Finance and compliance
Run core systems on physically isolated bare metal, front public APIs with WAF and DDoS protection, encrypt everything, and keep primary-standby databases with separate backups.
The challenge
- 01Regulators expect isolation and access records.
- 02Public APIs are prime targets.
- 03Data can be neither lost nor unavailable for long.
Reference architecture
How it rolls out
- 01
Zones and isolation
Public services, internal systems and databases sit in separate networks with only the connections they need.
- 02
Physical servers for core systems
Core ledgers and trading run on dedicated physical servers: steady performance, nothing shared.
- 03
Encrypt and audit everything
SSL in transit, encryption at rest, and an audit trail for every administrative action.
- 04
Back up and rehearse
Back up the database daily to object storage in another region, and rehearse a restore every quarter.
How a customer uses it
A fintech reconciling cross-border payments
- Before
- Compliance reviews required isolation and full audit trails, but everything ran in one network and every review meant scrambling for documents.
- After
- Rebuilt in zones with core systems on physical servers and audit logs kept in one place, they passed their latest review first time, with preparation down from weeks to days.
First time
Compliance review
−75%
Review preparation time
Quarterly
Restore rehearsals
Design notes
Physical isolation
Bare metal servers are dedicated hosts, never shared with other tenants.
OV certificates
Use organisation-validated certificates for public services, with SM2 available.
Separate backups
Keep a second copy of database backups in archive-class object storage for low-cost retention.