VeUP
← All case studies
Production Engagement · Anonymized
A six-pillar AWS Well-Architected Review for a multi-tenant GRC SaaS
Software & Internet (multi-tenant GRC / security SaaS)
Amazon EKSAmazon RDSAWS OrganizationsWell-Architected Tool
Security Foundations · GRC SaaS Security

A multi-tenant GRC SaaS provider

AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)

VeUP ran a six-pillar AWS Well-Architected Review for the customer multi-tenant GRC SaaS (~60 customer environments on Amazon EKS/RDS), surfacing 55 risk items (39 High, 16 Medium), a ~$600/month avoidable IPv4 cost, and a Top-5 remediation roadmap toward a multi-account, hub-and-spoke target state.

The challenge

the customer operates a multi-tenant GRC platform on AWS serving ~60 customer environments that had grown organically. All environments (Production, Dev, Trials) resided in a single AWS account, so one compromise's blast radius spanned every customer; the Root account had no MFA; every EC2 instance carried a public IP (no NAT Gateways), widening attack surface and adding avoidable IPv4 cost; observability was limited to Route 53 health checks and manual error review; RPO was 24h on nightly snapshots with manual, customer-by-customer restoration; and OS patching was manual ahead of the AWS Inspector Classic retirement. the customer needed an objective, prioritized risk read across security, resilience, cost, and operations.

The solution

A structured AWS Well-Architected Framework Review across all six pillars — Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability — combining a stakeholder-interview workflow with evidence-based scoring to produce a per-pillar risk profile and a concrete remediation approach per finding. Top-5 remediations: (1) Root hardware MFA then AWS Organizations multi-account isolation; (2) hub-and-spoke network with centralized NAT Gateway egress so instances move to private subnets; (3) Amazon CloudWatch with targeted metric filters + centralized fleet dashboard; (4) automated restoration + cross-region snapshot copying for RTO/RPO; (5) AWS Systems Manager Patch Manager automation + a cost-effective scanning approach ahead of Inspector Classic retirement. The review built on existing strengths — a CI/CD pipeline with Dry-Run security checks, broad Multi-AZ, and managed Amazon EKS / Amazon RDS.

Architecture

AWS Well-Architected view of the reviewed estate — from the single-account, public-IP EC2 fleet and manual operations of the previous state through to the target AWS Organizations multi-account, hub-and-spoke design with private-subnet Amazon EKS/RDS, centralized NAT Gateway egress, and the Security and Observability & DR rails that carry the Top-5 remediation roadmap.

A multi-tenant GRC SaaS provider — AWS Well-Architected architecture diagram. Previous state: a single AWS account spanning Production, Dev, and Trials with no root MFA, ~60 organically-grown per-customer VPC architectures, every EC2 instance public-IP'd with no NAT Gateways, a modernizing Amazon EKS platform on Amazon RDS Multi-AZ, a Dry-Run Security CI/CD pipeline, Route 53 health checks with manual error review, nightly snapshots with manual per-customer restoration (RPO 24h), and manual OS patching ahead of the AWS Inspector Classic retirement. Target state: AWS Organizations multi-account hub-and-spoke with a hardware-MFA root account, a hub/network account providing centralized NAT Gateway egress, spoke accounts isolating each customer/environment behind private subnets running Amazon EKS and Amazon RDS Multi-AZ, the retained CI/CD pipeline, Amazon Route 53 health checks, an AWS IAM and AWS Systems Manager Patch Manager security rail, and an Amazon CloudWatch, cross-region snapshot copy, and AWS Well-Architected Tool observability-and-DR rail. Includes a six-pillar Well-Architected findings strip.
VeUP-rendered Well-Architected diagram from the SimpleRisk WAFR Executive Summary (2026-02-13) and the VeUP engagement record.

Production outcomes

KPIResult
Production outcomes6 of 6 Well-Architected pillars assessed and risk-rated; 55 prioritized risk items documented (39 High, 16 Medium), each with finding, risk, and remediation; per-pillar risk levels delivered (Security/Reliability/Cost/Ops/Performance High, Sustainability Medium); ~$600/month avoidable IPv4 address cost identified with a concrete elimination path via hub-and-spoke / NAT Gateway; a Top-5 strategic remediation roadmap ranked by business impact and effort.
Engagement window2026-02-13 (WAFR review date) → 2026-02-13 (executive summary delivered); remediation is the customer's forward roadmap
Cost / TCO postureThe Cost Optimization pillar quantified a ~$600/month avoidable IPv4-address cost (every EC2 instance public-IP'd, no NAT Gateways), with a hub-and-spoke / NAT Gateway egress path to eliminate it. Annual AWS spend ~$99K (~$8.25K/month), onboarded to VeUP Managed Billing.
Lessons & continuationSingle-account multi-tenancy is the dominant structural risk for an organically-grown GRC SaaS — multi-account isolation and Root MFA lead the roadmap; a hub-and-spoke / NAT Gateway egress redesign closes attack surface and removes IPv4 cost in one move; sequence remediation by business impact and effort so a security-first customer can act immediately.
AWS services in production

AWS Well-Architected Tool · Amazon EKS · Amazon RDS · Amazon EC2 · Amazon VPC · NAT Gateway · AWS Organizations · Amazon CloudWatch · AWS Systems Manager · Amazon Route 53 · AWS IAM