Latest
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
Webinar: Release days shouldn't be stressful — solving the blast-radius problem Register Now →·
FinTech / Payments · Disaster Recovery · Azure Cloud

How Paycraft achieved PCI DSS 3.2 compliance with a green-field DR deployment on Azure

Paycraft is a payments company providing contactless, open-loop products for online and offline transaction processing. Since 2013, it has served banks, transit operators, card manufacturers, and global consulting companies. For a new green-field deployment, Paycraft needed to build its Azure environment around PCI DSS 3.2 requirements from the start. The architecture needed a disaster recovery site in a separate seismic zone, database synchronization between primary and DR environments, end-to-end encryption, and strict controls around infrastructure access. Flentas designed and deployed the Azure infrastructure, including the DR environment, database replication, network connectivity, security controls, and monitoring required for the deployment.

PaycraftContactless payment processingPCI DSS 3.2 requirementMillisecond transaction processing
At a Glance
PCI DSS 3.2Compliance achieved
Cross-regionDR site in a separate seismic zone
End-to-endSSL encryption, including database layer
The Challenge

A green-field build with strict compliance requirements from day one

Paycraft's new Azure environment had to satisfy specific compliance and resilience requirements while supporting a payment processing platform where availability and data protection were critical.

Load and DR provisioning

Application traffic needed to be distributed across web and application servers, while the DR environment had to be located in a different seismic zone from the primary data center.

Encryption and synchronization

The environment required SSL encryption through the application and database layers, along with synchronization between primary and secondary databases across the data center and DR regions.

Access and monitoring

Production infrastructure required controlled access, with strong authentication and monitoring of user activity across the Azure environment.

The Approach

A PCI DSS-compliant architecture built for resilience and visibility

Flentas designed the Azure environment around four key requirements: traffic management, database replication, disaster recovery, and security.

  1. 01

    Load balancing and database replication: Azure Load Balancers were placed in front of the web and application servers. MongoDB and PostgreSQL databases running on Azure VMs were replicated between the primary and secondary environments.

  2. 02

    Cross-region DR: Network peering was established between the primary and secondary regions, with database synchronization across environments and SSL encryption throughout the architecture.

  3. 03

    Network segmentation and access control: PCI-compliant network segmentation was implemented, with MFA-enabled bastion servers controlling access to web, application, and database servers. Trend Micro Deep Security was also deployed across the servers as an additional security layer.

  4. 04

    Connectivity and monitoring: VPN connectivity between Paycraft's on-premise network and Azure was established through Azure Virtual Network Gateway. NTP-based time synchronization was configured, while Azure Monitor and Log Analytics provided infrastructure monitoring.

Business Outcome

Compliant, resilient, and easier to monitor

The green-field deployment gave Paycraft an Azure environment designed around its compliance and disaster recovery requirements from the beginning.

PCI DSS 3.2 compliance

Required compliance artifacts were evaluated and submitted by the infrastructure and development teams, supporting the compliance process.

Disaster recovery readiness

Network peering, database synchronization, time synchronization, monitoring, and security controls were implemented across the primary and DR environments.

Stronger infrastructure security

Network segmentation, MFA-protected bastion access, SSL encryption, and Trend Micro Deep Security added multiple layers of protection.

Automated time synchronization

NTP-based synchronization removed the recurring manual effort previously required from the development team.

Centralized monitoring

Threshold-based monitoring was enabled across Azure infrastructure and Trend Micro Deep Security, providing visibility into the environment.

Technologies & Partners

Built on the Azure stack

Azure Load BalancersAzure Virtual Network GatewayMongoDB & PostgreSQL on Azure VMsTrend Micro Deep SecurityAzure MonitorAzure Log AnalyticsNetwork Time Protocol (NTP)
Common Questions

Related

Where this fits

BFSI

For banks, NBFCs, insurers, and fintechs, every release carries regulatory weight and every minute of downtime shows up in the news and in the numbers. Flentas helps you migrate, secure, and run your cloud so you can ship new products quickly, keep regulators satisfied, and hold uptime through your busiest days. From a 125 year old lender modernizing its core to a fintech scaling its first million users, we build the foundation that lets financial firms move fast without breaking what customers trust. Regulated. Resilient. AI ready.

Explore BFSI
Get Started

Ready to build a compliant, resilient architecture from the ground up?

Talk to an Azure-certified architect about your own deployment.