White-Label Web Application: Custom Domains and Branding

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
White-Label Web Application: Custom Domains and Branding
Complex
~2-4 weeks
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947

White-Label Web Application

Imagine your SaaS product is about to be sold by a large enterprise client, but they need their own brand—their domain, logo, colors, and even email templates. Without white-label, you would have to write a separate copy for each client, which doesn't scale. We have implemented white-label for 20+ projects; our engineers have deep experience in multi-tenant architecture. We build a white-label version of your web application with full tenant isolation, custom domains, and automatic SSL issuance via Cloudflare. Contact us for an audit—we will prepare a deployment plan within 2 days.

Problems We Solve

Data Isolation Between Clients. If data from two clients ends up in the same table without a tenant_id filter, it's a disaster. We use middleware that identifies the tenant based on the domain and passes its ID into all queries. For key entities in Prisma, we add @@index([tenantId]) and always filter by it. This way we handle up to 10,000 requests per day without isolation errors.

Custom Domains and SSL. A client wants app.acmecorp.com, but you need to issue an SSL certificate for each domain. Manual issuance via Let's Encrypt would mean thousands of requests per day. The solution is Cloudflare Custom Hostnames: they issue and renew certificates automatically, while we only verify the CNAME record. The process is fully automated and takes a few minutes.

Branding Without Rewriting UI. Each client wants their own colors, logo, fonts, and even custom CSS. Storing this in CSS variables is not enough: you need to dynamically generate styles and load fonts. We use a TenantStylesheet component that injects CSS variables and optional custom CSS based on tenant settings.

How We Do It: A Real Implementation Case

From our practice: one project was a white-label platform for project management. Our client was a large company with 50+ brands. Tech stack: Next.js 14 (App Router), Prisma, PostgreSQL, Cloudflare, and Resend for email.

Middleware for Tenant Determination. In Next.js, we created middleware that intercepts requests and determines the tenant from the host header. If the domain is not found, it redirects to 404. We pass tenantId and tenantSlug in response headers so that server components can read them. This solves isolation at the routing level.

Custom Domain Verification. When a client adds a custom domain, we verify that the CNAME points to our platform. We use Node.js dns/promises to look up the CNAME. If the record is correct, we save the domain in the database and add the custom hostname via the Cloudflare API. The certificate is issued automatically in minutes.

Branded Emails. All transactional emails (invitations, notifications) are sent via Resend with tenant branding: logo, color, sender name. If the client hides the watermark, we do not display the "Powered by" badge.

Process of Work

Stage Duration Result
Analysis and design 1-2 days Tenant isolation schema, list of custom domains, branding design
Middleware and routing implementation 2-3 days Tenant determination by domain, 404 handling
Custom Domain + SSL 1-2 days Cloudflare Custom Hostnames, DNS verification
Branding (UI, email, CSS) 2-3 days TenantStylesheet components, branded email templates
Testing and deployment 1-2 days Isolation tests, load testing, CI/CD

Comparison of Isolation Approaches

Approach Description When to Use
Shared database + tenantId All rows tagged with tenantId, Prisma middleware auto-filters For startups and medium projects with 10–50 clients
Separate schemas Each tenant in its own PostgreSQL schema, same database When logical isolation and per-client backups are needed
Separate databases Full physical isolation, each database separate For high-security projects with GDPR/ISO requirements

Approximate Timelines

Minimal white-label configuration (subdomains + branding) — from 5 business days. Full solution with custom domains, SSL, and email — up to 10 business days. If data isolation at the individual database level is required — up to 15 days. The cost is calculated individually after auditing your stack. Order a consultation—we will prepare a precise estimate.

What Is Included in the Work

  • Source code of middleware, branding components, and custom domain module
  • Documentation for adding a new client (API endpoints, admin panel)
  • Example CI/CD for deployment on Vercel or your own server
  • 30 days of technical support after launch

When Should You Choose White-Label?

Compare: a custom solution means copying code, separate repositories, duplicate work. White-label—one codebase, one infrastructure, thousands of clients. According to our data, white-label maintenance costs 3–5 times less than maintaining separate instances. And the speed of onboarding a new client goes from weeks to hours, reducing operational costs. If your product has more than 10 clients, white-label is almost always more cost-effective.

How to Implement Data Isolation Between Tenants?

We use the shared database, per-tenant rows approach: all records in tables are tagged with tenantId, and in Prisma we have a global middleware that automatically adds a filter for the current tenant. This is simpler than separate schemas and does not require complex orchestration. If pure isolation is needed, we can switch to separate databases with automatic creation upon client registration. We verify the correctness of filtering with load tests: simulate 1000 simultaneous requests from different tenants.

Typical Mistakes and How to Avoid Them

  • Not rechecking CNAME after verification. The client might delete the DNS record—then the domain stops working. We add a cron job that checks CNAME for all active domains every hour.
  • Ignoring watermark. Some clients do not want to see "Powered by". Give them the option to disable it in branding settings.
  • Forgetting SEO. On custom domains, there must be unique title and description. Use generateMetadata in Next.js to pull appName and favicon from tenant settings.

We use Cloudflare Custom Hostnames to automate SSL and Next.js Middleware for tenant determination. Get a white-label architecture consultation today. Contact us—we will evaluate your project for free and propose an implementation plan.

What Does SaaS Platform Development Involve? Multi-Tenancy, Billing, and Beyond

We know this pain by heart. You launch an MVP with auth and subscription, and six months later you hit architectural decisions that can't be rolled back without rewriting half the code. Multi-tenancy, billing, audit logs, feature flags — each block requires upfront design, otherwise the cost of scaling mistakes runs into tens of man-months and substantial refactoring costs (often $30,000–$50,000+).

Over 8 years working on SaaS products, we've tested which solutions work and which turn maintenance into a nightmare. Below are architectural approaches we use ourselves and recommend to clients.

How we build multi-tenancy: isolation without overhead

The first decision is the data separation scheme. Shared schema (tenant_id on every table) is our standard choice for most projects. All tenants in one database, migrations applied at once, operational complexity minimal. In Laravel we implement it via Global Scope:

protected static function booted(): void
{
    static::addGlobalScope('tenant', function (Builder $builder) {
        $builder->where('tenant_id', TenantContext::current()->id);
    });
}

The global scope is only the first line of defense. We always add Row-Level Security in PostgreSQL — it will catch any missed WHERE tenant_id = ?:

ALTER TABLE orders ENABLE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation ON orders
    USING (tenant_id = current_setting('app.tenant_id')::uuid);

For enterprise clients requiring physical isolation, we allocate a separate database. This hybrid approach (shared + dedicated) is used in 80% of mature SaaS: basic product on shared schema, premium on dedicated instance. We implement it from the first sprint to avoid rewriting logic later. Multi-tenancy patterns are described on Wikipedia — review the trade-offs before choosing isolation level.

Why Is Billing the Most Underestimated Block?

Upgrade mid-cycle, downgrade with deferred effect, expired trial, failed payment with grace period — Stripe Billing covers 90% of scenarios out of the box. We always process webhooks (customer.subscription.updated, invoice.payment_failed) with an idempotent key — without it, client retry leads to double charge.

For CIS markets — YooKassa or Tinkoff recurring. Their APIs are less convenient but cover 54-FZ requirements.

Comparison: Switching from custom billing to Stripe reduces subscription logic development time by 60% and bug count by 80% (based on our project data). That translates to $15,000–$25,000 savings on a typical SaaS MVP.

Onboarding: how not to lose the user before aha-moment

Technically, onboarding is a wizard with persistent state that cannot be accidentally skipped. Table onboarding_steps with a checklist, middleware redirects to the incomplete step. After completion — a flag in user settings, middleware disabled.

Critical nuance: show real product progress, not abstract steps. "Create your first report" instead of "Complete step 3 of 5." We use drip campaigns via Customer.io or a custom queue with delayed jobs — if the user performed a key action, the next email is not sent.

How to Implement Feature Flags and Access Control?

SaaS with plans requires granular control. Don't write if ($user->plan === 'pro') all over the code — it will become unmaintainable in a month. Instead:

  • Backend: Gate + Policy with checks via features table linked to plans.
  • Frontend: context with flags loaded at app initialization.
  • Open-source tools: Unleash or Growthbook — UI for A/B testing and rollout.

Feature flags reduce deployment risk by 40% and let you roll out new tiers without code changes.

How to Protect API from Aggressive Clients?

Rate limiting is a must for public API. One client can bring down all others. In Laravel we use Redis with sliding window counter:

Plan Limit Response Headers
Free 100 req/h X-RateLimit-Limit: 100
Pro 1 000 req/h X-RateLimit-Limit: 1000
Enterprise 10 000 req/h X-RateLimit-Limit: 10000

Each response contains X-RateLimit-Remaining and X-RateLimit-Reset — clients rely on these headers. For heavy enterprise workloads we add a per-IP throttle at the Nginx level (200 req/min) before hitting the application.

Audit Logs and Monitoring: What, Who, and When?

Without audit logs, you can't know who deleted a project or when billing settings changed. Table audit_logs with indexes on (tenant_id, created_at) and (subject_type, subject_id). In Laravel — Observers on key models.

Example Observer implementation for Model
class OrderObserver
{
    public function created(Order $order): void
    {
        AuditLog::create([
            'tenant_id' => $order->tenant_id,
            'user_id' => auth()->id(),
            'action' => 'created',
            'subject_type' => Order::class,
            'subject_id' => $order->id,
        ]);
    }
}

Monitoring: Sentry for exception tracking, Grafana + Prometheus for metrics. Alerts on error rate > 5% and response time p95 > 2s. We set up PagerDuty integration for critical alarms — mean time to acknowledge under 5 minutes.

Our Team's Experience and Guarantees

Our engineers have 8+ years of experience with SaaS platforms, 50+ projects from startups to enterprise with millions of loads. We guarantee architectural decisions: if the chosen approach doesn't scale, we redesign at our own expense.

Deliverables and Guarantees

  • Architecture documentation: diagrams, ERD, sequence diagrams.
  • CI/CD setup (GitHub Actions / GitLab CI).
  • Access to repository, staging, and production.
  • Team training: 2–3 sessions on code review and runbook.
  • Post-launch support for 1 month.
  • Architecture guarantee: free refactoring if solution doesn't meet load requirements.

Work Process

  1. Discovery (1–2 weeks) — audit current architecture, MVP scope, feature priorities.
  2. Design (1 week) — stack selection, multi-tenancy scheme, billing plan.
  3. Development (4–12 weeks) — 2-week sprints, demo after each.
  4. Testing (1 week) — load tests under target load, security audit.
  5. Deployment and training (1 week) — rollout, monitoring setup, documentation handover.

Timeline Estimates

Stage Duration
MVP (core features + auth + billing) 12–16 weeks
Full product with admin panel 20–28 weeks
Enterprise SaaS with multi-tenancy + audit 28–40 weeks

Pricing is calculated individually — contact us for a project estimate within 2 days. Order turnkey development: from design to deployment with architecture guarantee. Get a consultation on your product architecture — first hour free.