Appreciate - Migrating and running a regulated global investing platform on AWS
Managed Services
Appreciate - Migrating and running a regulated global investing platform on AWS
Appreciate is a Mumbai-headquartered fintech that gives Indian investors access to global markets. Its platform lets users buy US stocks, ETFs, mutual funds and digital gold from as little as ₹1, with automated SIPs and AI-driven recommendations, and it has grown to serve a base of more than 500,000 users. The company operates through Appreciate Broking IFSC Private Limited, an IFSCA-registered broker based in GIFT City, and works with regulated partners including DriveWealth, ViewTrade and YES Securities. It was the first fintech to enable mutual fund investments on the ONDC network. Its published security commitments include AES-256 encryption, gold-standard KYC, round-the-clock activity monitoring and AI-enabled fraud flagging. This is a workload where availability, data protection and audit evidence are not features — they are the licence to operate.
Case Overview
Project Snapshot
Appreciate is a Mumbai-headquartered fintech that gives Indian investors access to global markets. Its platform lets users buy US stocks, ETFs, mutual funds and digital gold from as little as ₹1, with automated SIPs and AI-driven recommendations, and it has grown to serve a base of more than 500,000 users.
The company operates through Appreciate Broking IFSC Private Limited, an IFSCA-registered broker based in GIFT City, and works with regulated partners including DriveWealth, ViewTrade and YES Securities. It was the first fintech to enable mutual fund investments on the ONDC network. Its published security commitments include AES-256 encryption, gold-standard KYC, round-the-clock activity monitoring and AI-enabled fraud flagging.
This is a workload where availability, data protection and audit evidence are not features — they are the licence to operate.
Understanding the Business Challenges
Every successful solution starts with understanding the problems, constraints and opportunities that shaped the project.
Appreciate approached Capspedia with a combined problem: an infrastructure estate that needed to be re-platformed for growth, and no in-house capacity to run it once it was.
A platform outgrowing its foundations
The environment had grown organically alongside the product. Infrastructure had been provisioned manually, environments drifted from one another, and there was no reproducible path from a clean account to a working platform. Scaling for user growth meant scaling the manual effort with it.
Peak load lands overnight
US market hours put the platform's busiest window in the Indian evening and overnight — precisely when an in-house team is least available. Trading, remittance and portfolio refresh activity all concentrate in that window.
A regulated environment with real audit exposure
As an IFSCA-registered broker holding KYC data and moving customer funds, Appreciate faces continuous scrutiny from regulators, partners and enterprise customers. Security posture, access governance and audit evidence had to be demonstrable on request, not reconstructed under pressure.
Cost growing faster than usage
Cloud spend was rising with every feature launch, with no tagging discipline, no view of cost by product line, and no commitment strategy against predictable baseline load.
Engineering time going the wrong way
The engineering team's mandate was new asset classes and features. Increasingly, its time was going to infrastructure work, incident response and audit paperwork instead.
Facing Similar Business Challenges?
Our experts can help you plan, build and deliver the right technology solution for your business.
A Practical Solution Built For Long-Term Success
We transformed the identified challenges into a practical, scalable and sustainable technology solution designed around real business needs.
Capspedia took the engagement in two phases: a migration and modernization programme, followed by ongoing managed operations under the same team — so the people who designed the environment remain accountable for how it runs.
3.1 Migration and modernization
- Discovery and dependency mapping across the existing estate, with a wave plan sequenced by risk and business criticality.
- Landing zone build on AWS with multi-account separation for production, non-production and shared services, guardrails and centralised logging in place before workloads landed.
- Full rebuild of infrastructure as code in Terraform — every environment now reproducible from a repository, with drift detection running continuously.
- Modernization where it paid for itself: containerised workloads, managed databases in place of self-managed instances, and managed services for queuing and caching.
- Wave-by-wave cutover with documented rollback criteria and hypercare following each wave.
3.2 DevOps and platform engineering
- CI/CD pipelines rebuilt with automated testing gates, artefact promotion and controlled production release.
- Golden image and container base pipelines, so security patching flows automatically into every new deployment.
- Policy-as-code guardrails preventing non-compliant infrastructure from reaching production.
- Ongoing platform operations: cluster upgrades, capacity management and developer self-service tooling.
3.3 Security and compliance
- Continuous cloud security posture management with automated detection and remediation of misconfiguration and drift.
- Identity governance: least-privilege IAM design, privileged access controls and periodic entitlement recertification.
- Encryption and key lifecycle management, secrets management, and centralised audit trail retention.
- Vulnerability management across workloads and container images, with remediation SLAs by severity.
- Standing evidence packs maintained for partner and regulator security reviews — assembled continuously rather than on demand.
3.4 Backup and data protection
- Policy-driven backup with centralised policy management across all accounts and regions.
- Retention schedules mapped per workload class to the company's regulatory record-keeping obligations.
- Immutable, logically isolated backup copies to defend against ransomware and accidental deletion.
- Scheduled sample restore testing, with results published in the monthly service report.
3.5 Disaster recovery and business continuity
- Business impact analysis to set recovery objectives per workload tier, agreed with the business rather than assumed by IT.
- Warm standby architecture for the customer-facing trading path; backup-and-restore for lower tiers.
- Documented recovery runbooks, maintained as the environment changes.
- Scheduled DR drills with measured results against stated RTO and RPO, and corrective actions tracked for any gap.
3.6 Data platform operations
- Managed operation of the data pipelines feeding portfolio analytics and the AI recommendations engine.
- Pipeline monitoring with SLA management on scheduled and streaming jobs, and alerting on freshness and volume anomalies.
- Warehouse performance and cost tuning, and access governance across the data estate.
3.7 Cost optimization (FinOps)
- Tagging taxonomy and account structure enabling cost attribution by product line and environment.
- Rightsizing of compute, storage and database resources against observed utilisation.
- Commitment portfolio management across Savings Plans and Reserved Instances, with coverage and utilisation targets.
- Storage lifecycle policies and elimination of idle and orphaned resources.
- Cost anomaly detection with alerting, and monthly reporting against the agreed baseline.
Tools & Technologies Behind This Project
A carefully selected technology stack was used to build a secure, scalable and high-performing solution aligned with the project's technical and business requirements.
AWS Services Used
The list below reflects a typical architecture for this workload profile and must be replaced with the actual service inventory before publication.
| Category | Services |
| Compute & containers | Amazon EC2Amazon ECS / Amazon EKSAWS Lambda |
| Data | Amazon RDSAmazon AuroraAmazon DynamoDBAmazon ElastiCache |
| Storage & delivery | Amazon S3Amazon CloudFront |
| Networking | Amazon VPCAWS Transit GatewayElastic Load BalancingAmazon Route 53 |
| Security | AWS IAM Identity CenterAWS KMSAWS Secrets ManagerAmazon GuardDutyAWS Security HubAmazon InspectorAWS WAF |
| Operations | Amazon CloudWatchAWS Systems ManagerAWS ConfigAWS CloudTrail |
| Resilience | AWS BackupAWS Elastic Disaster Recovery |
| Data platform | AWS GlueAmazon AthenaAmazon Redshift |
| Governance & cost | AWS OrganizationsAWS Control TowerAWS Cost ExplorerAWS Budgets |
How We Successfully Executed The Project
A structured implementation approach helped turn the solution design into a reliable, production-ready system while keeping delivery focused and controlled.
Service Used -
- Migration & modernization
- Cost optimization (FinOps)
- Backup & data protection
- Disaster recovery & BC
- Security & compliance
- DevOps & platform engg
- Data platform operations