Success Story
Modernization and security hardening for Lavoris on AWS: frontends on CloudFront, observability, and a full security stack
Lavoris is an Argentine healthcare startup running its platform on AWS (EC2, EKS, DynamoDB). Craftech supported it with an initial infrastructure assessment and, on that basis, a modernization and security project delivered by Squad 3.
Challenge
Lavoris needed to tidy up and harden its AWS platform before scaling further: frontends served outside AWS (Netlify), no standardized security stack, incomplete observability, and a need for controls over code and data. The starting point was an assessment of billing, networking, monitoring, and security to set priorities.
Solution
Craftech began with a full assessment (billing, networking, monitoring, and security stack) and an analysis document with an improvement proposal. It then executed the project: migrated the frontends (Ausentismo and Portal Lavoris) from Netlify to Amazon CloudFront with a production rollout; rolled out Gitleaks in batches for secret detection across repositories; deployed a complete security stack —GuardDuty, Amazon Inspector, Security Hub (CSPM), and AWS Config— with actionable alert flows; migrated a DynamoDB table with AWS Backups; and configured cost alerts. The work was organized into epics (kickoff, instance migration, Gitleaks, observability, security tooling, and closeout).
Results
Frontends are now served from Amazon CloudFront in production, repositories have continuous secret detection (Gitleaks), and the account runs a managed security stack (GuardDuty, Inspector, Security Hub CSPM, AWS Config) with alert flows. Data resilience was reinforced with managed DynamoDB backups, and cost alerts were added. The project reached its closeout stage with a continuity plan for ongoing operations.
Stack & technologies