Zero-Trust Architecture for Multi-Tenant SaaS Platforms on AWS:A Practitioner Framework for Authentication, Authorisation, and KYC in Regulated Financial Services
By Alan Terriaga Multi-tenant Software-as-a-Service (SaaS) platforms operating in regulated financial services face a unique intersection of security, compliance, and operational challenges that traditional perimeter-based architectures cannot adequately address. This paper presents a practitioner framework for implementing Zero-Trust Architecture (ZTA) across all layers of an AWS-hosted SaaS application, with particular focus on the authentication, authorisation, and Know Your Customer (KYC) verification pipelines that underpin financial compliance obligations. Drawing on direct engineering delivery experience leading IAM systems in regulated multi-tenant environments, we...
