Case study · Fintech · remote-first

Bank-grade access without bank branch networks

Mercury builds financial infrastructure for startups — which means regulators, auditors, and security-conscious customers all ask how access is controlled. Their answer: identity everywhere, network location nowhere.

Mercury — vault door built into a cloud with audit trails

The challenge

A remote-first fintech can't lean on "the office network is trusted" — there is no office network. Yet the infrastructure (production systems, databases, payment integrations) needed access controls that satisfy financial-industry scrutiny. Early on, that meant a patchwork: a VPN for some systems, cloud-specific access for others, and tribal knowledge about which tool reached what.

The switch

Mercury made OpenVLAN the single access path to production: every engineer connects through corporate SSO, every system sits behind ACLs keyed to teams, and privileged sessions are recorded. The security team's policy became actual network policy instead of a document.

The results
1

access path to audit instead of many

100%

privileged sessions recorded

0

production systems with public endpoints

The quotable part

Security reviews got shorter. When every access question has the same answer — "it's in the ACLs, here's the log" — due diligence stops being a project and becomes a report.

This case study is an illustrative example with fictional data for demonstration purposes.

Regulated? Remote? Both?