Cloud Security Foundation & Zero-Trust Network for FinTech Scale-up
Cloud InfrastructureCompleted 22 August 2025

Cloud Security Foundation & Zero-Trust Network for FinTech Scale-up

Designed and stood up a production-grade, SOC 2-ready multi-account AWS foundation with zero-trust network segmentation, automated compliance evidence, and a secure CI/CD pipeline supporting 40+ weekly deployments.

AWSTerraformKubernetes (EKS)IstioHashiCorp VaultAWS GuardDutyDatadogGitHub Actions
Duration10 weeks
Budget$142,000
Team Size5 people
RegionNorth America
  • Multi-account AWS landing zone with 12 logically separated environments
  • Zero-trust service mesh with mTLS between internal services
  • Secrets brokering via Vault with short-lived, just-in-time credentials
  • Continuous compliance monitoring with automated control evidence
  • Secure CI/CD with SBOM generation, SAST, DAST, and dependency scanning
  • WAF + DDoS + anomaly detection with 24/7 alert routing
  • Runbooks, tabletop exercises, and incident response playbooks delivered

WizPay had scaled product engineering faster than platform maturity and was preparing for SOC 2 Type II. Their AWS footprint was a single account with broad network access, a single admin IAM role shared across 18 engineers, and secrets stored in CI configuration.

Landing Zone & Segmentation

We stood up a multi-account foundation with 12 logically separated environments, private VPC networking with no default internet egress, and a least-privilege IAM model using roles with scoped session policies.

Zero-Trust & Secure Delivery

An Istio service mesh terminates all internal traffic with mTLS. Vault brokering replaced static secrets with short-lived credentials. The CI/CD pipeline was rebuilt to produce SBOMs, run static and dependency analysis, and block deployments on new findings without an approved waiver.

The team was moving 30+ deployments a week into a shared AWS account using a common admin role. Broad network access meant any compromised service could reach any other. Secrets were stored in CI configuration, and there was no way to prove who did what, when, and from where for audit purposes.

Landing zone delivered in four weeks without blocking a single release. We migrated service-by-service into the segmented environment, introduced short-lived credentials, and rebuilt the delivery pipeline. Controls were mapped against SOC 2 and GDPR requirements with automated evidence capture.

WizPay passed SOC 2 Type II on first attempt with zero exceptions in the cloud-security domain. Mean time to rotate secrets went from 6 days to under 30 seconds. Blast radius per service was reduced by ~95%. The platform has been handling over 40 weekly deployments without a security-related rollback for 7 consecutive months.

PeerHub didn't just set up infrastructure — they embedded compliance into every layer of our delivery pipeline. When the SOC 2 auditor reviewed the setup, the only comment was that it was the cleanest cloud environment they had seen that year.

Sarah M.CTO, WizPay Financial Technologies