Automating multi-tenant AWS infrastructure for an AI platform
A Salesforce AI platform
We worked with a Salesforce AI platform that helps enterprises cut Salesforce implementation time from months to days. As more enterprise customers came in, setting up the infrastructure for each one was taking longer than it should and slowing the whole onboarding process down.
A two-person team from Infraspec built a consistent multi-tenant AWS setup with enterprise security and compliance requirements built in.
52 min
customer environment provisioning
60%
lower infrastructure costs
3×
enterprise onboarding capacity
What was slowing enterprise onboarding down?
A new AWS account could take three to four days to set up for each enterprise customer. Security controls varied between environments, making it difficult to demonstrate the controls required by regulated industries and getting in the way of enterprise deals.
The development team was also spending around 60% of its time on infrastructure rather than the product.
How did we standardise each customer environment?
We built the setup around AWS Organizations, with separate organisational units for security, production, platform services and developer sandboxes. Each customer received a separate AWS account, while logging and audit data went into a central account. Service Control Policies applied 43 consistent guardrails.
Terraform modules covered repeatable infrastructure including VPCs, ECS clusters, RDS PostgreSQL, S3, KMS key management and Secrets Manager. API Gateway handled webhook ingress. Changes followed a GitOps flow: pull request, Terraform plan, security scan, manual approval and production apply.
How was provisioning automated for a new customer?
AWS Step Functions orchestrated the new-customer provisioning flow. Control Tower created the account with the right baseline. VPCs, Transit Gateway and PrivateLink provided networking, followed by GuardDuty, Security Hub and CloudTrail for security.
ECS provided compute, while Multi-AZ RDS, S3 and DynamoDB supplied the data infrastructure. The entire flow took about 52 minutes instead of three to four days.
How were application releases handled?
GitHub held source control with branch protection, and GitHub Actions handled builds. Rolling deployments included automatic rollback. Grafana and New Relic monitored production.
The platform was doing around 15 to 20 production deployments daily. Rollbacks took under a minute when needed, and deployment success was 99.9%.
How did the setup address enterprise security and compliance?
Network isolation used Transit Gateway and security groups, with WAF protecting public endpoints. Secrets were rotated every 30 days through AWS Secrets Manager. VPC Flow Logs and GuardDuty helped detect suspicious activity.
The work supported SOC 2 Type II and ISO 27001 certification, including monthly penetration testing through approved vendors and security controls for S3 and application workloads. SOC 2 Type II was achieved in four months; both certifications were complete within six months. The ISO 27001 audit had zero critical findings.
What changed for the business?
Customer infrastructure could be provisioned in under an hour with 100% automation and zero manual steps. The team could onboard three times as many enterprise customers, while infrastructure costs fell 60%. Uptime across customer environments was 99.95%.
New enterprise deals closed within 90 days of SOC 2 certification, and the sales cycle fell from four months to six weeks.
Want to make your infrastructure work harder for your team?
Tell us what your engineers are wrestling with.
