All customer stories
Customer storyDigital banking

Building a compliant digital banking foundation in three phases

TUROG helped Banank establish secure API management, FAPI-aligned identity, and end-to-end platform observability for a new digital banking proposition.

PolandMulti-phase programmeAPI management & identity
BCustomer story
Banank
API management & identity
3 phases

API management, identity, and observability

FAPI 2.0

aligned authentication and authorisation controls

1 distributed stack

deployed and load-balanced on Kubernetes

Banank

About the customer

Banank is a Poland-based bank building a new digital banking platform. Its team needed more than middleware: it needed a secure, observable foundation designed around European open-banking and privacy expectations.

TUROG delivered the programme across three successive phases, expanding from API management into identity and access management, then monitoring and analytics.

WSO2 API ManagerWSO2 Identity ServerApache FineractKubernetesFAPI 2.0
The challenge

Launching digital banking with security and regulation built in

Banank was assembling the base infrastructure for a digital bank. Its APIs needed protection, lifecycle controls, traffic management, and dependable access to distributed core banking services.

The identity layer also had to support strong customer authentication and prepare the platform for European open-banking and GDPR requirements. The team needed practical visibility into API health, runtime performance, authentication activity, and failure patterns.

  • Secure publication and consumption of core banking APIs
  • Open-banking readiness and FAPI 2.0 alignment
  • Consent, privacy, and right-to-be-forgotten workflows
  • Operational insight across APIs, infrastructure, and identity
Each subsequent phase deepened the platform—and the team's ability to run it. That continuity was the clearest signal of confidence in the work.
TUROG delivery team
The solution

API, identity, and observability delivered as one platform

Phase one introduced WSO2 API Manager for API security, throttling, lifecycle control, and load-balanced access to Apache Fineract services in a distributed Kubernetes environment.

Phase two added WSO2 Identity Server as the authorisation authority. TUROG configured role-based access, strong customer authentication, consent capabilities, and a custom certificate-based authentication handler. Phase three completed the operating model with monitoring and analytics across the stack.

01

API management

Protected core endpoints with policies, rate limits, controlled publication, and distributed traffic management.

02

Identity and open banking

Implemented FAPI-aligned access controls, OTP flows, consent handling, RBAC, and custom certificate authentication.

03

Runtime observability

Added visibility into logs, JVM performance, heap usage, caching, error rates, latency, and API demand.

04

Identity analytics

Built dashboards for successful and failed sessions, login activity, and application-level authentication patterns.

The result

A platform the internal team could operate and extend

By the end of the programme, Banank had a secure and measurable middleware foundation for its digital banking services. The team could deploy and protect APIs, operate identity controls, and see the health of the platform in day-to-day use.

Knowledge transfer was built into each phase, giving Banank's team the confidence to work on the systems directly. TUROG's selection for each successive phase reflected the trust established through delivery and technical depth.

  • Protected, load-balanced access to distributed core services
  • Strong authentication and fine-grained API authorisation
  • Actionable dashboards across API and identity operations
  • An enabled internal team able to operate the platform
Ready to get started?

Let's turn your platform challenge into the next customer story.

Talk to us