FinTech / Security
Crego.ai
100% secrets migrated to Secrets Manager
Overview
Crego.ai is a technology-driven lending ecosystem connecting banks, NBFCs, and financial institutions. As the platform scaled and onboarded additional partners, it required a security architecture meeting stringent financial-services expectations.
Key Objectives
- Establishing centralized management of secrets and encryption keys.
- Strengthening identity and access controls across cloud resources.
- Protecting customer-facing APIs against evolving web-based threats.
- Improving security visibility and operational monitoring.
- Implementing security best practices aligned with AWS Well-Architected.
Solution Components
- Amazon API Gateway for secure API exposure and traffic management.
- AWS WAF for application-layer threat protection.
- Amazon EKS within private networking for containerized workloads.
- AWS KMS for centralized encryption key management.
- AWS Secrets Manager for secure storage and lifecycle management of application secrets.
- Amazon CloudWatch and SNS for monitoring and operational visibility.
Security Enhancements
- Least-privilege IAM policies with resource-specific permissions.
- All application credentials and tokens migrated to AWS Secrets Manager.
- Encryption enforced using AWS KMS Customer Managed Keys (CMKs).
- Custom AWS WAF rules to identify and block malicious API traffic.
- Wiz integrated with EKS for continuous cloud security posture management.
Business Outcomes
- Migrated 100% of production application secrets to AWS Secrets Manager.
- Established centralized encryption key management using AWS KMS.
- Implemented secure API protection using AWS WAF and API Gateway.
- Achieved isolation of core financial workloads within private network segments.
- Strengthened alignment with financial-services security and compliance requirements.
Ready to achieve similar results?
Talk to our engineers about your cloud challenge. We'll get back to you within one business day.