Solutions
Stackap for SaaS products
Stackap can host a multi-tenant SaaS app and its database, but the isolation between your customers inside the app is still your code's job, not the platform's.
The situation
There are two different meanings of multi-tenant here, and they are worth separating. Stackap itself is multi-tenant: it keeps different organizations' projects, tokens and keys apart from each other. A SaaS product is multi-tenant in a second way, keeping its own customers' data apart inside one app and one database.
Stackap provides the first and cannot provide the second. Your customers all live behind one project, as far as the platform can tell.
What Stackap gives you here
- A project and a private Postgres database for the app, with a role that reaches nothing else.
- The pattern for tenant isolation used by the founder's own CRM, which serves about a hundred businesses from one codebase: a customer identifier on every row and one place in the code that filters by it. It is a reference, not a feature you switch on.
- Scheduled jobs, storage and backups for the app.
- Separate organizations on Stackap, if you want a customer's dedicated environment walled off from the rest.
How it looks in practice
The app's own isolation is the part that deserves the most testing. The founder's approach is a single wall module that every query goes through, a static check that fails the build if any query skips it, and a suite of attack tests. The same discipline protects Stackap's own organizations, with 43 cross-organization attempts all refused.
On the hosting side, plan for a staging project with its own database, a backup you have restored at least once, and cron jobs written to be safe to call twice.
Early-access fit
Early access is a less natural fit if you need recovery to a moment in time. A SaaS can lose a customer's work in a day, and daily backups with no point-in-time recovery are a real step down from a hosted database.
Early access is a less natural fit if you need a high-availability or multi-region story for contracts. One server in one region is what exists.
Early-access scope
- Stackap does not isolate your customers from each other; your app does.
- No point-in-time recovery, no standby, one region.
- A second, database-level lock such as row-level security is something your app can use in Postgres, but the platform does not set it up for you.
- No compliance certifications.
Questions
Does Stackap give each of my customers a database?
Where is the tenant-isolation pattern written down?
Stackap is in early access. Tell us what you run and we will reply with a straight answer about whether it fits.
Ask for an invitationLast updated .