Multi-Tenant Mobile App Development

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Multi-Tenant Mobile App Development
Complex
from 2 weeks to 3 months
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    860
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    746
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1163
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1036
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    970
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    564

Multi-Tenant Mobile App Development

We develop multi-tenant mobile applications where a single codebase serves multiple clients (tenants) with unique branding, data, and functionality. With 10+ years of experience, we've implemented such architectures for fintech, retail, and enterprise platforms. The core challenge is ensuring complete isolation of data and configurations while maintaining flexibility for adding new tenants. This article breaks down the key approaches and their impact on performance, security, and time-to-market.

Two Fundamentally Different Approaches

Single binary, runtime switching. The app loads tenant configuration at startup: colors, logo, feature flags, API endpoint, texts. The user sees "Bank A" or "Bank B" depending on the link used to install the app or the domain entered. Technically: deep link or QR code with tenant ID → TenantRepository loads JSON config from CDN → ThemeProvider applies tokens → FeatureFlagService enables/disables screens. One APK/IPA in the store. Downside: branding in App Store (screenshots, icon) is universal, not tenant-specific. Google Play accepts this; App Store does not for B2C, but acceptable for corporate MDM.

Separate binaries via build automation. For each tenant, a separate APK/IPA is built with unique applicationId/bundleIdentifier, icon, name, and config. Fastlane Lanes + Build Flavors (Android) + Xcode Schemes/Targets (iOS). Adding a tenant means adding a new flavor in build.gradle.kts and a new Xcode target — no code changes. CI builds all variants in parallel.

Which to choose depends on App Store presence requirements. If each tenant needs its own store listing, the second approach is inevitable.

Comparison of approaches:

Criteria Single Binary Separate Builds
App Store acceptance Limited (B2B/MDM) Full
Development complexity Lower Higher
Time to add tenant Days (config setup) Days + automation
Branding flexibility Medium Full

Why Data Isolation Is Critical

Data isolation is critical. Leaking one tenant's data to another is catastrophic. At the mobile app level:

tenant_id is stored in Keychain (iOS) / EncryptedSharedPreferences (Android) at first login. All API requests include a tenant-specific header or subdomain (tenant-a.api.example.com). Local DB — either a separate SQLite database per tenant or table prefixing.

When switching tenants (if supported) — full local cache flush, Keychain record cleanup, re-authentication. It must never happen that UserRepository returns cached data from a previous tenant.

We guarantee isolation at both code and infrastructure levels — each tenant uses separate credentials and keychain entries.

Feature Flags and Configuration

Tenant config is more than theming. Typical structure:

{
  "tenant_id": "bank-a",
  "theme": { "primary": "#1A73E8", "logo_url": "..." },
  "features": {
    "transfers_enabled": true,
    "crypto_tab": false,
    "biometric_required": true
  },
  "api_base_url": "https://bank-a.api.example.com",
  "support_phone": "+7-800-...",
  "terms_url": "https://bank-a.example.com/terms"
}

Feature flags control visibility of entire navigation sections and business logic behavior. FeatureFlagService is the single source of truth; all components reference it only. Flags are cached locally with TTL and updated in the background at startup.

How feature flags speed up app adaptation for a client?

Feature flags let you enable or disable a function for a specific tenant without releasing a new build. This cuts release time from weeks to minutes. For example, if a client asks to hide the cryptocurrency section, just change the flag in the config — other tenants are unaffected.

Theming. In Flutter — ThemeData with custom ColorScheme and TextTheme, MaterialApp(theme: TenantTheme.fromConfig(config)). In React Native — Context with tokens via StyleSheet or styled-components. Dynamic fonts — via @font-face (RN) or FontLoader (Flutter). Icons — SVG with recolor via colorFilter or sprite pack per tenant.

Authentication and Authorization

Each tenant can have its own Identity Provider: one uses corporate SSO (OAuth 2.0 + PKCE), another uses corporate SAML via mobile proxy, a third uses simple email/password authentication. AuthStrategy — interface with implementations per type. AppAuth (iOS/Android) for OAuth PKCE is the standard recommended by RFC 8252 for mobile clients.

How to implement authentication for different Identity Providers?

We use an abstract AuthStrategyFactory that returns the correct implementation based on tenant ID. This allows plugging in a new IdP without changing core code. Each strategy is tested in isolation — token leakage between tenants is prevented.

Case study. White-label fintech platform: 12 tenants — banks and MFOs. One binary on Google Play, separate IPAs via Apple Business Manager for corporate clients. Tenant config is loaded from CDN (CloudFront) at first launch and cached in EncryptedSharedPreferences/Keychain with 24h TTL. Feature flags control 23 functions. Each tenant has an isolated backend database; the mobile client uses tenant-subdomain for all requests. Average time to add a new tenant after infrastructure setup — 4 hours (config creation + Fastlane lane + CI pipeline). This approach reduced the platform's time to market for new clients by 40% compared to a monolithic app.

What's Included in Our Work

When ordering development of a multi-tenant mobile app, you get:

  • Architecture document with strategy selection (single binary / separate builds).
  • Configured CI/CD infrastructure (Fastlane, GitHub Actions, CodeMagic).
  • CDN for configs and feature flag updates.
  • Integration with tenant-specific Identity Provider.
  • Code with data isolation tests.
  • Playbook for adding a new tenant.
  • Post-release support for 1 month.

Timelines for Multi-Tenant App Development

Scope Estimated Timeline
Multi-tenant with branding, single binary 10–16 weeks
Separate builds per tenant (flavor pipeline) +3–5 weeks on top of base
Complex feature flags + auth strategy 5–9 months (full product)

Cost is calculated individually. The key factors are number of tenants, differences in business logic, and App Store presence requirements.

Contact us for a consultation on your multi-tenant app architecture. Order development and get a reliable solution with guaranteed isolation and scalability.

Mobile App Architecture

The app is built in a single ViewController with 2000 lines. Network calls, business logic, UI updates—all in one place. Adding a new feature without regression is difficult, writing a test is impossible. This isn’t “bad code”—it’s a lack of architecture. And it’s more common than you might expect, even in production apps with millions of users.

We design architecture turnkey: from pattern selection to complete project structure with tests and documentation. In 7–10 days you get clean, modular code ready for scaling.

Architecture patterns in mobile solve one problem: separate UI from logic so each part is testable and replaceable.

MVVM: Basic Pattern

Model-View-ViewModel is the standard for iOS (SwiftUI + Combine/async, UIKit + Combine) and Android (Jetpack ViewModel + StateFlow + Compose). The ViewModel holds UI state and business logic. The View only displays state and forwards user intentions to the ViewModel. The Model represents data and its source.

Key rule: ViewModel knows nothing about UIKit or Android View classes. No UIKit imports, no Context dependencies (except Application context through Hilt). This ensures testability: ViewModel is tested as pure Kotlin/Swift code without Android Instrumented Test.

MVVM covers 70% of needs. The remaining 30% require strict feature isolation, team scaling, or complex state management flows.

Clean Architecture: When MVVM Isn’t Enough

Adds layers on top of MVVM:

  • Domain layer — business logic, platform-independent. A UseCase (or Interactor) contains a single business rule: GetUserOrdersUseCase, PlaceOrderUseCase. Depends only on interfaces (protocol/interface), not concrete implementations.
  • Data layer — repository implementations. OrderRepositoryImpl implements OrderRepository from domain. Knows about Retrofit, Room, UserDefaults. The ViewModel doesn’t know where data comes from—network or cache.
  • Presentation layer — ViewModel + View. Knows about Domain, not Data.

Dependency rule: dependencies point inward only. Domain depends on nothing. Data and Presentation depend on Domain.

Presentation → Domain ← Data

This allows swapping implementations: tests use an in-memory repository instead of network, the interface remains the same.

Practical caveat: Clean Architecture adds files and layers. For small apps, this is overhead. It’s justified starting from ~15 features and teams of 3+ developers.

BLoC for Flutter: Predictable State Flow

BLoC (Business Logic Component) is the standard pattern in the Flutter community. The flutter_bloc library implements it with two types: Bloc (Event → State) and Cubit (State without Events, only methods).

Bloc processes Event and emits a new State via on<EventType> handlers. State is immutable—a new object for each change. BlocBuilder re-renders only the part of the tree where state changed.

// Event
abstract class CartEvent {}
class AddItemToCart extends CartEvent {
  final String productId;
  AddItemToCart(this.productId);
}

// State
abstract class CartState {}
class CartLoaded extends CartState {
  final List<CartItem> items;
  CartLoaded(this.items);
}

// Bloc
class CartBloc extends Bloc<CartEvent, CartState> {
  CartBloc(this._cartRepository) : super(CartLoaded([])) {
    on<AddItemToCart>(_onAddItem);
  }

  Future<void> _onAddItem(AddItemToCart event, Emitter<CartState> emit) async {
    final current = state as CartLoaded;
    final updated = await _cartRepository.addItem(event.productId);
    emit(CartLoaded(updated));
  }
}

The advantage of BLoC is testability. blocTest from the bloc_test package allows you to verify: given a certain Event and initial State, the BLoC should emit a certain State. No UI, no mocks for the Flutter framework.

VIPER: For Large iOS Projects

VIPER (View, Interactor, Presenter, Entity, Router) is the strictest separation of responsibilities for iOS. Each component has a protocol and concrete implementation.

  • View — UI only, delegates everything to Presenter
  • Interactor — business logic, network and data operations
  • Presenter — mediator between View and Interactor, formats data for View
  • Entity — data models (pure structures)
  • Router — navigation between modules

Each module (screen or feature) is a separate VIPER module. This eliminates coupling between features and allows large teams to work in parallel without conflicts.

The cost: many files, many protocols. Boilerplate is generated via Sourcery or custom Xcode templates. VIPER is justified for apps with 10+ developers and 50+ screens.

TCA (The Composable Architecture)

TCA by Point-Free is a more modern alternative to VIPER for iOS/macOS. Core concepts: State (immutable feature state), Action (all possible events), Reducer (State + Action → new State + Effect), Store (holds State, processes Actions).

Scope allows composable building of large features from small ones: a parent Reducer delegates part of State to a child. Each feature is tested in isolation via TestStore with precise control over Effects.

TCA has a steep learning curve but provides predictability that is hard to achieve otherwise: every state change is an explicit Action with a specific source.

Which Pattern to Choose for Your Project?

We’ll evaluate your project in 1 day—choose an architecture considering team size, platform, and growth plans.

Pattern Platform Team Size When to Choose
MVVM iOS, Android, Flutter 1–5 Starting standard, MVP, small projects
MVVM + Clean iOS, Android 3–10 Medium projects, testability critical
BLoC Flutter 2–8 Flutter with predictable state management
VIPER iOS 5–20 Large iOS projects, modular architecture
TCA iOS/macOS 3–15 Strict testability, Swift Concurrency

There is no universal answer. Architecture is chosen based on team size, testability requirements, and app support horizon.

What Components Are Included in Our Architecture Work?

  • Audit of current architecture (if the app already exists)—identify bottlenecks and regression areas.
  • Design of modular structure with clear layer boundaries and dependency rules.
  • Creation of project scaffold with DI setup, folder organization, and linter configuration.
  • Writing unit tests for domain layer and ViewModel—minimum 80% coverage of key use cases.
  • Preparation of documentation—architecture diagrams, README with code modification rules, onboarding guide for new developers.
  • Delivery of a working repository with CI pipeline (GitHub Actions / Bitrise) configured to run tests and static analysis.

All this is included in the design cost. Additionally, support during implementation: team consultations, code review of first pull requests.

How Does Lack of Architecture Affect Development Speed?

Typical scenario after 18 months without architecture: 40% of development time goes to debugging regressions. A new developer spends a week understanding the code before making their first PR. Tests aren’t written “because it’s hard to mock.” Adding a new feature requires understanding half the codebase.

Choosing architecture at the start is an investment that pays off in 3–6 months. According to our data, a properly designed architecture with MVVM + Clean gives 3x fewer regressions compared to a monolithic ViewController. And the cost of implementation is recouped in 2–3 sprints.

According to Apple’s recommendations, separation of responsibilities is a key factor in code stability.

Why Trust Our Team with Architecture?

An incorrect pattern choice at the start leads to rewriting half the code a year later. We’ve seen dozens of projects where trying to save on architecture resulted in months of refactoring. With over 10 years of commercial development experience and work on apps from 1 to 50 developers, we help avoid common mistakes:

  • Overengineering for a simple MVP (we assign MVVM, not VIPER).
  • Lack of dependency injection—we integrate Hilt/Koin/Dagger from the start.
  • Ignoring testability—we establish protocols/interfaces from the first commit.

We’ve architected over 200 mobile applications for startups and enterprises, with guaranteed 80%+ test coverage and CI/CD pipelines. Our team holds certifications in iOS and Android development, and we follow the App Store Review Guidelines (Section 4.2/5.1) to ensure smooth store approvals.

Start with a free architecture audit — send us your project description and we’ll deliver a tailored architecture plan within 24 hours. Reach out via Telegram or email to get started.