Skip to main content

Secure Cloud Foundation for a Private Capital Platform

Controlled access for a high-trust investment environment.

100%
Static SSH keys and long-lived database passwords eliminated
Zero
Public K8s API exposure
Real-time
Threat detection via SIEM

The story of Twin Premium Capital

Twin Premium Capital is an insurance premium platform managing high-stakes financial calculations and capital distribution. Given the sensitive nature of insurance data, the platform's infrastructure is built on a Security-First philosophy, ensuring that every layer from code to cloud storage is monitored, audited, and protected.

To deliver on that promise at scale, Twin Premium Capital partnered with Carbonteq to engineer a hardened DevSecOps environment combining zero-trust access, automated compliance gates, and real-time threat correlation.

Challenges Faced by Twin Premium Capital

  • Securing Private Cloud Environments

    To minimize exposure, the Kubernetes (k8s) and database instances are entirely private. This required a secure way for CI/CD pipelines and Engineers to interact with the cluster without exposing it to the public internet.

  • Managing Sensitive Data at Scale

    With a high volume of unstructured data stored in buckets, the platform needed a way to ensure no PII (Personally Identifiable Information) was accidentally exposed or improperly stored.

  • Modernizing Access Management

    Traditional SSH keys and VPNs were insufficient for a modern cloud-native team. The challenge was to provide seamless yet Zero-Trust access to GCP resources.

  • Infrastructure Visibility

    Achieving a single pane of glass for security signals across GCP audit logs, container runtimes, and secret access.

Solution Provided: Hardened DevSecOps & Identity Governance

Carbonteq delivered a hardened DevSecOps and identity governance stack — combining a private CI/CD perimeter, zero-trust engineering access, automated data sanitization, and a SIEM integration that correlates security events in real time.

  • Secure CI/CD & Private Perimeter: GitHub Action runners operate against a Private GKE Cluster with dynamic IP whitelisting — the runner's IP is dynamically whitelisted at the firewall level and immediately purged after the Helm Chart deployment completes. Every Pull Request triggers a mandatory security suite including SCA to scan all open-source dependencies for known vulnerabilities, and container scanning to identify CVEs in base images and application layers before they reach the registry.

  • Zero-Trust Engineering Access with Teleport: We implemented a zero trust access tool which acts as a unified gateway for all infrastructure access. Engineers no longer use static SSH keys; instead, they use short-lived, identity-backed certificates to access K8s clusters, GCP instances, and Databases. Every session is logged and recorded, providing a complete audit trail of what was changed and by whom, satisfying internal compliance requirements.

  • Data Sanitization & Infrastructure Scanning: Implemented a security layer to scan Cloud Storage buckets for sensitive data (PII), ensuring that while buckets follow WORM (Write Once, Read Many) protocols for integrity, they are also clean of unauthorized sensitive info. GCP Security Command Center provides continuous infrastructure scanning, detecting misconfigurations like open ports or unencrypted disks across the entire GCP organization.

  • Secret Management & SIEM Integration: Centralized all application secrets in a Secret Vault for secure, encrypted injection into CI/CD and K8s pods — ensuring that no plain-text secrets ever exist in code repositories. All GCP Audit Logs, Teleport logs, and runtime alerts are streamed into Datadog SIEM, allowing the team to correlate a vault access event with a K8s shell event, providing real-time threat detection and automated security alerts.

Partnership & Performance Snapshot

Category
Secret management
Implementation detail
Centralized Secret Vault
Category
Identity access
Implementation detail
Zero-Trust Identity Access proxy
Category
Security gates
Implementation detail
SCA and container image scanning
Category
Data protection
Implementation detail
WORM buckets with automated sensitive data scanning
Category
Threat detection
Implementation detail
Datadog SIEM with runtime monitoring

Results

Zero Static Credential Exposure

By using a secret vault and zero trust access tool, the platform has eliminated 100% of static SSH keys and long-lived database passwords for engineers.

Hardened Private Perimeter

The dynamic whitelisting strategy ensures the K8s API remains 100% private, with zero exposure to the public internet except for the seconds required for a deploy.

Automated Data Compliance

Automated bucket scanning ensures that sensitive insurance data is categorized and protected, reducing the risk of accidental PII exposure.

Real-Time Threat Visibility

The Datadog SIEM integration provides the security team with instant alerts on anomalous behavior, such as unauthorized access attempts or suspicious container activity detected by runtime security tools.

Through its partnership with Carbonteq, the Twin Premium Capital platform is now a model of modern, secure financial infrastructure, capable of scaling without compromising on data privacy or system integrity.

Work with us

Ready to build something that lasts?

Every engagement starts with a real conversation. No proposals, no pitch decks. Just an honest look at what you’re building and whether we’re the right team to build it.