Case Study

Security-First AI Platform on Azure

From zero to encrypted-by-default platform with AKS, PostgreSQL, and Azure Front Door

AI Legal Tech <50 Confidential

Quick Facts

Engagement
Greenfield Azure platform build (security-first)
Duration
8-12 weeks
Date
Q4 2025
Start your project →

Deploys / day

N/A

Lead time

N/A

MTTR

N/A

Encryption at rest everywhere with customer-managed keys (Key Vault/HSM)

AKS with private networking and Azure Front Door (WAF) for global ingress

Managed PostgreSQL (HA, PITR) with private endpoints and CMK

Overview

Project Overview

We built Boulevard Tech's security-first cloud platform from the ground up on Azure, enabling compliant, encrypted-by-default operations while preserving rapid delivery for AI features.

Business Context

As an AI legal tech company handling sensitive documents, Boulevard Tech required strong data protection, audit readiness, and a scalable foundation to support fast product iteration.

What We Did

Provisioned a greenfield Azure platform with AKS, Azure Front Door (WAF), and Azure Database for PostgreSQL; enforced encryption at rest using customer-managed keys; implemented private networking, identity/RBAC, and policy guardrails; codified everything with Terraform; and established a CI/CD pipeline for secure, automated deployments.

Challenges

What Was Holding Them Back

Protecting sensitive legal data

Implementing CMK-backed encryption, secret management, and auditable controls without slowing teams.

Zero-trust networking

Private clusters/endpoints, segmented VNets, and WAF-protected ingress.

Compliance readiness

Aligning to GDPR/SOC 2/ISO 27001 practices while keeping delivery velocity high.

Goals

Target Outcomes

Security-first foundation with customer-managed keys and encryption at rest across services

Reliable, scalable AKS and managed PostgreSQL with private endpoints

Global, protected ingress via Azure Front Door with WAF

Solution

How We Built It

Environment

Azure AKS, Azure Database for PostgreSQL (HA/PITR), Azure Front Door (WAF), Key Vault (CMK/HSM), private networking, Azure Monitor/Log Analytics

Practices

Security by design, infra as code, environment promotions, least-privilege IAM

IaC & Platforms

Terraform, Azure (AKS/Front Door/PostgreSQL/networking), Azure Key Vault, Azure Policy

Security

Encryption at rest with CMK, Key Vault-backed secrets, least-privilege IAM/PIM, private endpoints, Azure Policy guardrails, WAF, MS Defender for Cloud

Observability

Azure Monitor and Log Analytics; alerts integrated with team workflows

Implementation

Step-by-Step Implementation

  1. Foundations: Landing zone, VNet, private endpoints, Key Vault with CMK/HSM and key rotation
  2. Data: Azure Database for PostgreSQL (HA, backups/PITR) with private access and CMK encryption
  3. Compute: Private AKS cluster with RBAC, pod security/policies, managed identities
  4. Edge: Azure Front Door (WAF) to private ingress, TLS everywhere
  5. Guardrails: Azure Policy, Defender for Cloud, logging and audit
  6. Handover: CI/CD integration and operational runbooks
Results

Measurable Impact

Deployment Frequency

Multiple per day

Lead Time for Changes

N/A

Change Failure Rate

N/A

MTTR

N/A

Cloud Cost

Uptime

“Working with acks.io was one of the best decisions we made aiming for infra that is both secure and scalable. They made sure the solutions served our specific needs and the highest standards. Top notch work for reasonable fees”

— Joosua Virtanen — CEO @ Boulevard Tech Oy

Tech Stack

Technologies Used

Azure AKS Azure Database for PostgreSQL Azure Front Door (WAF) Azure Key Vault (CMK/HSM) Azure Policy Terraform Azure Monitor/Log Analytics MS Defender for Cloud

Have a similar challenge?

Book a free 30-minute discovery call and get a tailored plan for your infrastructure.