The challenge
A regional bank needed to run core transaction processing on public cloud infrastructure, but internal compliance and their regulator required on-prem-level data control. Every prior cloud migration attempt had stalled at the same review stage: nobody could prove, cryptographically, that the cloud provider couldn't access customer data.
The approach
Modelyo deployed a confidential boundary across the bank's existing cloud accounts: no new infrastructure, no migration of the underlying provider relationship. Kubernetes, the transaction database, and the analytics pipeline all moved inside a single hardware-enforced perimeter, with encryption keys held exclusively by the bank's own HSM.
The result
The bank's compliance team signed off without a single exception raised, the first cloud migration in the organisation's history to clear review on the initial submission. First workloads went live within three weeks of contract signature.
We didn't have to trust Modelyo's word for it. We could verify it ourselves, every time.Head of Cloud Security, regional banking group
