

Skalierbare Identity-Lösungen aus der Schweizer Cloud
Technologische Weiterentwicklung durch Replatforming auf AWS Kubernetes für den internationalen Markt
ITSENSE ist ein Schweizer Spezialist für Identity and Access Management (IAM) mit Sitz in Aarau. Mit der CoreOne Suite bietet das Unternehmen eine modulare IDaaS-Lösung, die Customer-IAM-, Enterprise-IAM- und E-Government-Szenarien abdeckt. Um seiner Mission gerecht zu werden, „einfache, effiziente und skalierbare IAM-Lösungen für den internationalen Markt" bereitzustellen, hat sich ITSENSE mit copebit und AWS zusammengetan, um eine umfassende technologische Transformation zu realisieren.
Im Zentrum des Projekts stand ein vollständiges Replatforming: Die bisherige Architektur wurde in eigenständige Microservices überführt und in die AWS-Region Zürich migriert. Die neue Plattform läuft auf Amazon EKS (Kubernetes) und nutzt modernste Cloud-Services wie OpenSearch für Analytics, ElastiCache für hochperformantes Caching und Amazon MQ für zuverlässiges Messaging. Ein besonderer Fokus lag auf der Mandantenfähigkeit, sodass mehrere unabhängige Organisationen parallel auf einer gemeinsamen Instanz betrieben oder exklusive Instanzen für hochregulierte Use Cases bereitgestellt werden können.
Die gesamte Infrastruktur wird über Infrastructure as Code (Terraform/OpenTofu) gesteuert, das Deployment erfolgt vollständig automatisiert nach GitOps-Prinzipien mit Flux. Durch die Integration von AWS-Sicherheitsdiensten wie GuardDuty, WAF, Shield und KMS wurde ein umfassendes End-to-End-Sicherheitsmodell etabliert. Das Ergebnis ist eine agile, hochgradig automatisierte Grundlage, die Innovation beschleunigt und Schweizer Qualitätsstandards mit internationaler Skalierbarkeit verbindet.
“We arrived on AWS with a platform that was already live for hundreds of enterprises, so there was no room to learn slowly.”

“We arrived on AWS with a platform that was already live for hundreds of enterprises, so there was no room to learn slowly.”

“We arrived on AWS with a platform that was already live for hundreds of enterprises, so there was no room to learn slowly.”

ITSENSE ist ein Schweizer Spezialist für Identity and Access Management (IAM) mit Sitz in Aarau. Mit der CoreOne Suite bietet das Unternehmen eine modulare IDaaS-Lösung, die Customer-IAM-, Enterprise-IAM- und E-Government-Szenarien abdeckt. Um seiner Mission gerecht zu werden, „einfache, effiziente und skalierbare IAM-Lösungen für den internationalen Markt" bereitzustellen, hat sich ITSENSE mit copebit und AWS zusammengetan, um eine umfassende technologische Transformation zu realisieren.
Im Zentrum des Projekts stand ein vollständiges Replatforming: Die bisherige Architektur wurde in eigenständige Microservices überführt und in die AWS-Region Zürich migriert. Die neue Plattform läuft auf Amazon EKS (Kubernetes) und nutzt modernste Cloud-Services wie OpenSearch für Analytics, ElastiCache für hochperformantes Caching und Amazon MQ für zuverlässiges Messaging. Ein besonderer Fokus lag auf der Mandantenfähigkeit, sodass mehrere unabhängige Organisationen parallel auf einer gemeinsamen Instanz betrieben oder exklusive Instanzen für hochregulierte Use Cases bereitgestellt werden können.
Die gesamte Infrastruktur wird über Infrastructure as Code (Terraform/OpenTofu) gesteuert, das Deployment erfolgt vollständig automatisiert nach GitOps-Prinzipien mit Flux. Durch die Integration von AWS-Sicherheitsdiensten wie GuardDuty, WAF, Shield und KMS wurde ein umfassendes End-to-End-Sicherheitsmodell etabliert. Das Ergebnis ist eine agile, hochgradig automatisierte Grundlage, die Innovation beschleunigt und Schweizer Qualitätsstandards mit internationaler Skalierbarkeit verbindet.
“Handling millions of exceptions a day requires a foundation that is governed, reproducible, and built to scale. A Terraform-managed landing zone, segmented accounts and per-step model choice on Amazon Bedrock in European regions mean BLP can use fast models where throughput matters and high-end models where the reasoning is hardest, without renegotiating compliance each time — and the same foundation is what lets them sell through AWS Marketplace into markets they weren’t in a year ago.”

“Handling millions of exceptions a day requires a foundation that is governed, reproducible, and built to scale. A Terraform-managed landing zone, segmented accounts and per-step model choice on Amazon Bedrock in European regions mean BLP can use fast models where throughput matters and high-end models where the reasoning is hardest, without renegotiating compliance each time — and the same foundation is what lets them sell through AWS Marketplace into markets they weren’t in a year ago.”

“Handling millions of exceptions a day requires a foundation that is governed, reproducible, and built to scale. A Terraform-managed landing zone, segmented accounts and per-step model choice on Amazon Bedrock in European regions mean BLP can use fast models where throughput matters and high-end models where the reasoning is hardest, without renegotiating compliance each time — and the same foundation is what lets them sell through AWS Marketplace into markets they weren’t in a year ago.”

ITSENSE ist ein Schweizer Spezialist für Identity and Access Management (IAM) mit Sitz in Aarau. Mit der CoreOne Suite bietet das Unternehmen eine modulare IDaaS-Lösung, die Customer-IAM-, Enterprise-IAM- und E-Government-Szenarien abdeckt. Um seiner Mission gerecht zu werden, „einfache, effiziente und skalierbare IAM-Lösungen für den internationalen Markt" bereitzustellen, hat sich ITSENSE mit copebit und AWS zusammengetan, um eine umfassende technologische Transformation zu realisieren.
Im Zentrum des Projekts stand ein vollständiges Replatforming: Die bisherige Architektur wurde in eigenständige Microservices überführt und in die AWS-Region Zürich migriert. Die neue Plattform läuft auf Amazon EKS (Kubernetes) und nutzt modernste Cloud-Services wie OpenSearch für Analytics, ElastiCache für hochperformantes Caching und Amazon MQ für zuverlässiges Messaging. Ein besonderer Fokus lag auf der Mandantenfähigkeit, sodass mehrere unabhängige Organisationen parallel auf einer gemeinsamen Instanz betrieben oder exklusive Instanzen für hochregulierte Use Cases bereitgestellt werden können.
Die gesamte Infrastruktur wird über Infrastructure as Code (Terraform/OpenTofu) gesteuert, das Deployment erfolgt vollständig automatisiert nach GitOps-Prinzipien mit Flux. Durch die Integration von AWS-Sicherheitsdiensten wie GuardDuty, WAF, Shield und KMS wurde ein umfassendes End-to-End-Sicherheitsmodell etabliert. Das Ergebnis ist eine agile, hochgradig automatisierte Grundlage, die Innovation beschleunigt und Schweizer Qualitätsstandards mit internationaler Skalierbarkeit verbindet.
“Now the pattern has flipped: when we want to move faster on AWS, we pull copebit in early rather than after we hit the wall. They know our architecture as well as we do, so a decision that used to cost us weeks of investigation takes one conversation. That is what has accelerated our AWS journey — not just the build, but how quickly we can keep changing it.”

“Now the pattern has flipped: when we want to move faster on AWS, we pull copebit in early rather than after we hit the wall. They know our architecture as well as we do, so a decision that used to cost us weeks of investigation takes one conversation. That is what has accelerated our AWS journey — not just the build, but how quickly we can keep changing it.”

“Now the pattern has flipped: when we want to move faster on AWS, we pull copebit in early rather than after we hit the wall. They know our architecture as well as we do, so a decision that used to cost us weeks of investigation takes one conversation. That is what has accelerated our AWS journey — not just the build, but how quickly we can keep changing it.”

Nachhaltigkeit ist unser Anspruch. Unser ESG-Zertifikat unterstreicht unser Engagement für den Umweltschutz, soziale Verantwortung und eine gute Unternehmensführung.