Building a compliant digital banking foundation in three phases
TUROG helped Banank establish secure API management, FAPI-aligned identity, and end-to-end platform observability for a new digital banking proposition.
API management, identity, and observability
aligned authentication and authorisation controls
deployed and load-balanced on Kubernetes
About the customer
Banank is a Poland-based bank building a new digital banking platform. Its team needed more than middleware: it needed a secure, observable foundation designed around European open-banking and privacy expectations.
TUROG delivered the programme across three successive phases, expanding from API management into identity and access management, then monitoring and analytics.
Launching digital banking with security and regulation built in
Banank was assembling the base infrastructure for a digital bank. Its APIs needed protection, lifecycle controls, traffic management, and dependable access to distributed core banking services.
The identity layer also had to support strong customer authentication and prepare the platform for European open-banking and GDPR requirements. The team needed practical visibility into API health, runtime performance, authentication activity, and failure patterns.
- Secure publication and consumption of core banking APIs
- Open-banking readiness and FAPI 2.0 alignment
- Consent, privacy, and right-to-be-forgotten workflows
- Operational insight across APIs, infrastructure, and identity
“Each subsequent phase deepened the platform—and the team's ability to run it. That continuity was the clearest signal of confidence in the work.”
API, identity, and observability delivered as one platform
Phase one introduced WSO2 API Manager for API security, throttling, lifecycle control, and load-balanced access to Apache Fineract services in a distributed Kubernetes environment.
Phase two added WSO2 Identity Server as the authorisation authority. TUROG configured role-based access, strong customer authentication, consent capabilities, and a custom certificate-based authentication handler. Phase three completed the operating model with monitoring and analytics across the stack.
API management
Protected core endpoints with policies, rate limits, controlled publication, and distributed traffic management.
Identity and open banking
Implemented FAPI-aligned access controls, OTP flows, consent handling, RBAC, and custom certificate authentication.
Runtime observability
Added visibility into logs, JVM performance, heap usage, caching, error rates, latency, and API demand.
Identity analytics
Built dashboards for successful and failed sessions, login activity, and application-level authentication patterns.
A platform the internal team could operate and extend
By the end of the programme, Banank had a secure and measurable middleware foundation for its digital banking services. The team could deploy and protect APIs, operate identity controls, and see the health of the platform in day-to-day use.
Knowledge transfer was built into each phase, giving Banank's team the confidence to work on the systems directly. TUROG's selection for each successive phase reflected the trust established through delivery and technical depth.
- Protected, load-balanced access to distributed core services
- Strong authentication and fine-grained API authorisation
- Actionable dashboards across API and identity operations
- An enabled internal team able to operate the platform
