AWS Managed Services / Cloud Infrastructure
Voly Group is the market-leading yacht and multi-asset financial management platform designed for superyacht captains, crew, owners, management companies, and family offices. Founded in 2016, Voly serves the global maritime industry with cloud-based accounting, treasury management, and crew services. Recognised as number one Best Superyacht Software for three consecutive years. CloudiQS delivers ongoing AWS Managed Services and Managed Security Services, providing continuous infrastructure operations, PCI DSS Level 1 compliance governance, threat detection, incident response, and operational resilience for mission-critical financial systems serving a global maritime client base.

Manage Services, Security and Scalability
Customer Challenges
As Voly Group rapidly expanded its global maritime SaaS platform, its infrastructure needed to support 24/7 financial operations for superyacht captains, crew, owners, and family offices operating across multiple time zones.
The platform processes real-time financial transactions for high-net-worth individuals, requiring continuous availability, strong encryption, strict access control, and PCI DSS Level 1 compliant payment processing. With two strategic acquisitions (Voyonic and WorkRest), Voly needed to integrate additional systems quickly without disrupting live services or compromising security posture.
Key challenges included:
- Limited scalability during international growth across APAC and Americas
- Increasing API latency for global users accessing the platform at sea
- PCI DSS Level 1 compliance requirements for payment processing
- Security requirements for sensitive financial data across multiple jurisdictions
- No continuous threat detection or container-level security monitoring
- Complex acquisition integration requiring secure account and identity consolidation
- Lack of centralised security monitoring and structured incident response
- Need for continuous security operations for a 24/7 global customer base
- Hybrid AWS and Azure environment requiring multicloud security governance
Voly required a managed services partner capable of delivering continuous infrastructure operations, PCI DSS compliance management, threat detection and response, and performance optimisation across global operations.
AWS Cloud-Native Architecture for Global Maritime Operations
Our Solution
CloudiQS designed and implemented a cloud-native AWS architecture optimised for high-availability financial workloads, PCI DSS compliance, and global maritime access, with comprehensive managed services covering both infrastructure operations and security operations.
AWS Cloud Infrastructure:
- Amazon ECS Fargate for containerised application scalability with task-level security group isolation
- Amazon Aurora PostgreSQL Global Database for low-latency multi-region financial data access
- Amazon CloudFront CDN for optimised mobile performance at sea across global edge locations
- Amazon API Gateway and AWS Lambda for serverless transaction processing
- Multi-AZ deployments with automated failover across three availability zones
- Amazon CloudWatch with custom dashboards for Fargate task health, Aurora replication, API latency, and Lambda performance
- CI/CD pipelines enabling 3 to 4 releases per week with automated security scanning and rollback
Security and Compliance Architecture:
- Amazon GuardDuty with ECS Runtime Monitoring for container-level threat detection including privilege escalation, suspicious processes, and network anomalies
- AWS Security Hub with FSBP, CIS, and PCI DSS standards for centralised security and compliance posture management
- Amazon Security Lake providing OCSF-normalised centralised log aggregation across all sources for unified security analysis
- Amazon Inspector for automated vulnerability scanning across EC2 and container workloads
- AWS Shield Advanced for DDoS protection on internet-facing financial API endpoints
- AWS WAF with managed and custom rule groups for application-layer protection of payment processing endpoints
- AWS KMS with customer-managed keys and automatic rotation for financial data and cardholder data encryption
- AWS Secrets Manager with automatic 30-day credential rotation for database and API credentials
- Amazon ECR with scan-on-push for container image vulnerability scanning before deployment
- AWS CloudTrail organisation trail with log file validation for complete API audit logging
- AWS Config with compliance rules monitoring PCI DSS configuration requirements continuously
- IAM Identity Center with Azure AD/Entra SAML federation and SCIM automated user provisioning
- IAM Access Analyzer for continuous least-privilege validation and external access detection
- Amazon EventBridge routing operational and security events to CloudiQS SOC via PagerDuty
- Dedicated PCI Cardholder Data Environment in isolated VPC with stricter SCPs and network controls
Resilience Architecture:
Isolated backup account with restricted access and separate IAM controls
AWS Backup with automated daily and weekly plans and cross-region replication
Amazon S3 Object Lock for immutable backup storage preventing tampering or deletion
Aurora Global Database providing cross-region failover with 15-minute RPO
Documented RTO (2 hours) and RPO (15 minutes) with quarterly PCI-validated DR testing


99.98% Uptime, 65% Faster Performance, 40% Cost Reduction
Ongoing AWS Managed Services and Managed Security Services:
- Following deployment, Voly Group engaged CloudiQS under a comprehensive AWS Managed Services agreement covering both infrastructure operations and security operations. CloudiQS provides:
- Infrastructure and Operations Management:
- 24/7 infrastructure and application monitoring via Amazon CloudWatch with real-time alerting
- SLA-driven incident response including triage, remediation, and root cause analysis
- Container management including ECS Fargate task health monitoring, image updates, and rolling deployments
- Aurora Global Database performance tuning, query optimisation, and replication monitoring
- Proactive scaling management during transaction volume spikes
- CI/CD pipeline management supporting 3 to 4 releases per week with automated rollback
- Monthly cost optimisation reviews (achieved 40% cost reduction, GBP 8,200 monthly savings)
- Quarterly architecture reviews against AWS Well-Architected Framework
- Security and Compliance Operations:
- Continuous threat detection via Amazon GuardDuty with ECS Runtime Monitoring and AWS Security Hub with 24/7 SOC monitoring
- Centralised security analytics via Amazon Security Lake with OCSF-normalised log analysis
- NIST 800-61 aligned incident response with P1 acknowledgment SLA under 30 minutes
- Continuous PCI DSS Level 1 compliance monitoring via Security Hub PCI standard and AWS Config rules
- Container security management including ECR image scanning enforcement, Fargate task security group reviews, and runtime threat monitoring
- Continuous vulnerability management via Amazon Inspector with risk-prioritised remediation
- IAM governance including quarterly access reviews with PCI-specific cardholder data access certification
- Azure AD/SCIM integration management for automated identity lifecycle (joiners, movers, leavers)
- Encryption lifecycle management including KMS key rotation and Secrets Manager credential rotation
- Shield Advanced and WAF rule management for financial API endpoint protection
- Security Lake ingestion optimisation and cost management (30% reduction achieved)
- Resilience and Business Continuity:
- Multi-region backup validation and integrity testing
- Quarterly PCI-validated disaster recovery drills against documented RTO/RPO targets
- Aurora Global Database failover testing
- Immutable backup architecture with S3 Object Lock and isolated backup account
- Acquisition integration playbooks (Voyonic and WorkRest integrated in 6 weeks)
- Governance and Reporting:
- Monthly operational reports covering uptime, incidents, patch compliance, PCI posture, security findings, and cost
- Quarterly PCI compliance review and audit readiness assessment
- Quarterly strategic reviews with customer leadership
- CloudiQS MSP Portal providing real-time dashboards across Security, Cost, Operations, Resilience, and Engineering dimensions
- Multicloud Support:
- Voly operates a hybrid AWS and Azure environment. CloudiQS manages security across both platforms, providing unified monitoring, incident response, and compliance governance spanning AWS-native and Azure-hosted workloads.
- CloudiQS operates as Voly’s outsourced cloud operations and security operations team, delivering continuous infrastructure management, PCI DSS compliance, threat detection, incident response, and security governance for mission-critical global financial systems.

The Results?
Reliability and Performance:
- Achieved 99.98% uptime (improved from 99.5%)
- Reduced API response times by 65% (850ms to 300ms)
- Eliminated unplanned downtime impacting financial transactions
- Enabled 24/7 global access across time zones
Security and Compliance:
- 50% reduction in high-severity security incidents year-over-year
- Sub-30-minute acknowledgment for critical security incidents
- Continuous PCI DSS Level 1 compliance monitoring and audit readiness
- Container-level threat detection via GuardDuty ECS Runtime Monitoring
- Centralised security analytics via Security Lake
Operations and Growth:
- Increased deployment velocity 3x (weekly to 3 to 4 releases per week)
- Integrated two acquisitions in 6 weeks (versus 4 to 6 months previously)
- Enabled expansion into APAC and Americas without new infrastructure investment
- Reduced infrastructure costs by 40% (GBP 8,200 monthly savings)
- Improved cost predictability through structured cloud governance
AWS Services:
Amazon ECS Fargate, Amazon Aurora PostgreSQL, Amazon CloudFront, Amazon API Gateway, AWS Lambda, Amazon CloudWatch, AWS CloudFormation, Amazon GuardDuty, AWS Security Hub, Amazon Security Lake, Amazon Inspector, AWS Shield Advanced, AWS WAF, AWS KMS, AWS Secrets Manager, Amazon ECR, AWS CloudTrail, AWS Config, Amazon EventBridge, AWS Systems Manager, AWS Backup, Amazon S3, Amazon VPC, IAM Identity Center, IAM Access Analyzer, AWS Organizations, AWS Control Tower