{"id":11607,"date":"2016-11-03T06:51:17","date_gmt":"2016-11-02T21:51:17","guid":{"rendered":"https:\/\/jirak.net\/wp\/alkami-technology-achieves-a-security-and-scalability-with-nginx-plus\/"},"modified":"2016-11-03T09:34:27","modified_gmt":"2016-11-03T00:34:27","slug":"alkami-technology-achieves-a-security-and-scalability-with-nginx-plus","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/alkami-technology-achieves-a-security-and-scalability-with-nginx-plus\/","title":{"rendered":"Alkami Technology Achieves \u201cA+\u201d Security and Scalability with NGINX Plus"},"content":{"rendered":"<p>Alkami Technology Achieves \u201cA+\u201d Security and Scalability with NGINX Plus<br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jirak.net\/wp\/wp-content\/uploads\/2016\/11\/111523_alkami_logo_gold_shiny.png\" width=\"483\" height=\"156\"><\/p>\n<h3><em>Providing Flexibility to Ensure a Skyrocketing User Base is Protected<\/em><\/h3>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.wp.nginx.com\/wp-content\/uploads\/2016\/09\/111523_alkami_logo_gold_shiny.png\" alt=\"Alkami Technology NGINX Plus Security and Scalability Case Study Logo\" width=\"350\" height=\"113\" class=\"aligncenter size-full wp-image-45830\" \/><br \/>\n<strong><\/p>\n<h3>Situation<\/h3>\n<p><\/strong><\/p>\n<p>In 2009, Alkami Technology set out to transform ordinary online banking into a high-value experience for both financial institutions and their end users. At the time, \u201cWeb 2.0\u201d companies like Twitter and Facebook were focusing on delivering superior user experiences, but the online banking experience was lagging behind. The team at Alkami Technology began creating a compelling user interface for online banking that would not only be friendly and intuitive, but also enrich the lives of end users.<\/p>\n<p>Beyond traditional online banking activities, <a href=\"https:\/\/www.alkamitech.com\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\" target=\"_blank\">Alkami Technology<\/a> offers features in its platform that help end users become more educated about finance, build long-term wealth, and monitor and improve their spending habits. Alkami\u2019s platform revolutionizes the mobile and online banking experience by offering a valuable end-user experience and helping financial institutions strengthen their relationship with their customers. <\/p>\n<p>Alkami initially anticipated that customers would prefer an on-premises software solution in the short term to a hosted offering. However, they quickly found that even large financial institutions were already looking ahead five to ten years and were making strategic decisions to move to hosted software solutions. Financial institutions increasingly don\u2019t want to own and manage their own data centers. In addition, the Federal Financial Institutions Examination Council (FFIEC) \u2013 the group responsible for setting regulations and standards for financial institutions \u2013 provided guidance that adopting cloud technologies was permissible. <\/p>\n<p>With the financial industry embracing cloud and software-as-a-service (SaaS), Alkami\u2019s hosted platform for online and mobile banking quickly took off. Today the company serves well over 1 million users. The Infrastructure and Security team at Alkami works behind the scenes to continue improving the scalability and security of the application architecture in order to better serve the needs of the company&#8217;s growing user base, and to ensure that financial data is well protected on all fronts.<\/p>\n<p>Alkami partners with a service provider to manage some pieces of its infrastructure, which is part of its strategic decision to focus on its core competency of building great online banking applications while a partner builds and manages the data center that hosts them. On the advice of the service provider, Alkami first used Riverbed Stingray (now Brocade vADC) appliances for load balancing. However, Alkami quickly found that Riverbed Stingray didn\u2019t have the security capabilities it needed. At the time, Riverbed Stingray didn\u2019t support <a href=\"https:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog#TLS_1.2\" target=\"_blank\">TLS 1.2<\/a>, the most recent version of the secure protocol. <\/p>\n<p>\u201cWe want to be not just on the forefront of online banking in terms of features, but also forward leaning in our security practices. Not having TLS 1.2 available in Riverbed Stingray was a deal breaker for us. We want the highest marks possible on security, and we want to be ahead of potential security issues, not react to them. Riverbed Stingray didn\u2019t take us where we needed to be from a security protocol standpoint,\u201d says Sean McElroy, VP of IT and CISO at Alkami Technology.<\/p>\n<p>Alkami then replaced Riverbed Stingray with Citrix NetScaler virtual appliances for load balancing, but they ran into the same problem again. At the time, only Citrix NetScaler hardware appliances supported TLS 1.2, not virtual appliances. In addition, the Netscaler virtual appliances could not scale to the level Alkami needed. <\/p>\n<p>\u201cIn order to get certain types of TLS encryption and the scale we needed, we found out that with Citrix NetScaler we would need to add physical appliances to our environment. But we\u2019re virtual. We\u2019re not going to go back to physical appliances at a certain scaling point. It just doesn\u2019t align with our strategy of being nimble and scalable to, at a certain threshold, have to move to a physical version of the product because a feature is not available in the virtual offering,\u201d explains McElroy.<\/p>\n<p>Alkami also found that the NetScalers didn&#8217;t allow the administrator to specify the selection order for SSL\/TLS ciphers. In initiating an SSL\/TLS connection, the web browser or app sends a list of the ciphers it supports to the server, which compares the list to its own list of supported ciphers and selects the most secure cipher that overlaps. Alkami wanted fine-grained control over cipher ordering in order to guarantee selection of the cipher that provides the strongest security for its users. <\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.wp.nginx.com\/wp-content\/uploads\/2016\/11\/Alkami-Technology-1_Banner_A-1024x228.jpg\" alt=\"Alkami Technology online banking runs on NGINX Plus\" width=\"1024\" height=\"228\" class=\"aligncenter size-large wp-image-47166\" \/><\/p>\n<p><strong><\/p>\n<h3>Solution<\/h3>\n<p><\/strong><\/p>\n<p>As an online banking platform provider responsible for protecting a growing number of users\u2019 financial details, choosing a reliable, industry-validated solution was crucial for Alkami. On its ongoing quest to enhance both security and scalability, Alkami ultimately found <a href=\"https:\/\/www.nginx.com\/products\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\">NGINX Plus<\/a>. Alkami looked at NGINX Plus not just because of its reputation for performance, but because some of the largest websites in the world have chosen it.<\/p>\n<p>\u201cWe knew that NGINX had widespread adoption for TLS termination and as a web server. And we know that large enterprises don\u2019t usually depend on a technology unless it\u2019s been validated on many different levels. With that level of industry acceptance, we worked with our managed service provider to start evaluating NGINX Plus internally in our environment,\u201d says McElroy.<\/p>\n<p>Alkami first used NGINX Plus for TLS termination in front of the Citrix NetScaler load balancers to fill the gaps in security features and give it the flexibility and control to tune the ordering of ciphers in the TLS selection process. <\/p>\n<p>NGINX Plus worked so well for TLS termination that it wasn\u2019t long before Alkami looked into using it for more than just a security layer. The Citrix NetScaler load balancers were struggling to handle the increasing traffic load as Alkami experienced organic growth \u2013 including ever larger customers \u2013 in the success of its online banking software. \u201cTo get the concurrent connection counts that we were wanting to be able to plan for, the virtual or physical Citrix Netscaler devices weren\u2019t going to be as scalable as we needed,\u201d notes McElroy.<\/p>\n<p>After verifying in a load-test environment that NGINX Plus could scale to handle the anticipated level of traffic, Alkami completely replaced the frontend Citrix NetScaler load balancers in its production environment with NGINX Plus. NGINX Plus easily handled the traffic load without any issues.<\/p>\n<p>Alkami then continued by replacing the Citrix Netscaler load balancers another layer down in its infrastructure, between the app servers and web servers. With NGINX Plus handling traffic at the frontend and between components, Alkami achieves security and scale throughout its architecture, without the limitations of the previous solutions from hardware vendors.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.wp.nginx.com\/wp-content\/uploads\/2016\/11\/CaseStudy_Alkami-1024x442.png\" alt=\"Alkami Technology products rely on NGINX Plus (image)\" width=\"1024\" height=\"442\" class=\"aligncenter size-large wp-image-47161\" \/><\/p>\n<p><strong><\/p>\n<h3>Results<\/h3>\n<p><\/strong><\/p>\n<p><strong><\/p>\n<h4>A+ Security Rating<\/h4>\n<p><\/strong><\/p>\n<p>The industry standard for determining security strength is the <a href=\"https:\/\/www.ssllabs.com\/ssltest\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\" target=\"_blank\">Qualys SSL Labs Server Test<\/a>. With NGINX Plus\u2019s security features, Alkami\u2019s customers earn an \u201cA+\u201d \u2013 the highest possible score on the test \u2013 for their online banking sites, which validates that Alkami can offer the best level of security to its customers.<\/p>\n<p>Specifically, NGINX Plus enables Alkami to easily leverage TLS 1.2, the latest and most secure approved version of the TLS protocol. In addition, with NGINX Plus Alkami can <a href=\"https:\/\/www.nginx.com\/blog\/nginx-ssl\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\">control the SSL\/TLS cipher preference order<\/a>, staying on top of rapidly evolving security trends and ensuring the strongest cipher is always selected.<\/p>\n<p>\u201cWe wanted to be using the solution that was most relevant for security best practices today, and have full control to advance as better security approaches are established. NGINX Plus gives us the flexibility and configurability to reorder ciphers and to achieve the highest level of security,\u201d explains McElroy. <\/p>\n<p><strong><\/p>\n<h4>Forward-Looking Architecture<\/h4>\n<p><\/strong><\/p>\n<p>Given Alkami\u2019s rate of growth, an architecture that works for its current user base isn\u2019t enough. It needs a forward-looking architecture that\u2019s ready for future growth as well.<\/p>\n<p>\u201cWhen we were looking at NGINX Plus, one of our requirements was to build an architecture that works for the number of users we have today, and scales out vertically and horizontally for the future. We wanted to develop that recipe once, and not have to redo it in six months time,\u201d says McElroy.<\/p>\n<p>To date, NGINX Plus has done the job, working phenomenally well as Alkami has grown.<\/p>\n<div class=\"ngx_blockquote_wrap\">\n<div class=\"ngx_blockquote\"><span class=\"left-quote\">&#8220;<\/span>Right now NGINX&nbsp;Plus is supporting well over 1 million users in our environment. That environment is going to grow 200% this year as well. Based on what we&#8217;ve seen, we feel very confident that not only can NGINX&nbsp;Plus grow and scale with us, but that we can even pack things denser. We just don\u2019t foresee it becoming a bottleneck.<span class=\"right-quote\">&#8221;<\/span><\/div>\n<div class=\"ngx_blockquote_author\">&ndash; Sean&nbsp;McElroy, VP of IT and CISO at Alkami&nbsp;Technology<\/div>\n<\/div>\n<p><strong><\/p>\n<h4>Increased Operational Visibility<\/h4>\n<p><\/strong><\/p>\n<p>One of the biggest benefits Alkami sees with NGINX Plus is the <a href=\"https:\/\/www.nginx.com\/products\/live-activity-monitoring\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\">NGINX Plus live activity monitoring dashboard<\/a> and the increased visibility it gives into the traffic being <a href=\"https:\/\/www.nginx.com\/solutions\/load-balancing\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\">load balanced<\/a>.<\/p>\n<p>\u201cOne of the key value-adds for us has been the ability to provide our production operations team with more visibility into the way that the load balancers are functioning by using the NGINX Plus dashboard. This is tremendous for us.\u201d McElroy elaborates, \u201cjust being able to show the traffic flowing, and the errors as they\u2019re happening; that heads-up display we get is invaluable and that\u2019s something that we didn\u2019t have with the other solutions.\u201d<\/p>\n<p>If an issue pops up with the application or infrastructure, it&#8217;s the operations team that identifies the root cause and solves it. With the real-time load and performance metrics on the NGINX Plus Dashboard, the team at Alkami can troubleshoot issues faster than ever before.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.wp.nginx.com\/wp-content\/uploads\/2016\/05\/dashboard-nginx-plus-r9-1024x464.png\" alt=\"The NGINX Plus dashboard provides detailed statistics for monitoring and managing your infrastructure\" width=\"1024\" height=\"464\" class=\"aligncenter size-large wp-image-33752\" \/><\/p>\n<p><strong><\/p>\n<h4>Straightforward Deployment and Increased Automation<\/h4>\n<p><\/strong><\/p>\n<p>After validating NGINX Plus in its load testing environment to make sure it could handle its traffic loads, Alkami found the actual deployment process to be simple and straightforward. <\/p>\n<p>McElroy&#8217;s team was able to implement NGINX Plus quickly in its environment in part due to  strong documentation and <a href=\"https:\/\/www.nginx.com\/blog\/nginx-wins-silver-stevie-award-for-outstanding-customer-support\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\">award-winning support<\/a>. When asked whether his staff needed to contact NGINX Plus\u2019s dedicated support team, McElroy says, \u201cWe had a few clarifying questions but it was really a very straightforward implementation. The documentation is great, and so is the support from NGINX.\u201d<\/p>\n<p>In addition, Alkami\u2019s deployment process leverages the <a href=\"https:\/\/www.nginx.com\/blog\/3-ways-to-automate-nginx-nginx-plus\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\">automation capabilities of NGINX Plus<\/a>. Whereas Alkami\u2019s previous load balancers had a GUI interface that required manual configuration, NGINX Plus\u2019s command line interface enables Alkami\u2019s engineers to easily script the deployment process and automate configuration.<\/p>\n<p>&#8220;The fact we can do scripted deployments of configuration files with NGINX Plus is great. It\u2019s very straightforward, it\u2019s easy to manage, and it has simplified our application deployment process,&#8221; McElroy explains. &#8220;As we further automate, knowing that NGINX Plus will be able to support our automation efforts is awesome.&#8221;<\/p>\n<p><strong><\/p>\n<h3>About Alkami Technology<\/h3>\n<p><\/strong><\/p>\n<p>Based in Plano, Texas, Alkami Technology, Inc. provides online and mobile banking solutions to credit unions and banks. The company\u2019s flagship product, the ORB Platform, offers security, flexibility, extensibility, and a superior architecture for the future of digital banking. With its modern interface, intelligent content-delivery system, and customizable feature set, the ORB Platform is the ultimate digital banking solution for financial institutions. Alkami provides the ORB Platform as a SaaS solution. For more information about Alkami, please visit <a href=\"https:\/\/www.alkamitech.com\/?utm_source=alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus&amp;utm_medium=blog\" target=\"_blank\">www.alkamitech.com<\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.nginx.com\/blog\/alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus\/\">Alkami Technology Achieves \u201cA+\u201d Security and Scalability with NGINX Plus<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.nginx.com\">NGINX<\/a>.<\/p>\n<p>Source: <a href=\"https:\/\/www.nginx.com\/blog\/alkami-technology-achieves-a-plus-security-and-scalability-with-nginx-plus\/\" target=\"_blank\">Alkami Technology Achieves \u201cA+\u201d Security and Scalability with NGINX Plus<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>Alkami Technology Achieves \u201cA+\u201d Security and Scalability with NGINX Plus Providing Flexibility to Ensure a Skyrocketing User Base is Protected &nbsp; Situation In 2009, Alkami Technology set out to transform ordinary online banking into a high-value experience for both financial institutions and their end users. At the time, \u201cWeb 2.0\u201d companies like Twitter and Facebook were focusing on delivering superior user experiences, but the online banking experience was lagging behind. The team at Alkami Technology began creating a compelling user interface for online banking that would not only be friendly and intuitive, but also enrich the lives of end users. Beyond traditional online banking activities, Alkami Technology offers features in its platform that help end users become more educated about finance, build long-term wealth, and monitor and improve their spending habits. Alkami\u2019s platform revolutionizes the mobile and online banking experience <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/alkami-technology-achieves-a-security-and-scalability-with-nginx-plus\/\" title=\"Alkami Technology Achieves \u201cA+\u201d Security and Scalability with NGINX Plus\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":11608,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[169],"tags":[652],"class_list":["post-11607","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-nginx"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/11607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=11607"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/11607\/revisions"}],"predecessor-version":[{"id":11609,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/11607\/revisions\/11609"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media\/11608"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=11607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=11607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=11607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}