One firm per machine
Multi-tenant is cheaper and I did not build it that way. A shared database holding six accounting firms is one authorization bug away from a breach notification in every state those firms' clients live in. That bug is not hypothetical. Broken object level authorization is the most common serious finding in web application security, year after year, in everybody's code.
So the isolation is physical. One firm, one host, one database. It costs more per tenant, every month, forever. That cost is not overhead. It is the thing the buyer is actually purchasing, and it is demonstrable to an auditor in a way that a row level security policy never is.