Secure Cloud Foundation for a Private Capital Platform
Controlled access for a high-trust investment environment.
The story of Twin Premium Capital
Twin Premium Capital is an insurance premium platform managing high-stakes financial calculations and capital distribution. Given the sensitive nature of insurance data, the platform's infrastructure is built on a Security-First philosophy, ensuring that every layer from code to cloud storage is monitored, audited, and protected.
To deliver on that promise at scale, Twin Premium Capital partnered with Carbonteq to engineer a hardened DevSecOps environment combining zero-trust access, automated compliance gates, and real-time threat correlation.
Challenges Faced by Twin Premium Capital
Securing Private Cloud Environments
To minimize exposure, the Kubernetes (k8s) and database instances are entirely private. This required a secure way for CI/CD pipelines and Engineers to interact with the cluster without exposing it to the public internet.
Managing Sensitive Data at Scale
With a high volume of unstructured data stored in buckets, the platform needed a way to ensure no PII (Personally Identifiable Information) was accidentally exposed or improperly stored.
Modernizing Access Management
Traditional SSH keys and VPNs were insufficient for a modern cloud-native team. The challenge was to provide seamless yet Zero-Trust access to GCP resources.
Infrastructure Visibility
Achieving a single pane of glass for security signals across GCP audit logs, container runtimes, and secret access.
Solution Provided: Hardened DevSecOps & Identity Governance
Carbonteq delivered a hardened DevSecOps and identity governance stack — combining a private CI/CD perimeter, zero-trust engineering access, automated data sanitization, and a SIEM integration that correlates security events in real time.
- •
Secure CI/CD & Private Perimeter: GitHub Action runners operate against a Private GKE Cluster with dynamic IP whitelisting — the runner's IP is dynamically whitelisted at the firewall level and immediately purged after the Helm Chart deployment completes. Every Pull Request triggers a mandatory security suite including SCA to scan all open-source dependencies for known vulnerabilities, and container scanning to identify CVEs in base images and application layers before they reach the registry.
- •
Zero-Trust Engineering Access with Teleport: We implemented a zero trust access tool which acts as a unified gateway for all infrastructure access. Engineers no longer use static SSH keys; instead, they use short-lived, identity-backed certificates to access K8s clusters, GCP instances, and Databases. Every session is logged and recorded, providing a complete audit trail of what was changed and by whom, satisfying internal compliance requirements.
- •
Data Sanitization & Infrastructure Scanning: Implemented a security layer to scan Cloud Storage buckets for sensitive data (PII), ensuring that while buckets follow WORM (Write Once, Read Many) protocols for integrity, they are also clean of unauthorized sensitive info. GCP Security Command Center provides continuous infrastructure scanning, detecting misconfigurations like open ports or unencrypted disks across the entire GCP organization.
- •
Secret Management & SIEM Integration: Centralized all application secrets in a Secret Vault for secure, encrypted injection into CI/CD and K8s pods — ensuring that no plain-text secrets ever exist in code repositories. All GCP Audit Logs, Teleport logs, and runtime alerts are streamed into Datadog SIEM, allowing the team to correlate a vault access event with a K8s shell event, providing real-time threat detection and automated security alerts.
Partnership & Performance Snapshot
- Category
- Secret management
- Implementation detail
- Centralized Secret Vault
- Category
- Identity access
- Implementation detail
- Zero-Trust Identity Access proxy
- Category
- Security gates
- Implementation detail
- SCA and container image scanning
- Category
- Data protection
- Implementation detail
- WORM buckets with automated sensitive data scanning
- Category
- Threat detection
- Implementation detail
- Datadog SIEM with runtime monitoring
| Category | Implementation detail |
|---|---|
| Secret management | Centralized Secret Vault |
| Identity access | Zero-Trust Identity Access proxy |
| Security gates | SCA and container image scanning |
| Data protection | WORM buckets with automated sensitive data scanning |
| Threat detection | Datadog SIEM with runtime monitoring |
Results
Zero Static Credential Exposure
By using a secret vault and zero trust access tool, the platform has eliminated 100% of static SSH keys and long-lived database passwords for engineers.
Hardened Private Perimeter
The dynamic whitelisting strategy ensures the K8s API remains 100% private, with zero exposure to the public internet except for the seconds required for a deploy.
Automated Data Compliance
Automated bucket scanning ensures that sensitive insurance data is categorized and protected, reducing the risk of accidental PII exposure.
Real-Time Threat Visibility
The Datadog SIEM integration provides the security team with instant alerts on anomalous behavior, such as unauthorized access attempts or suspicious container activity detected by runtime security tools.
Through its partnership with Carbonteq, the Twin Premium Capital platform is now a model of modern, secure financial infrastructure, capable of scaling without compromising on data privacy or system integrity.
Work with us
Ready to build something that lasts?
Every engagement starts with a real conversation. No proposals, no pitch decks. Just an honest look at what you’re building and whether we’re the right team to build it.
