Skip to content
🌙 ☀️
AWS Case Study
NBFC / FinTech Cloud Operations RBI-Regulated

Hindon Mercantile:
Tested Recovery &
Encryption by Policy

An RBI-regulated lending platform moves from undefined recovery to policy-enforced resilience — where encryption is guaranteed at resource creation and recovery is proven by testing, not assumed.

4hr
Recovery Time Objective
15min
Recovery Point Objective
Multi-AZ
Automatic Failover
Hindon Mercantile — Resilience Dashboard
Encryption
Enforced
↑ SCP at creation
Recovery
Tested
↑ Isolated restore
Data-Tier Failover
Automatic
↑ RDS Multi-AZ
Routing
Health-Checked
↑ Route 53 + ALB
RTO
4 Hours
↑ Validated
RPO
15 Minutes
↑ Defined
WAF
Edge Protection
↑ CloudFront
01
AWS Cloud Operations Delivery
Establishing Tested Recovery and Enforcing Encryption by Policy for an RBI-Regulated Lender
About Hindon Mercantile Limited
Hindon Mercantile Limited is an India-based non-banking financial company operating a digital lending and loan origination platform under Reserve Bank of India regulation. Both service availability and demonstrable data protection carry regulatory consequence.
The Challenge

Undefined recovery and human-dependent encryption in a regulated lending platform

Cloud operations challenge — no structured failover and undefined recovery objectives
🔌
No Structured Failover
The platform had no automatic failover for its data tier, so a component failure implied service interruption with no defined recovery path.
🎯
Undefined Recovery Objectives
Recovery time and recovery point expectations had not been established, so recovery capability could neither be designed against a target nor demonstrated to a regulator.
Encryption Dependent on Human Action
A database instance was created without encryption at rest and required manual remediation, revealing that a regulatory obligation depended on an engineer remembering a setting.
Solutions Provided

Policy-enforced encryption, tested recovery, and availability by design

🔐
Encryption Enforced at Creation
Introduced an AWS Organizations service control policy denying creation of in-scope resources where the required encryption condition is not met, so the obligation is guaranteed by policy rather than by individual diligence.
🔄
Defined and Tested Recovery
Established a recovery time objective of four hours and a recovery point objective of fifteen minutes, and validated recovery by restoring into an isolated environment configured without an internet gateway, peering connection or shared routing.
🗄️
Automatic Data-Tier Failover
Deployed Amazon RDS Multi-Availability-Zone with synchronous replication and automatic failover, so the loss of an Availability Zone is absorbed rather than becoming an outage.
🛡️
Edge Protection & Health-Checked Routing
Implemented Amazon CloudFront with AWS WAF applied at the edge and request logging to Amazon S3, an Application Load Balancer withdrawing unhealthy targets automatically, and Amazon Route 53 health-checked DNS.
🔧
Controlled Change and Patching
Applied AWS Systems Manager for patch execution, with changes raised as change requests carrying impact analysis and executed within agreed maintenance windows.
Policy-enforced resilience — RDS Multi-AZ failover and tested recovery on AWS
Result Outcome

A class of non-compliance eliminated and recovery proven — not assumed

Cloud operations results — policy-enforced encryption and proven recovery for regulated lender
🚫
A Class of Non-Compliance Eliminated
An unencrypted in-scope resource can no longer be created, so the obligation no longer depends on remediation after the fact.
Recovery Proven, Not Assumed
Recovery objectives are validated by isolated restore testing, so the recovery position is evidence rather than intention.
Availability by Design
Zone-level failure is handled by automatic failover and unhealthy targets are withdrawn without operator action.
🌐
Governance Covering Future Resources
Because the control acts at creation, it governs resources not yet provisioned without per-resource effort.
🔐
By Policy
Encryption Enforced
Unencrypted in-scope resources can no longer be created — no post-hoc remediation
Tested
Recovery Position
Validated by isolated restore — evidence rather than intention
Automatic
Zone Failover
AZ loss absorbed, unhealthy targets withdrawn without operator action
🌐
Future
Resources Governed
Control acts at creation — no per-resource effort for new provisioning
Success Metrics

Measurable resilience improvements across recovery and governance

Recovery Objectives
None
4hr RTO / 15min RPO
Recovery time and point objectives defined where none previously existed
Recovery Validation
Untested
Isolated Restore
Validated by restoration into an isolated environment with no route to production
Encryption Governance
Manual
Service Control Policy
SCP denies creation of in-scope resources without the required encryption condition
Database Availability
Single-AZ
Multi-AZ Failover
Multi-Availability-Zone deployment with automatic failover and health-checked routing
Before
No automatic failover mechanism for the data tier
No recovery objectives defined, and recovery capability untested
Encryption at rest dependent on an engineer enabling it at creation
A non-compliant resource required manual remediation after it already existed
Changes applied without a structured approval path or agreed window
After
Multi-Availability-Zone deployment with synchronous replication and automatic failover
RTO of 4 hours and RPO of 15 minutes defined and validated by isolated restore testing
Creation of in-scope resources without encryption denied by service control policy
CloudFront with AWS WAF at the edge, request logging and health-checked routing
Changes raised, impact-assessed, approved and executed in agreed maintenance windows
The most durable outcome was not a service deployed but a class of error eliminated: encryption enforcement now applies at resource creation, so the regulatory obligation is met by the platform rather than by the person configuring it.
Technology Stack

AWS Services Deployed

🏛️
AWS Organizations SCP
Encryption Enforcement
🗄️
Amazon RDS Multi-AZ
Automatic Failover
☁️
Amazon CloudFront
Edge Distribution
🛡️
AWS WAF
Edge Protection
⚖️
Application Load Balancer
Unhealthy Target Withdrawal
🌐
Amazon Route 53
Health-Checked DNS
🪣
Amazon S3
WAF Request Logging
🔧
AWS Systems Manager
Controlled Patching
🔐
AWS KMS
Encryption at Rest
🔄
Synchronous Replication
Zero-Loss Standby
🧪
Isolated Restore Env
Recovery Validation
📋
Change Management
Impact-Assessed Windows
Accepting New Enterprise Clients

Ready to Enforce Resilience
by Policy?

Book a complimentary cloud operations review. Our AWS-certified engineers will assess your recovery and encryption governance posture and deliver a tailored resilience roadmap — no commitment required.

No commitment required
Response within 24hrs
AWS Advanced Partner