Main challenge

A platform that got slower as more people used it.

The system was built as one monolithic application. As the user base grew, it became slower and harder to maintain, and a security audit found further problems.

  • Slow Booking Engine

    Performance problems were worst in the booking engine and the event management modules.

  • Long Load Times

    Users waited, and administrators dealt with slow screens and unstable deployments.

  • Manual Deployments

    Releases depended on manual steps, which slowed the in-house team down.

  • Audit Findings

    The security audit found configuration gaps and inconsistent infrastructure management.


Project approach

Working inside the client's engineering team.

We joined the client's engineers with architecture experience, AWS integration and extra development capacity. Together we set four goals: better performance, no manual deployment steps, a fix for every audit issue, and infrastructure that scales with demand.


How we solved it

The core system rebuilt on a serverless AWS stack.

We moved the core services to AWS Lambda behind API Gateway, so the backend scales automatically with demand and no longer pays for idle capacity. Every resource is defined in Terraform, which makes environments easy to copy, version and audit.


Key features

What the new platform runs on.

  • Serverless Backend

    Core services on AWS Lambda behind API Gateway, scaling automatically with demand.

  • Amplify Frontend

    A preview for every feature branch, one-click rollbacks and a global CDN.

  • Terraform Infrastructure

    Every API, function, IAM role and Amplify app defined as code.

  • Cognito Sign-In

    One identity system for admins, organisers and participants, with role mapping and token-based access.

  • CI/CD Pipeline

    CodeBuild runs builds and tests, and CodePipeline deploys to staging and production.

  • Performance Tuning

    Database tuning for high load, faster Lambda cold starts and better timeouts and retries.


Security

Audit findings fixed, then tested again.

  • Least-Privilege IAM
  • Encryption in Transit
  • Encryption at Rest
  • Token-Based Access
  • Infrastructure as Code
  • Stricter Access Controls

Separate Staging and Production

Isolated environments with stricter controls, so every change is tested before it reaches users.


Business impact

Faster releases on a system that is easier to maintain.

95% Less Deployment Time
After deployments moved to the CodeBuild and CodePipeline pipeline.
0 Critical Vulnerabilities
In follow-up security testing after the audit fixes.

The platform performs better under real use, and the in-house team releases in shorter cycles, so it spends more of its time on new features. The infrastructure has room to grow with the user base.


Outcome

An in-house team free to build new features.

The client now runs its booking platform on infrastructure it can change safely and scale when demand grows. Our work with the in-house team continues after more than two years.