Lab76 builds and ships software products — and a growing share of them land in industries where the buyer's first question is not about the roadmap, it is about the audit. A development studio cannot answer that question once. It has to answer it separately, and provably, for every client it builds for. Iron Fort's multi-tenant structure is how Lab76 does that without maintaining a dozen parallel compliance programs by hand.
Lab76 is a product studio — marketplaces with payments and matching, conversion-focused websites, and native Apple applications — built around getting software actually shipped rather than perpetually maintained. Engagements run from fixed-price milestone work to embedded developers on a monthly basis, with an AI project manager attached to every engagement for visibility.
What makes the compliance picture interesting is the studio's own positioning: enterprise-ready infrastructure from day one, with SOC 2 and HIPAA-compliant foundations from the first commit. That is a promise made to every client, which means it has to be demonstrable per client — not asserted once on a marketing page.
Why this is a hard compliance problem: a studio carries two distinct obligations at once. It has its own security posture as a vendor with access to client systems, and it has the posture of each product it builds, each of which belongs to a different company, in a different regulatory context, and will eventually be audited by a different party. Running those in a single shared workspace is how evidence ends up in the wrong client's report.
Building regulated software for other people creates problems that a single-product company never encounters.
Lab76 runs Iron Fort as a multi-tenant estate: one tenant per client build, plus its own, administered centrally from the agency account.
Each client build gets its own tenant with its own framework selection, control set, risk register, vendor list, and evidence vault. Nothing crosses between them, which means a diligence request from one client can never surface another client's artefacts.
The controls common to every regulated build — access control, logging and monitoring, encryption, backup and recovery, secure development, vendor review — are established once as the studio's baseline and instantiated into each new tenant, rather than re-derived per project. Multi-Framework Overlap Detection means a build that needs both SOC 2 and HIPAA maintains the shared criteria once.
A healthcare product turns on HIPAA safeguards; a SaaS platform selling into enterprise turns on the Trust Services Criteria; some carry both. The tenant is configured for the product being built, so the evidence collected is the evidence that client's auditor will ask for.
Studio developers are provisioned into the tenants they work on and removed when the engagement rotates, with the review trail captured centrally. The control an auditor tests is the control the studio can produce.
At the end of an engagement the client does not receive a codebase and a verbal assurance. The tenant — policies, control set, risk decisions, and timestamped evidence accumulated across the build — belongs to their program and continues from there.
A note on scope: Iron Fort manages the compliance program, not the client's application data. Each tenant holds policies, controls, risk records, and evidence about the systems being built — the products themselves stay in their own environments, under their own owners.
Lab76's compliance claim is now something it can demonstrate per client, on the day a client asks, rather than a posture it reconstructs at the end of a build.
One tenant per build, so evidence, risk registers, and access never cross between clients — by structure, not by discipline.
The controls every regulated build needs, established once and instantiated per project instead of rebuilt each time.
Compliance artefacts accumulating from project start, which is what makes "from the first commit" a checkable statement.
Handover transfers a live, documented compliance program alongside the product, rather than leaving the client to start one.
Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.
Cookies on goironfort.com
Essential cookies keep this site working and are always on. With your consent we also load third-party content, such as our review badge, which shares your IP address with that provider. Rejecting keeps everything non-essential switched off. Read our Privacy Policy — you can change your choice any time from the footer.