Skip to main content
Hamrix Logo

SaaS Product Engineering

SaaS development for UAE and free-zone product teams

B2B SaaS product development, multi-tenant cloud architecture, and residency-aware infrastructure built for UAE product teams: so DIFC and mainland clients operate securely on one scalable platform.

Where customer data physically sits is an architecture decision made in the first sprint. Moving it later means re-plumbing storage, backups, logs, and support tooling at the worst possible moment.

See the architecture
  • SaaS development company UAE
  • Multi-tenant SaaS architecture
  • Cloud application development
  • Subscription billing integration
  • UAE data residency SaaS

Regulatory Landscape

Cloud products carry data obligations from day one

A SaaS product sold into the UAE inherits obligations from its largest customer, not its average one. A single DIFC financial services customer can define your residency, audit, and sub-processor requirements for the entire platform.

The regulatory picture is layered rather than singular. Federal personal data law applies alongside the DIFC and ADGM regimes for free-zone entities, which means the same tenant can be governed by a different rule set than the tenant next to it. A product that models jurisdiction and data location per tenant, instead of per company, is what makes that supportable.

Sources: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, as published on uaelegislation.gov.ae; DIFC Data Protection Law, DIFC Law No. 5 of 2020, consolidated version July 2025 as amended by DIFC Laws Amendment Law No. 1 of 2025; ADGM Data Protection Regulations. Last reviewed October 2026.

Federal Decree-Law No. 45 of 2021 (Personal Data Protection)
The federal personal data protection law, in force from 2 January 2022, applying to the processing of personal data inside or outside the country. It sets controller and processor duties, data subject rights, breach notification and the conditions for cross-border transfer and sharing.
UAE Data Office
The federal data regulator, established by Federal Decree-Law No. 44 of 2021, responsible for data protection policy, standards, complaint handling and implementation guidance.
DIFC Data Protection Law (DIFC Law No. 5 of 2020)
The data protection regime applying inside the DIFC, including the Commissioner of Data Protection, processor registration and obligations, breach reporting, and international transfers. Amended by DIFC Laws Amendment Law No. 1 of 2025, which added a private right of action and clarified that sub-processors can fall within scope.
ADGM Data Protection Regulations
The Abu Dhabi Global Market regime, administered by its own Commissioner of Data Protection, applying to the processing of personal data in the context of activities of an establishment in ADGM.

Domain Overview

How we build multi-tenant SaaS platforms

Tenant isolation is the decision everything else follows from

Three isolation strategies exist: separate databases, a schema per tenant, or a shared schema with a tenant key. The trade is operational cost against isolation strength, and the honest answer is that most SaaS products should start on a shared schema and most enterprise deals eventually argue for more.

What matters is that the choice is explicit and enforced rather than implied by which queries somebody remembered to write. We make the tenant part of the data access path itself, so a query that forgets the tenant filter fails instead of returning someone else's rows. A mistake returns no data rather than another customer's data, and that difference is the whole game when an enterprise customer asks their auditor to look. Making the tenant's jurisdiction and data location part of that same path is multi-tenant SaaS development with per-tenant data residency, and where the product is still early MVP development for a first UAE release is usually the right first step.

Sharing a codebase does not mean sharing a database

Multi-tenancy is often confused with code reuse, and conflating them is where the real problem appears. A shared schema with strict access control is a legitimate cloud software architecture and is the right default. What is not legitimate is a shared schema where isolation depends on every developer remembering a filter in every query.

So we push tenant scoping into the data layer: row-level security, or an ORM and query builder that cannot express a tenant-unaware query. The cost is a small amount of up-front discipline. The benefit is that isolation no longer degrades as the team grows, which is the actual risk in a growing SaaS product.

Billing is a state machine, not a monthly job

Subscription billing looks simple until a customer upgrades mid-cycle, adds seats, applies a coupon from a sales deal, switches from monthly to annual, or fails a payment during a bank holiday. Each of those changes what is owed and when, and getting it wrong creates refund requests and a finance team that stops trusting the product.

We model billing as an explicit state machine: subscriptions, plan changes, proration, usage records, invoices, and payment attempts, with the rule that the source of truth is the subscription record and everything else is derived. That is what makes a revenue report trustworthy and what makes it possible to answer a customer question about their invoice without an engineer reconstructing history by hand.

Enterprise buyers ask about identity first

The question that most often decides whether a B2B deal progresses is not about the feature set. It is whether the product supports single sign-on (SSO), directory provisioning, and role mapping from the customer's own identity provider. Teams that treat this as a late feature often lose the deal on a requirement that takes weeks, not months, if it was designed for.

We build SAML and OIDC sign-in, SCIM provisioning, and role mapping as part of the core identity model rather than an enterprise bolt-on, with a permission model that is fine-grained enough to map onto how the customer's organisation is actually structured.

The public API is a product surface

If customers integrate, the public API is part of your product whether or not you designed it that way. We treat it as one: versioned contracts, generated documentation, a sandbox, a clear deprecation policy, and rate limits that behave predictably. An API that breaks customers without warning converts integration partners into support tickets.

Product Friction

What breaks as a SaaS product grows

These are the engineering and scaling failures that appear as tenant volume increases.

The problem
  • One customer's data reaches another

    A database query forgets the tenant filter, and the first notice is an enterprise customer whose own compliance officer spotted it during an audit.

  • Billing cannot explain itself

    A mid-cycle tier upgrade produces an invoice nobody can reconstruct, and the finance team starts building spreadsheets to track MRR.

  • Enterprise deals stall on identity

    Single sign-on was never designed into the identity layer, so it becomes a bespoke integration that takes a quarter and blocks other pipeline deals.

  • The public API breaks customers quietly

    A API field is renamed with no deprecation period, and the team's first signal is a customer reporting that their automated workflow failed.

  • Usage is discovered on the invoice

    Metering is aggregated at billing time rather than recorded as immutable events, so overage disputes have no telemetry data to settle them.

The engineering answer
  • Enforce tenant scope in the data layer

    Row-level security or a query builder that cannot express a tenant-unaware query, so data isolation does not depend on developer memory.

  • Model billing as an auditable state machine

    Every plan change, proration, and payment attempt is a recorded transition, so any subscription invoice can be explained line by line.

  • Build identity into the core, not the enterprise tier

    SAML, OIDC, and SCIM are part of the core identity model, with a permission system fine-grained enough for enterprise role mapping.

  • Version the public API and deprecate properly

    Contracts are versioned, changes are announced with a migration path, and breaking changes are released as new versions rather than silent edits.

Core Capabilities

Modules we build for B2B SaaS platforms

Production-ready software building blocks designed to handle enterprise requirements without technical debt.

Multi-Tenant Data Architecture

Shared or isolated models with tenant scope enforced at the data layer, tenant-aware caching, and background jobs that maintain strict context.

  • Row-level security or enforced query scoping
  • Tenant-aware cache keys and routing
  • Per-tenant rate limiting and quotas

Subscription Billing Engine

Tiered plans, per-seat licensing, usage metering, proration, dunning workflows, tax handling, and auditable financial invoicing.

  • Mid-cycle proration handled explicitly
  • Usage recorded as immutable event streams
  • Dunning sequences with retry and downgrade rules

Identity, SSO & Access Control

Passwordless, SAML, and OIDC sign-in with SCIM provisioning, role mapping, and fine-grained RBAC/ABAC permission systems.

  • SAML 2.0 and OIDC enterprise federation
  • SCIM user and group automated provisioning
  • Fine-grained role-based and attribute access control

Entitlements & Feature Gating

Plan-derived and custom contract entitlements evaluated at the application edge, enforcing strict limits across tenant tiers.

  • Plan and contract derived entitlements
  • Server-side evaluation, protected against client tampering
  • Usage quotas with soft warnings and hard stops

Public API & Webhook Platform

Versioned REST or GraphQL APIs with API key management, rate limiting, OpenAPI specifications, and signed webhooks with retry logic.

  • Versioned contracts with structured deprecation
  • Signed webhooks with automated retries and dead-letter queues
  • Scoped API keys and developer sandbox environments

Admin Control Plane & Observability

Internal support tools, system metrics, tenant-scoped administrative overrides, and immutable audit logs for operational visibility.

  • Support tooling with tenant-scoped access controls
  • Immutable audit logging of administrative actions
  • Distributed tracing and tenant SLO tracking

Reference Architecture

How the layers stack

Tenant context must persist reliably across all synchronous request paths and asynchronous background jobs.

Client Surfaces

Web applications, mobile apps, partner API consumers, and administration consoles. Never where authorization rules are evaluated.

Identity & Entitlements

Authentication, tenant resolution, entitlement evaluation, and authorization checks enforced on every request.

Domain Services

Core SaaS application logic written so tenant context is passed explicitly as an immutable parameter.

Billing & Data Layer

Subscription state machine, event ledger, usage data, and tenant-isolated database storage.

Platform & Evidence

Message queues carrying tenant metadata, audit logs, and distributed traces to answer compliance and performance queries.

A tenant-unaware query should fail to compile or execute, never silently returning another tenant's data.

Async background jobs carry tenant context explicitly within message payloads to avoid data leakage.

The subscription record is the ultimate source of truth; invoices and financial reporting derive directly from it.

Security Engineering

Controls we build in

Practical engineering controls implemented to safeguard tenant data and maintain compliance across cloud deployments.

Tenant isolation enforced below the application

Row-level security or database schema separation ensures an application-level bug cannot cross tenant boundaries.

Row-level security · tenant-scoped keys

Encryption in transit and at rest

TLS 1.3 for external endpoints, AES-256 encrypted storage volumes, and field-level encryption for sensitive PII data.

TLS 1.3 · encrypted volumes · field-level keys

Secrets and key rotation

No long-lived API keys or credentials in source code. Signing and encryption keys are stored in hardware-backed managed key vaults.

Managed key store · automated rotation · usage logging

Immutable audit log

Admin overrides, role changes, data exports, and security settings are recorded in write-once, append-only logs.

Append-only log · actor and reason capture

Dependency and supply chain hygiene

Pinned dependency versions, continuous vulnerability scanning in CI/CD, and explicit Software Bill of Materials (SBOM) generation.

Pinned deps · CI scanning · per-release SBOM

Backup integrity and restore testing

Encrypted, point-in-time database backups with automated restore drills to verify recovery time and point objectives.

Immutable retention · scheduled restore drills

Typical Stack

Technologies we reach for

  • TypeScript
  • Node.js
  • React and Next.js
  • PostgreSQL
  • Prisma or Drizzle
  • Redis
  • Temporal or BullMQ
  • Stripe Billing
  • Keycloak or WorkOS
  • Kubernetes
  • Terraform
  • OpenTelemetry

Delivery Lifecycle

How an engagement runs

  1. Product and tenancy discovery

    We analyze data isolation boundaries, subscription plan structures, and enterprise compliance requirements on your roadmap.

    OutputTenancy options analysis and plan model

  2. Architecture decisions in writing

    Tenant isolation strategy, billing state machine design, and API contract approaches are documented with trade-offs upfront.

    OutputDecision records and a diagram set

  3. Build the risky parts first

    Data isolation layers, billing engines, and entitlement checks are engineered before frontend UI development to mitigate core risks.

    OutputProven core with tests around the boundaries

  4. Isolation, billing & load verification

    We perform penetration tests for tenant boundaries, simulate complex billing edge cases, and run load tests at scale.

    OutputVerification report with residual risks

  5. Launch & operational readiness

    Deployment of observability dashboards, system runbooks, and team training for ongoing operational maintenance.

    OutputDashboards, runbooks, handover

Use Cases

What gets built

Multi-tenant platform for a DIFC-regulated customer base

Tenant isolation with configurable data location, retention policies, and sub-processor controls required during enterprise compliance reviews.

Free-zone customers get the evidence trails required by internal auditors.

Usage-based billing and metering engine

Event ingestion pipeline converting telemetry into billable metrics, matched against complex tier rates and integrated with invoicing systems.

Billing disputes are resolved instantly through clear event logs.

Residency-aware infrastructure for mainland customers

Cloud deployment configurations keeping primary data, backups, and operational logs within UAE borders for regulated mainland tenants.

Data residency is handled as a tenant configuration setting.

Bilingual Arabic and English SaaS user experience

Right-to-left and left-to-right interface layouts built into one core codebase with locale-specific formatting and per-tenant language preferences.

A single product seamlessly serves regional and international users.

Enterprise single sign-on and provisioning

SAML 2.0 and OpenID Connect identity federation paired with SCIM provisioning, automating identity lifecycles for client organizations.

User access syncs directly with enterprise HR and identity platforms.

Regulator and customer evidence reporting

Automated exports for access logs, sub-processor lists, and data processing records formatted for client data protection officers.

Compliance reviews and customer security questionnaires are answered rapidly.

Integration Surface

What we connect to

Billing and payments

  • Stripe, Chargebee, and Paddle for subscription billing and automated dunning
  • Telr, PayTabs, and Network International for local UAE payment processing
  • VAT calculation and tax compliance engines for regional and global sales
  • Usage metering event pipelines converting product telemetry into billable metrics

Identity and access

  • SAML 2.0 and OpenID Connect identity providers including Okta, Entra ID, and Ping
  • SCIM provisioning protocols for automated joiner, mover, and leaver user sync
  • UAE Pass authentication for citizen and business identity verification
  • Fine-grained RBAC and ABAC permission frameworks for tenant administration

Product and data

  • Data warehouses and analytics platforms like Snowflake, BigQuery, and ClickHouse
  • CRM and support platforms including Salesforce, HubSpot, and Zendesk
  • Feature management and rollout tools like LaunchDarkly and Flagsmith

Cloud and residency

  • Local UAE cloud infrastructure on AWS Middle East (UAE) and Microsoft Azure UAE
  • Kubernetes container orchestration and managed cloud platform services
  • S3-compatible object storage, CDN edge delivery, and failover architectures
  • Observability and APM tools including Datadog, Grafana, and OpenTelemetry

FAQ

Questions SaaS teams ask first

In local cloud regions inside the UAE (such as AWS Middle East UAE or Azure UAE regions) when customer contracts or regulations dictate local residency. Data isolation extends beyond the main database to object storage, backups, logging pipelines, and third-party sub-processors. We design data routing as a configurable per-tenant setting rather than an all-or-nothing global rule.

By treating regulatory jurisdiction as a tenant property. DIFC entities operate under DIFC Law No. 5 of 2020, while ADGM entities fall under ADGM regulations, and mainland organizations align with Federal Decree-Law No. 45 of 2021. We build per-tenant controls for data residency, consent logging, sub-processor authorization, and audit trail exports.

Yes. We engineer complete RTL/LTR interface support including bi-directional typography, mirrored layouts, localized currency/date formats, and isolated Latin identifiers. Tenants can define default language preferences, and users can toggle locales instantly without affecting performance.

Use an established billing gateway (like Stripe, Chargebee, or Paddle) for payment processing, card tokenization, and PCI compliance. Maintain the subscription state machine and entitlements inside your application core, as this represents your business logic and source of truth.

We implement explicit versioning in request headers or URL paths, publish clear deprecation schedules, and provide developer migration guides. Breaking changes are released under new API versions to ensure existing customer integrations remain stable.

We work directly within your version control repositories and cloud infrastructure. All architectural decisions, API contracts, and infrastructure definitions are documented in codebase runbooks, leaving your internal team with complete ownership and zero lock-in.

Tell us what your platform does today

Send us your current data model and the enterprise requirement that keeps coming up. We will come back with a written view of what we would change and what we would leave alone.

A 30-minute technical conversation, not a sales call.

EmailWhatsApp
© 2026 Hamrix.