Case Studies/Agency Multi-Tenant
Product Studio & Software Development

Lab76: One Tenant Per Client,
From the First Commit.

Lab76 builds and ships software products — and a growing share of them land in industries where the buyer's first question is not about the roadmap, it is about the audit. A development studio cannot answer that question once. It has to answer it separately, and provably, for every client it builds for. Iron Fort's multi-tenant structure is how Lab76 does that without maintaining a dozen parallel compliance programs by hand.

Product StudioIndustry
SOC 2 + HIPAAFrameworks
One Per ClientTenant Model
Build PhaseStage

The Company

Lab76 is a product studio — marketplaces with payments and matching, conversion-focused websites, and native Apple applications — built around getting software actually shipped rather than perpetually maintained. Engagements run from fixed-price milestone work to embedded developers on a monthly basis, with an AI project manager attached to every engagement for visibility.

What makes the compliance picture interesting is the studio's own positioning: enterprise-ready infrastructure from day one, with SOC 2 and HIPAA-compliant foundations from the first commit. That is a promise made to every client, which means it has to be demonstrable per client — not asserted once on a marketing page.

Why this is a hard compliance problem: a studio carries two distinct obligations at once. It has its own security posture as a vendor with access to client systems, and it has the posture of each product it builds, each of which belongs to a different company, in a different regulatory context, and will eventually be audited by a different party. Running those in a single shared workspace is how evidence ends up in the wrong client's report.

The Challenge

Building regulated software for other people creates problems that a single-product company never encounters.

  • Every client is a separate compliance boundary. A healthcare marketplace and a fintech platform have different frameworks, different risk registers, different subprocessors, and different auditors. Their evidence must never mix, and neither must their access.
  • Compliance posture has to transfer at handover. A studio ships and moves on. If the security work lives only in the builder's heads or the builder's account, the client inherits a product with no provable posture — and pays to reconstruct it during their first audit.
  • The same groundwork, over and over. Access control, logging, encryption, backup, secure SDLC, vendor review — largely the same control set on every project, rebuilt from scratch each time unless something carries it forward.
  • "From the first commit" is a claim with a deadline. Retrofitting HIPAA or SOC 2 controls onto a shipped product is materially more expensive than designing them in, and the studio's differentiator only holds if the evidence starts at project start.
  • Studio staff rotate across clients. Developers move between engagements. Provisioning, review, and revocation across several client environments is precisely the control an auditor will test — and precisely the one that decays quietly.

The Solution

Lab76 runs Iron Fort as a multi-tenant estate: one tenant per client build, plus its own, administered centrally from the agency account.

A tenant per client, isolated by default

Each client build gets its own tenant with its own framework selection, control set, risk register, vendor list, and evidence vault. Nothing crosses between them, which means a diligence request from one client can never surface another client's artefacts.

One control baseline, applied per tenant

The controls common to every regulated build — access control, logging and monitoring, encryption, backup and recovery, secure development, vendor review — are established once as the studio's baseline and instantiated into each new tenant, rather than re-derived per project. Multi-Framework Overlap Detection means a build that needs both SOC 2 and HIPAA maintains the shared criteria once.

Framework selection follows the client, not the studio

A healthcare product turns on HIPAA safeguards; a SaaS platform selling into enterprise turns on the Trust Services Criteria; some carry both. The tenant is configured for the product being built, so the evidence collected is the evidence that client's auditor will ask for.

Access reviewed across the estate

Studio developers are provisioned into the tenants they work on and removed when the engagement rotates, with the review trail captured centrally. The control an auditor tests is the control the studio can produce.

Hand over the program with the product

At the end of an engagement the client does not receive a codebase and a verbal assurance. The tenant — policies, control set, risk decisions, and timestamped evidence accumulated across the build — belongs to their program and continues from there.

A note on scope: Iron Fort manages the compliance program, not the client's application data. Each tenant holds policies, controls, risk records, and evidence about the systems being built — the products themselves stay in their own environments, under their own owners.

The Outcome

Lab76's compliance claim is now something it can demonstrate per client, on the day a client asks, rather than a posture it reconstructs at the end of a build.

Clean Client Separation

One tenant per build, so evidence, risk registers, and access never cross between clients — by structure, not by discipline.

A Baseline That Travels

The controls every regulated build needs, established once and instantiated per project instead of rebuilt each time.

Evidence From Day One

Compliance artefacts accumulating from project start, which is what makes "from the first commit" a checkable statement.

A Program the Client Keeps

Handover transfers a live, documented compliance program alongside the product, rather than leaving the client to start one.

Next Case Study

Anjo.ai: Building a HIPAA Program Alongside a Connected Medical Device

Read It →

Join Our Case Study Program

Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.