Mercury builds financial infrastructure for startups — which means regulators, auditors, and security-conscious customers all ask how access is controlled. Their answer: identity everywhere, network location nowhere.
A remote-first fintech can't lean on "the office network is trusted" — there is no office network. Yet the infrastructure (production systems, databases, payment integrations) needed access controls that satisfy financial-industry scrutiny. Early on, that meant a patchwork: a VPN for some systems, cloud-specific access for others, and tribal knowledge about which tool reached what.
Mercury made OpenVLAN the single access path to production: every engineer connects through corporate SSO, every system sits behind ACLs keyed to teams, and privileged sessions are recorded. The security team's policy became actual network policy instead of a document.
access path to audit instead of many
privileged sessions recorded
production systems with public endpoints
Security reviews got shorter. When every access question has the same answer — "it's in the ACLs, here's the log" — due diligence stops being a project and becomes a report.
This case study is an illustrative example with fictional data for demonstration purposes.