Skip to content

Finance and compliance

Run core systems on physically isolated bare metal, front public APIs with WAF and DDoS protection, encrypt everything, and keep primary-standby databases with separate backups.

The challenge

  • 01Regulators expect isolation and access records.
  • 02Public APIs are prime targets.
  • 03Data can be neither lost nor unavailable for long.

Reference architecture

How it rolls out

  1. 01

    Zones and isolation

    Public services, internal systems and databases sit in separate networks with only the connections they need.

  2. 02

    Physical servers for core systems

    Core ledgers and trading run on dedicated physical servers: steady performance, nothing shared.

  3. 03

    Encrypt and audit everything

    SSL in transit, encryption at rest, and an audit trail for every administrative action.

  4. 04

    Back up and rehearse

    Back up the database daily to object storage in another region, and rehearse a restore every quarter.

How a customer uses it

A fintech reconciling cross-border payments

Before
Compliance reviews required isolation and full audit trails, but everything ran in one network and every review meant scrambling for documents.
After
Rebuilt in zones with core systems on physical servers and audit logs kept in one place, they passed their latest review first time, with preparation down from weeks to days.
  • First time

    Compliance review

  • −75%

    Review preparation time

  • Quarterly

    Restore rehearsals

Design notes

Physical isolation

Bare metal servers are dedicated hosts, never shared with other tenants.

OV certificates

Use organisation-validated certificates for public services, with SM2 available.

Separate backups

Keep a second copy of database backups in archive-class object storage for low-cost retention.