Passed a regulatory audit with segregation-of-duties policies enforced in the pipeline.
“The auditors asked who approved a change in March. It took eleven seconds to answer.”
Release 2390
rolling out started 4m 02s ago-
build
24s
-
test
1m 12s
-
staging
8s
-
canary
25%
-
production
—
| Service | Version | |||
|---|---|---|---|---|
| api-gateway | production | v2.14.0 | live | 1m 48s |
| checkout | canary | v2.14.0 | rolling | 4m 02s |
| search-index | staging | v2.14.1 | queued | — |
| billing | production | v2.13.2 | live | 2h ago |
Pipelines
Three pipeline files, 41 services, one promotion path each.
| Pipeline | Runs (30d) | Success | Last run |
|---|---|---|---|
| web-monorepo | 412 | 99.3% | 6m ago |
| platform-services | 1,284 | 98.8% | 12m ago |
| data-jobs | 96 | 100% | 1h ago |
Environments
Promotion order is fixed. Production requires two approvals.
- production 2 approvals
eu-west-1 · 38 services
- canary
eu-west-1 · 38 services
- staging
eu-west-1 · 41 services
- dev
local · 41 services
Industry
Financial services
Headquarters
Tallinn, EE
Size
3,200 employees
Relationship
Customer since 2023
- 11s
- to answer an audit query
- 2 yr
- retained history
- 100%
- changes attributable
The story
How Kestrel Bank moved from where they were to where they are, in their platform team's words.
The problem
Every audit began with a two-week evidence-gathering exercise. Proof that the person who wrote a change was not the person who approved it lived across screenshots, ticket comments and email threads, assembled by hand each time. The control existed and was genuinely followed — it simply could not be demonstrated quickly, and an auditor's question about a specific change six months ago could take days to answer.
What changed
Segregation of duties became a policy the pipeline enforces rather than a convention people follow: the author of a change cannot approve its promotion, and production requires an approver from a named group mapped out of Okta. Deploy credentials are issued per promotion from Vault and expire, so a standing production credential no longer exists. Every promotion records the checks, the approver and the diff, retained for two years.
Where they are now
The audit passed with the pipeline itself submitted as the control evidence. A query about any individual change is answered from the release record in seconds rather than days, and every change in the retention window is attributable to a named approver.
“We stopped preparing for audits. The evidence is a by-product of deploying, not a project.”
Marta Ilves · Head of Platform, Kestrel Bank Get started
Put every release behind one gate.
Start with a single environment for free. Add the rest when your team is ready — no migration, no rebuild, no second dashboard.
- Free for one environment
- SOC 2 Type II
- Self-host or managed
- No card required