Global document storage solution

CLIENT

Re-insurance

TECHNOLOGIES

  • .NET
  • SQL Server,
  • CQRS
  • Alfresco DMS
  • Azure Cloud
  • Kubernetes

Case studies

Other usecases

Description

A multi-national re-insurance company successfully launched a secure document management platform that completely eliminated additional auditing costs while meeting strict international compliance requirements. The solution handles confidential documents across multiple countries with unique security policies.

The system architecture of the system that was developed
The system architecture of the system that was developed

Key Achievements:

  • Minimized Additional Audit Costs - minimize the new developed features and use as much existing solutions already available in the company
  • Full Compliance - Met international security standards across multiple jurisdictions without compromising functionality

Original Context

The company adheres to strict security standards for personal information storage and access rights management, with external audits conducted every six months to ensure compliance. Each audit process cost the company money and it has to be performed for each software system that is deployed in the company.

Basically any new software that is deployed inside the company was supposed to be attacked by a group of white hackers which tested the system security as black and white box. On top of this was also the audit cost which was directly porportioned with the number of lines written in the product.

Business Constraints:

  • Regulatory Complexity: Each country required unique security policies for document storage and access management
  • Audit Cost Risk: The company undergoes external security audits every six months - any new system could dramatically increase audit expenses
  • Compliance Requirements: Strict standards for personal information storage and access rights management with zero tolerance for violations
  • Integration Challenges: New systems needed to integrate seamlessly with existing certified authentication and authorization infrastructure

The Planning Paralysis: After more than 12 months of analysis, the project had not progressed beyond planning stages. The complexity of balancing security requirements, audit costs, and technical integration had created analysis paralysis. Business stakeholders were frustrated with the lack of progress while operational needs continued to grow.

Solution Approach

First step was to list all the available solutions that are inside of the company. Because of the audit cost, we leveraged already solutiosn which had an audit process build in. We made a list with each functionality and where it came from, which we sent to the Governance department. Several of the features that we had used were:

  • an already solution that could allow to store the documents
  • retrieve the company hierarchy graph of the people
  • Azure Graph users

Based on these we developed a set of rules which allowed to build on top of it, we were able to develop a simple authorization mechanism which required few lines of code.

Key Technical Decisions:

  • Alfresco DMS: Chosen for its enterprise-grade document management capabilities and existing certifications
  • Container Strategy: Docker containers managed by Kubernetes ensured consistent deployments across environments

The collaborative approach between client representatives and development team ensured that business requirements drove technical decisions, not the reverse.

Technology Stack Used:

  • .NET for core application development with proven enterprise reliability
  • Domain-Driven Design (DDD) and Event Sourcing for robust architectural patterns and precise audit trails
  • Alfresco DMS for document management with built-in compliance features
  • Azure Cloud with Kubernetes orchestration for scalable, secure cloud infrastructure
  • Docker containers for consistent deployment and maintenance

Conclusions

The project successfully broke through the planning paralysis by focusing on strategic reuse of existing certified infrastructure. The solution delivered full compliance across multiple jurisdictions while minimized additional audit costs - a critical business requirement that had blocked progress for over a year.

This approach demonstrates how understanding regulatory constraints can drive innovative technical solutions that deliver business value without compromising security or compliance requirements.