The EZ4Youtech platform

Multi-tenant BYOK SaaS — one secure workspace per client. How it works · Security · Pricing

How the platform works

Three roles — one isolated tenant per business. Each tenant gets 20 workspace apps (by plan) plus 10 industry workflows for one vertical — Browse the full catalog.

Platform operator

  • Creates client workspaces from the operations console
  • Sets industry vertical and plan (Basic / Standard / Elite / Enterprise)
  • Controls which catalog apps are Live vs coming soon
  • Provisions tenant admins and team sign-ins

Client admin (setup)

  • One-time BYOK setup — OpenAI, Together, or Anyscale keys
  • Encrypted credentials stored per tenant; never logged
  • No day-to-day workspace or industry apps on this login

Team members (daily use)

  • Run structured AI apps — forms and tuned prompts, not open chat
  • Plan tier unlocks seats and catalog depth (2+3+5 per 10-app pack)
  • Upload, draft, summarize, and extract inside tenant boundaries

Typical rollout

  1. Provision — Operator creates the tenant, industry, and plan.
  2. BYOK — Client admin adds provider keys (required for pilots and production).
  3. Team access — Agents sign in; they see only apps their plan unlocks.
  4. Run workflows — Complete the job in the app built for that task.

Pilot launch waives the platform fee for 2 months; BYOK applies from day one.

Security at a glance

Built for client-facing and regulated work. We describe an enterprise-ready architecture. We do not claim SOC 2, ISO 27001, or HIPAA unless agreed in a signed contract.

Core security controls

How we protect tenant data and credentials in the live application.

Authentication & access

  • JWT with tenant_id, plan, and role on every API call
  • bcrypt password hashing; login rate limiting per IP
  • RBAC — superadmin, partner, tenant admin, agent
  • Plan gating — app catalog and agent seats enforced server-side

BYOK & data handling

  • Fernet-encrypted provider keys in MongoDB Atlas
  • Keys decrypted only for outbound provider requests
  • Uploads and run history under tenant_id/ storage paths
  • Production security headers (HSTS, X-Frame-Options, Referrer-Policy)

Agent request flow

  1. Agent signs in → JWT with tenant_id and plan.
  2. App catalog loaded per plan; admin BYOK keys already configured.
  3. Run submitted → API decrypts tenant key, calls provider, stores result under tenant scope.
  4. Usage recorded for dashboards — not resold to third parties.

Deeper diagrams: Architecture & security guide · Security FAQ

Technology stack & operations

For IT and security reviewers — USA production posture (May 2026).

Production stack

LayerTechnologyRole
EdgeHTTPS, CDNTLS for marketing site and platform hostname
ApplicationFastAPI + StreamlitREST API and agent/admin UI
ComputeAzure Container AppsManaged runtime, tagged releases
SecretsAzure Key VaultJWT key, encryption key, Mongo URI — not in git
DatabaseMongoDB Atlas (M10)Tenants, users, encrypted BYOK, usage
StorageAzure BlobTenant-scoped documents and artifacts
AI (BYOK)OpenAI, Together, AnyscaleCustomer keys; billed on your provider account

Security & data protection

AreaPractice
Data in transitTLS 1.2+ end-to-end
Secrets at restFernet encryption for BYOK keys
Tenant isolationAPI checks + tenant_id/ blob paths
LoggingNo keys, passwords, or raw prompts in app logs
OpsAzure Monitor; Atlas backups; blob soft-delete

Your responsibilities

Platform tour

Workspace, routing, credentials, and team controls.

Open live platform

EZ4Youtech platform dashboard showing workspaces, AI routing, and team analytics

Workspace

Catalog apps by plan and industry

AI router

Route to your BYOK providers

Credentials

Encrypted keys — never logged

Team & plans

Roles, seats, access

Ready to see it on your stack?

Start with a pilot — connect BYOK, run one workflow, then scale seats and plan tier.

Positioning and cost comparison — Home · FAQ