FinTech // Client Project

Access Management:
One Secure View of Users and Assets.

We built a practical FinTech solution combining context-aware proxying, just-in-time (jit) elevation, and spiffe service identity. The project delivered 100% Identity Coverage and 99% Lateral Risk Reduction.

Key Results RESULTS
100%
Identity Coverage
vs 60% Older
99%
Lateral Risk Reduction
ROI: 14 Weeks
<50ms
Auth Response time
SLA OPTIMIZED

Trusted by teams building ambitious products

What We Set Out to Improve.

Industry
FinTech

Business fund management handling $40B+ AUM across globally distributed investment pods.

How We Worked
Dedicated product team

DevSecOps Architect + 2 IAM Engineers + SRE Lead embedded within Global System.

Goal
Controlled-access System & Controls

Replacing fragile VPN entry points with context-aware, cryptograpatient health informationcally verified resource access.

What We Built
Controlled-access Platform

A practical solution designed around the client’s existing tools, teams, and day-to-day workflow.

What Was Getting in the Way.

The client relied on older VPNs that granted broad Network-Level access. Once a user bypassed the perimeter, they had lateral visibility into valuable databases and trade-execution engines, creating a massive blast radius for compromised credentials.

The biggest issues were over-privileged users, lateral threat speed, and onboarding response time. The team needed a faster, clearer way to manage the work while keeping the right checks in place.

Over-Privileged Users
80% of staff had persistent Admin or Editor access to environments they only needed for seasonal reporting.
Lateral Threat Speed
A single patient health informationshed credential could potentially expose the entire business ledger due to lack of micro-segmentation.
Onboarding Response Time
Provisioning secure access for new investment pods took 5+ business days due to manual firewall ticket cycles.
The Solution

What We Built.

01
Context-Aware Proxying
Added a global Identity-Aware Proxy (IAP) that verifies user identity, device health, and geolocation before exposing any service endpoint.
Key details
Auth Model OIDC Federated
Verification MFA Enforced
Response time <40ms p95
02
Just-In-Time (JIT) Elevation
Replaced Always-On permissions with a JIT request flow, where privileged access is granted for 4-hour windows via automated Slack approvals.
Key details
Default Zero Access
TTL Ephemeral
Approval Agentic Trigger
03
SPIFFE Service Identity
Introduced SPIFFE/Spire to provide short-lived, mTLS-verified identities to every microservice, eliminating static secrets and hard-coded API keys.
Key details
Identity Workload Native
Encryption mTLS Everywhere
Standard Traceable Data
Before and After

How the Workflow Improved.

Area
Before
After
Trust Level

Implicit / Network

Once on the VPN, the user is Trusted and can scan the internal network.

Explicit / Resource

Access is denied by default. every request is re-verified at the resource level.

User Experience

Hard to Use

Slow VPN handshakes and repeated password prompts across tools.

Simple SSO

Single cryptograpatient health informationc identity session across all internal and cloud assets.

Audit trail

Log Separate systems

Firewall logs and app logs were disconnected, making incident mapping slow.

Unified Lineage

Every single action is tied to a verified identity and device ID in an secure and traceable log.

Key Features

What Made the Solution Useful.

Ready to Grow

Sidecar Proxy Injection

Automated identity handling via sidecars, ensuring developers never have to write auth code or manage secrets manually.

Business impact
Zero Auth Code-Bloat
Traceable Data

Continuous Attestation

The platform continuously checks device compliance (disk encryption, OS patches) during active sessions, auto-revoking access if status fails.

Business impact
100% Live Compliance
Faster Delivery

How We Reduced Build Time.

Tested foundations helped the team spend less time on setup and more time on the parts that made this product useful.

What accelerated the work

3 reusable building blocks
01

Identity Auth Module

A tested starting point for identity auth module reduced repeated setup work.

02

Identity Monitoring Platform

Reusable work for identity monitoring platform let the team focus more time on the client’s specific needs.

03

Controlled-access Guardrail Module

This made it easier to add controlled-access guardrail module without rebuilding common foundations.

Results

The Business Difference.

A straightforward before-and-after view of what changed for the team and their customers.

RESULT: RISK01

Blast Radius Suppression

Micro-segmentation ensures that a single compromised account cannot access adjacent service clusters.

Older VPNHigh Risk
Controlled-accessIsolated
Outcome99% Blast Radius
RESULT: OPS02

Pod Provisioning Speed

Automated identity-based permissions replaced manual firewall tickets for global investment teams.

Before5 Days
After4 Hours
Outcome30x Faster Onboarding
Results99% Blast Radius • 30x Faster Onboarding
Trust and Control

How We Kept It Safe and Reliable.

01
Regulatory Alignment
Framework meets NIST 800-207 and FFIEC controlled-access maturity requirements for global financial institutions.
Business SECURE
02
Data Privacy
Identity data and audit logs are sharded by region to comply with local data residency laws (GDPR/APPI).
VERIFIABLE DATA
03
Reliable Service
Reliable proxy clusters introduced across 3 regions with automated failover logic.
ZERO DOWNTIME
04
Code and IP Ownership
Coretus provides 100% ownership of the Controlled-access configuration, proxy logic, and identity scripts.
100% OWNED
Client Testimonial

In their own words.

Coretus didn't just give us a new VPN, they built a zero-default identity framework that reconciled our speed with security. We now provision teams in hours instead of days, with a level of a clear audit trail that satisfies our global board.

Eliminate Your Perimeter Risk.

Have a similar challenge? We can help you plan and build a practical FinTech solution around your goals, budget, and existing systems.

NIST 800-207 Aligned

JIT Access Enabled

100% Source Ownership