One system runs many isolated tenant sites — each with its own themeOn the left a runtime core of one backend and one frontend. It powers three mutually isolated accounts; each account holds an organisation and a site with its own domain, its own theme and its own content.One runtimeone backend · one frontendBackendFrontendone systemmany isolated tenantsAccountisolatedOrganisationSitedomain · theme · contentAccountisolatedOrganisationSitedomain · theme · contentAccountisolatedOrganisationSitedomain · theme · content

Overview

Capabilities at a glance.

Each pillar, honestly sorted by maturity — details below.

✅ Live · 🔨 In progress · 📋 Planned — honestly marked.

01

Multi-tenancy & architecture

  • LiveTrue multi-tenant SaaS — one app, many sites
  • LiveProduct = configuration, not code
  • LiveHierarchy: account → organisation → site
  • LiveHard tenant isolation
  • LiveProvisioning from a template
02

Sovereignty & privacy

  • LiveEU/DE hosting
  • LivePrivacy scan in the pipeline (no Google Fonts, analytics, US trackers, external CDNs)
  • LiveSystem fonts
  • LiveCustom domains + TLS
  • PlannedRegion/residency policy
  • PlannedDPA / TOMs / consent
03

Security & access

  • LiveRoles & permissions (RBAC + capabilities)
  • LiveManaged login (OIDC) + sessions
  • LiveMFA detection
  • In progressMFA enforced across the board
  • LiveSecret scanning
  • LiveVulnerability gate
04

Content & editing

  • LiveBlock content model
  • LiveDraft / publish + versioning
  • LiveFrontend serves real tenant content
  • In progressInline editing in the premium admin
05

Design & theming

  • LiveTheme layer with design tokens (a distinct look per tenant)
  • LiveBrand theming in practice (e.g. Leovino)
  • In progressPre-built content and design modules
06

Operations & quality

  • LiveSafe, automatic migrations
  • LiveHealth probes
  • LiveA central 5-stage CI/CD pipeline with a quality gate
  • LiveGitOps deployment
  • In progressOperator console
  • PlannedBackups / monitoring

Sovereignty & privacy

Privacy is architecture, not a checkbox.

Here sovereignty means concretely: EU hosting, no external trackers, system fonts instead of Google Fonts — and a privacy scan that enforces it in the pipeline. Honestly: technology is one thing, residency and law are their own layers.

Live

Technical

EU hosting, no US trackers, no external CDNs, system fonts — checked automatically before anything ships.

Planned

Residency

An explicit region/residency policy that binds where data lives and flows is in the works.

Planned

Legal

DPA, technical and organisational measures and consent building blocks (especially for children's data) are being worked out formally.

How a new site comes to be

A template plus data becomes a site.

  1. 01

    Create an account

    A provider or association is created as an account — the hard isolation boundary.

  2. 02

    Organisation & site

    Within the account, organisation and site are created from a versioned template.

  3. 03

    Configuration

    Theme, domain, roles and scope are set as data — no new code.

  4. 04

    Publish

    Content is edited as a draft and, on approval, published live and versioned.

Working together

Interested in the platform or in working together?

Whether a look at the platform, a professional exchange, or concrete collaboration — a brief note about your context is enough to start.

Get in touch