Success Story
Secure PCI-DSS infrastructure on AWS for Glic Solutions: a compliant foundation for processing payments
Glic Solutions is a Uruguay-based company focused on secure technology solutions for the global payments industry: it designs tokenization, gateway and alternative-payment products to operate in any country, currency and market reality. Craftech built the AWS infrastructure that let it meet PCI-DSS certification requirements.
Challenge
The goal was to implement a fully secure, PCI-DSS-compliant infrastructure to achieve certification. While the guidelines were clear from the start, the challenge was purely technical: it required double-checking every resource for compliance with the standard, on an isolated architecture that minimized common exposure problems.
Solution
Craftech designed a scalable, highly available, compliance-oriented architecture with security as its premise: least-privilege access and segmented networking with deny-by-default. It segmented networking into VPCs with public, private and persistence subnets, applied deny-by-default NACLs, Network Firewall and WAF rules. It implemented event auditing with CloudTrail, AWS Config, Security Hub, Inspector and GuardDuty; built a SIEM on OpenSearch with event ingestion and correlation via Lambda and Kinesis; encrypted resources with KMS; and produced PCI-compliant documentation along with alerts so any incident triggered SOC review.
Results
Glic used this infrastructure as the architectural foundation to meet PCI-DSS certification requirements. The platform became the basis for securely processing financial transactions, with segmented networking, end-to-end security observability (SIEM + GuardDuty + Security Hub) and managed encryption.
Stack & technologies
