İçeriğe geç
Tres Teknoloji
Solutions / Fintech and finance

Regulation-ready cloud, with audit-ready records

Infrastructure that meets data residency, isolation and auditability requirements for payment institutions, e-money companies and brokerage firms.

Requirements met
TCMB / BDDK Primary and secondary systems within Turkey.
PCI DSS A dedicated segment and WAF for the cardholder data environment (requirement 6.6).
KVKK and 5651 Log retention, time-stamping and access records.
MASAK Identity verification flow and audit trail (with Identio).
99.95% HA configuration SLA
RPO 1-5 min Disaster recovery target
2 regions Synchronous replication
2 years Audit log retention
Challenges

When the auditor arrives, finding the evidence should not take hours

In financial institutions the real cost is not the infrastructure itself, but the burden of proving compliance. Who accessed what and when, where the data resides and whether the backup works must all be documentable.

Dedicated cardholder data segment

Systems in PCI DSS scope are isolated in a separate VPC with a separate access policy.

Immutable audit trail

All administrative operations are stored with WORM object lock; they cannot be deleted.

Approved change management

Every change in production is recorded and goes through an approval flow.

DR drill report

A disaster recovery test is run once a quarter and its result is reported.

Recommended architecture

The architecture we typically build for payment and core banking workloads. It can be narrowed or expanded to fit your needs.

Entry layer
DDoS protection NetWaf (WAF) Load balancer TLS termination
Application
Virtual server (isolated) Kubernetes Private VPC Bastion access
Data
Managed PostgreSQL (HA) Encrypted block storage KMS key management
Compliance
Logchase (SIEM) WORM archive Time-stamping Identio (KYC)
Customer reviews

What fintech teams say

“Our PCI DSS audit went this smoothly for the first time. We could pull the access records the auditor asked for within minutes.”
EK Emre Kılıç Director of Information Technology · PayÇözüm Ödeme
“They migrated our core payment system in weekend windows; on Monday no one noticed a thing.”
SA Selin Aydın CTO · FinNokta
“Isolating the cardholder data environment in a separate VPC narrowed our audit scope and lowered our compliance cost.”
BD Burak Demir Information Security Manager · e-Para Teknoloji
S.S.S.

Frequently asked questions about fintech cloud infrastructure

Yes. Both primary and secondary (backup) systems run on infrastructure operated in Tier III+ data centers within Turkey; card and customer data never leaves the country.

The cardholder data environment (CDE) is segmented in a separate VPC with its own security groups and access policies. The NetWaf (WAF) in front of it meets PCI DSS requirement 6.6, which narrows the audit scope.

We use DDoS protection, a WAF and a load balancer at the entry layer; isolated virtual servers or Kubernetes at the application layer; and highly available PostgreSQL with KMS-encrypted storage at the data layer.

All administrative and access operations are held in a WORM (immutable) archive on Logchase (SIEM); records for any date range the auditor requests can be reported within minutes.

For 5651 and financial audit requirements, access and transaction logs are kept time-stamped for a default of two years; the period can be extended according to your organization’s policy.

In a highly available configuration the disaster recovery target is RPO 1-5 minutes, with continuous replication between two regions. The recovery scenario is tested and reported through a drill once a quarter.

Yes. The KYC/identity verification flow and an immutable audit trail are integrated with the Identio product; your customer onboarding processes are recorded in line with regulation.

Yes. The migration is done piece by piece in weekend maintenance windows, running in parallel with the old system; in one payment institution’s core system migration, transaction traffic never stopped and it was completed with zero downtime.

A case from this sector A payment institution migrated its core system in 6 weeks

The payment infrastructure running on physical servers was migrated to a virtual data center. The migration was done piece by piece in weekend windows, and transaction traffic never stopped. The PCI DSS audit was completed smoothly three months after the migration.

0 min Downtime
6 weeks Migration time
38% Infrastructure cost reduction

Talk to a team that knows your sector

A solution architect who has run projects in that sector joins the meeting. In the first meeting we produce an architecture draft and a cost range.

Schedule a meeting