), a ~$600/month avoidable IPv4 cost, and a Top-5 remediation roadmap toward a multi-account, hub-and-spoke target state.
The challenge
the customer operates a multi-tenant GRC platform on AWS serving ~60 customer environments that had grown organically. All environments (Production, Dev, Trials) resided in a single AWS account, so one compromise's blast radius spanned every customer; the Root account had no MFA; every EC2 instance carried a public IP (no NAT Gateways), widening attack surface and adding avoidable IPv4 cost; observability was limited to Route 53 health checks and manual error review; RPO was 24h on nightly snapshots with manual, customer-by-customer restoration; and OS patching was manual ahead of the AWS Inspector Classic retirement. the customer needed an objective, prioritized risk read across security, resilience, cost, and operations.
The solution
A structured AWS Well-Architected Framework Review across all six pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability — combining a stakeholder-interview workflow with evidence-based scoring to produce a per-pillar risk profile and a concrete remediation approach per finding. Top-5 remediations: (1) Root hardware MFA then AWS Organizations multi-account isolation; (2) hub-and-spoke network with centralized NAT Gateway egress so instances move to private subnets; (3) Amazon CloudWatch with targeted metric filters + centralized fleet dashboard; (4) automated restoration + cross-region snapshot copying for RTO/RPO; (5) AWS Systems Manager Patch Manager automation + a cost-effective scanning approach ahead of Inspector Classic retirement. The review built on existing strengths — a CI/CD pipeline with Dry-Run security checks, broad Multi-AZ, and managed Amazon EKS / Amazon RDS.
Architecture
AWS Well-Architected view of the reviewed estate — from the single-account, public-IP EC2 fleet and manual operations of the previous state through to the target AWS Organizations multi-account, hub-and-spoke design with private-subnet Amazon EKS/RDS, centralized NAT Gateway egress, and the Security and Observability & DR rails that carry the Top-5 remediation roadmap.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | 6 of 6 Well-Architected pillars assessed and risk-rated; 55 prioritized risk items documented (39 High, 16 Medium), each with finding, risk, and remediation; per-pillar risk levels delivered (Security/Reliability/Cost/Ops/Performance High, Sustainability Medium); ~$600/month avoidable IPv4 address cost identified with a concrete elimination path via hub-and-spoke / NAT Gateway; a Top-5 strategic remediation roadmap ranked by business impact and effort. |
| Engagement window | 2026-02-13 (WAFR review date) → 2026-02-13 (executive summary delivered); remediation is the customer's forward roadmap |
| Cost / TCO posture | The Cost Optimization pillar quantified a ~$600/month avoidable IPv4-address cost (every EC2 instance public-IP'd, no NAT Gateways), with a hub-and-spoke / NAT Gateway egress path to eliminate it. Annual AWS spend ~$99K (~$8.25K/month), onboarded to VeUP Managed Billing. |
| Lessons & continuation | Single-account multi-tenancy is the dominant structural risk for an organically-grown GRC SaaS — multi-account isolation and Root MFA lead the roadmap; a hub-and-spoke / NAT Gateway egress redesign closes attack surface and removes IPv4 cost in one move; sequence remediation by business impact and effort so a security-first customer can act immediately. |
AWS Well-Architected Tool · Amazon EKS · Amazon RDS · Amazon EC2 · Amazon VPC · NAT Gateway · AWS Organizations · Amazon CloudWatch · AWS Systems Manager · Amazon Route 53 · AWS IAM