FinTech case study

NORTH Merchant & Partner Platform Case Study

Modernizing a serverless merchant and partner platform on AWS while continuing to ship business-critical features.

Build with Various Technologies

At a glance

Client
NORTH
Industry
FinTech
Services
Application Modernization, Custom Software Development, API Integration
Repositories migrated to GitHub Actions
10+
Microservices upgraded to Node.js 22
14+
Partner notification delivery
Sub-second
Business test scenarios passed
16/16

Overview

The Summary.

NORTH is a cloud-based merchant and partner platform built on a scalable serverless microservices architecture. It covers merchant onboarding, partner integrations, authentication and authorization, business workflows, notifications, and other critical operational processes.

The team works across platform engineering and business-critical product development, with a focus on scalability, security, reliability, and delivery speed.

Platform engineering and business-critical product development: CI/CD, runtime upgrades, security, authorization, partner notifications, and onboarding features.

The Challenge

Modernize the platform while continuing to deliver business-critical functionality safely and reliably.

  • A fragmented CI/CD setup across 10+ repositories
  • Outdated Node.js versions and critical dependency vulnerabilities
  • Complex authentication and authorization requirements
  • Legacy services with extensive business and payment logic
  • Unreliable partner integrations that needed real-time communication
  • Broken API documentation and test/mock data
  • High-priority business changes that had to ship without disrupting existing functionality

What the Team Delivered

  • CI/CD Modernization

    10+ serverless repositories moved from Bitbucket to GitHub Actions, with a standardized build-once, deploy-everywhere process.

    • Upgraded 14+ microservices to Node.js 22
    • Remediated critical dependency vulnerabilities
    • Added CI pre-flight checks to catch missing build tools early
    • Wrote migration documentation for other teams
    • Recovered ~650 broken mock/test values across 103 files
  • Authentication & Authorization

    A scalable authorization model for internal services and external clients.

    • Database-backed RBAC for roles, permissions, and resource-level access
    • Standardized token-based authentication
    • Client ID / client secret authentication
    • Reusable authentication libraries
    • Efficient permission evaluation that scales with the platform
  • Real-time Partner Notifications

    An event-driven platform that automatically delivers critical business events to external partners.

    • Sensitive-data cleansing
    • Security validation of external destinations
    • Digital message signatures
    • Independent delivery processing per partner
    • Delivery audit trails, failure monitoring, and team alerts

    Each partner is processed independently, so one unavailable system never blocks the rest. Delivery went from minutes or hours to under a second.

  • Business-critical Product Engineering

    Complex business rules in the merchant onboarding platform, such as the “No Deployment” option that sales agents didn't always read as “no equipment will ship”.

    • Investigated every relevant case
    • Aligned the expected behavior with the business
    • Added a confirmation-stage warning covering all applicable scenarios

    16/16 test scenarios passed with no false warnings.

Results and Impact

CI/CD
10+ repositories migrated to GitHub Actions
Runtime
14+ microservices upgraded to Node.js 22
Security
Critical dependency vulnerabilities remediated
Test/mock data
~650 values restored across 103 files
Notifications
Delivery reduced from minutes/hours to sub-second
Notification tracking
100% of delivery attempts recorded in audit history
Business validation
16/16 test scenarios passed with no false warnings
Architecture
Standardized serverless patterns introduced
Authorization
Scalable database-backed RBAC implemented

Technical Challenges

Legacy modernization
Upgrading 14+ services to Node.js 22 while keeping existing dependencies, plugins, and deployment processes compatible.
Complex business logic
Some legacy validation modules hold 5,000+ lines of business and payment rules, so small changes can carry real risk.
External system reliability
Partner integrations had to tolerate slow or unavailable external systems without one failure affecting other partners.
Security
Critical vulnerabilities had to be remediated and partner-facing functionality protected without breaking changes.
Data recovery
A cleanup process affected 650+ mock/test values across 103 files, requiring systematic recovery with production data kept isolated.

Engineering Approach

  • Build once, deploy everywhere, so the tested artifact is the deployed artifact
  • Reusable serverless patterns for faster new-service development
  • Database-backed RBAC for explicit, scalable authorization
  • Independent event delivery to isolate partner failures
  • Continuous dependency management to address vulnerabilities early
  • Business-rule validation before QA to surface edge cases sooner

Technology Stack

Cloud & architecture

  • AWS Lambda
  • Amazon API Gateway
  • Amazon S3
  • AWS CodeBuild
  • AWS MWAA / Apache Airflow
  • AWS IAM
  • Serverless Framework
  • Docker

Backend & data

  • Node.js 22
  • TypeScript / JavaScript
  • PostgreSQL / MySQL

Frontend

  • React
  • TypeScript
  • Redux
  • Vite
  • Tailwind CSS
  • Keycloak

Testing & security

  • Jest
  • Playwright
  • Snyk
  • npm audit
  • Dependabot

CI/CD & API

  • GitHub Actions
  • Make
  • OpenAPI / Swagger
  • ReDocly
  • Claude Code

What This Project Shows

NORTH shows the team combining platform modernization, cloud architecture, security, and product engineering inside a complex legacy environment.

The team owns work across the full delivery lifecycle, from architecture and infrastructure through backend and frontend development, automated testing, security remediation, and production-critical business features, so the platform modernizes without slowing product delivery or compromising reliability.

Start the conversation

Facing a Similar Challenge?

Tell us what you're building or fixing. You'll meet the engineers who would work on it before you sign anything.