The Client
Flottando is a Swiss-based technology company that provides an AI-powered fleet management platform designed to simplify and automate mobility operations for modern businesses. Their software serves as an all-in-one operating system for fleets, replacing manual spreadsheets and fragmented tools with real-time insights into vehicle costs, fuel consumption, maintenance, and compliance.
By integrating live data from cars, fuel cards, and invoices into an intuitive dashboard, Flottando helps procurement, finance, and operations teams work together seamlessly to reduce repair costs by nearly 30% and cut the time spent on routine administrative tasks.
- Industry:Technology, Information and Internet
- Company Size:11-50
- Country:Switzerland
Great working with Cloudvisor, very structural and knowledge cloud expert. They helped us setting up the base infrastructure with IaC (infrastructure as code) and automated checks to keep continues checking for security issues. This is helped Flottando to easier scale our applications in a safe way and prepare the road for security certifications.
Challenges
Environmental overlap. The company’s foundational AWS setup ran production and development workloads within a single account, needing dedicated environment separation to mitigate operational risks as operations expanded.
Networking constraints. The architecture required transitioning from a single default VPC to a professional multi-tier network with public, private, and isolated data subnets.
Governance & scaling gaps. Rapid growth necessitated establishing centralized management via AWS Organizations to streamline cross-account governance, billing, and security policies.
Security visibility. The team sought to replace manual compliance checks with automated, nightly configuration scans and continuous threat monitoring.
Alerting fragmentation. The platform needed a unified monitoring strategy to centralize alerts for system performance, data spikes, and budget thresholds directly to Slack and email.
As Flottando prepared for enterprise expansion, upgrading this foundational setup was essential to support increasing platform usage, maintain strict security isolation, and establish a scalable operational baseline.
Solutions
Cloudvisor established an automated AWS foundation based on the Landing Zone model, using Terraform for full reproducibility and infrastructure as code.
AWS Organizations & Multi-Account Strategy
Created a centralized AWS Organization with dedicated accounts for Production, Test/Development, and a standalone Security hub to ensure complete environment isolation.
Multi-Tier VPC Architecture
Deployed a multi-tier VPC featuring dedicated public, private, and database subnets across multiple Availability Zones to strictly isolate sensitive resources.
Modular Infrastructure as Code
Built the networking layer using dynamic Terraform scripts, allowing easy expansion from a single Availability Zone in Development to a high-availability multi-AZ setup in Production.
Centralized Governance & Security Monitoring
Implemented a governance layer within the Security Account utilizing AWS GuardDuty, AWS Security Hub, and AWS Config rules for automated compliance and resource scanning.
Unified Observability & Budget Control
Configured Grafana-based dashboards and budget alarms integrated directly with Slack and email for real-time visibility into system health, data spikes, and spending.
Isolated Traffic & Secure Gateways
Configured NAT Gateways for secure outbound traffic and an S3 VPC Gateway to keep internal data transfers off the public internet.
AWS Services Used
- AWS Organizations
- AWS Control Tower / Landing Zone
- Amazon VPC
- AWS GuardDuty
- AWS Security Hub
- AWS Config
- AWS Budget Alarms
- Amazon S3 (VPC Gateway)
- NAT Gateway
- Terraform
Results
The new infrastructure provides Flottando with a production-ready, highly secure environment built to scale smoothly as their fleet management platform expands globally.
- Isolated Multi-Account StructureEliminated environmental risk by isolating Production and Dev/Test into separate AWS accounts
- Real-Time Cost ControlProtected VC budget ($25K in credits) through real-time Slack and email budget alerts
- Automated Infrastructure DeploymentBuilt for seamless scaling using dynamic, multi-AZ Terraform templates.
- Secure Network ArchitectureProfessionalized networking stack with isolated private subnets and secure VPC gateways.
- Continuous Governance & ScanningAutomated security compliance using nightly AWS Config scans for misconfigurations.
- Accelerated Product DevelopmentBoosted engineering efficiency by delivering a standardized base, letting their team focus on core software.
