Mass market SAAS will generally just use other products to handle this stuff. And if there does happen to be a leak, they just say sorry and move on, there are very few consequences for security failures.
but guess who advises that architecture and implements it... the principal developer/architect.
You can use good security tools, badly.