All success stories

Building Qawn’s regulated AWS platform end to end

CloudVests designed and delivered Qawn’s AWS platform end to end—from a governed, PCI DSS-aligned landing zone and hybrid bank connectivity to microservices, data engineering, security, observability, and GitOps delivery.

ClientQawn — Jordan Ahli Bank
60%lower cloud operating cost
99.99%uptime through transaction peaks
65%faster feature releases
150K+active users supported

Core services in the architecture.

A focused view of the AWS services most representative of this engagement. The complete technical scope is described below.

  1. 01AWS Control Tower
  2. 02AWS IAM Identity Center
  3. 03AWS Security Hub
  4. 04AWS Key Management Service
  5. 05AWS Site-to-Site VPN
  6. 06Amazon Elastic Kubernetes Service
  7. 07Amazon API Gateway
  8. 08AWS Glue
  9. 09Amazon Redshift
  10. 10Amazon CloudWatch

Watch the project story.

Hear the context, approach, and results directly in this project feature.

01

The challenge

Jordan Ahli Bank set out to launch Qawn, Jordan’s first social payment application connected to the national CliQ payment switch. The platform needed to support consumer-scale growth while meeting the reliability, security, auditability, and data-protection expectations of a regulated bank.

This was not a lift-and-shift hosting engagement. The bank needed an end-to-end cloud operating model: governed AWS accounts, federated workforce access, private connectivity to on-premises banking data, encrypted application and analytics services, resilient event-driven microservices, centralized observability, and controlled software delivery. The architecture also had to align with the AWS Well-Architected Framework and PCI DSS control requirements from the beginning.

02

What CloudVests delivered

CloudVests worked alongside the bank, product, development, operations, and big-data teams as the AWS architecture and delivery partner. We designed the target platform, implemented the foundational controls, enabled the application and data workloads, and established the operational practices required to run the service securely in production.

Governed multi-account foundation

We built the AWS organization and landing zone using AWS Organizations and AWS Control Tower, creating governed account boundaries for shared services, security, application environments, and data workloads. Preventive and detective controls established a consistent baseline across accounts, while AWS Config and AWS CloudTrail produced configuration and activity evidence for operational and compliance review.

Federated identity and regulated access

AWS IAM Identity Center was integrated with Microsoft Entra ID, formerly Azure Active Directory, so workforce access followed the bank’s existing identity lifecycle. Developers and operators received role-based, least-privilege access without relying on shared or long-lived credentials, and AWS Client VPN provided controlled remote access to private cloud resources.

Security, encryption, and continuous assurance

The security architecture combined AWS Security Hub, Amazon GuardDuty, Amazon Macie, AWS Config, and AWS CloudTrail to centralize findings, detect threats, identify sensitive data, and retain an auditable record of change. AWS Key Management Service governed encryption keys, and data was protected in transit and at rest across storage, application, analytics, and integration paths. AWS WAF protected public endpoints, including APIs exposed through Amazon API Gateway.

Hybrid connectivity to bank systems

CloudVests implemented AWS Site-to-Site VPN connectivity between the AWS environment and the bank’s on-premises network, enabling the platform to integrate privately with bank databases and dependent services. The connectivity design was incorporated into routing, access control, monitoring, and recovery planning rather than treated as a standalone network tunnel.

Event-driven microservices and protected APIs

We helped the application teams build an event-driven microservices platform using Amazon ECS and Amazon EKS for Kubernetes-based workloads. Elastic Load Balancing and AWS Auto Scaling supported resilient capacity across Availability Zones, while Amazon API Gateway and AWS WAF provided a governed, protected entry point for service APIs and external integrations.

Data engineering and analytics platform

Working with the bank’s big-data team, CloudVests established ingestion and ETL patterns using Amazon Kinesis Data Streams and AWS Glue. Amazon S3 provided the durable data foundation, Amazon Athena supported governed ad hoc analysis, and Amazon Redshift served analytical workloads that required warehouse-scale querying and reporting.

Centralized observability, GitOps, and CI/CD

Application, container, network, and security telemetry was consolidated through Amazon CloudWatch and centralized dashboards and alerts using Grafana and Prometheus. GitOps practices made desired platform and application state reviewable and repeatable, while AWS CodePipeline automated build, validation, and deployment stages across environments.

03

The outcome

Qawn launched on an AWS platform engineered as a regulated banking environment rather than a collection of isolated cloud services. Governance, identity, connectivity, encryption, security findings, observability, and delivery controls operate as one end-to-end model across the application and data estate.

The bank gained a reliable microservices foundation for the social-payments product, a private integration path to on-premises banking systems, and an analytics platform that allows the big-data team to ingest, transform, and query operational data using managed AWS services.

CloudVests’ contribution covered the complete cloud lifecycle: architecture, landing-zone implementation, security and PCI DSS alignment, hybrid networking, application and data enablement, observability, CI/CD, GitOps, operational readiness, and close knowledge transfer with the bank’s teams.

“CloudVests accelerated Jordan Ahli Bank’s technology deployment on AWS, going above and beyond to ensure success. Their talented team saved us significant time and effort.” — Nidal Khalifeh, Chief Information Officer, Jordan Ahli Bank