Secure by Design: How Rapyd Gives Engineering Speed While Raising Its Cloud Defense Baseline
How Rapyd builds secure-by-design cloud environments that let engineering move fast on innovation and AI while security raises its enforced defense baseline, using preventive guardrails on native AWS controls.
Rapyd, a global fintech-as-a-service platform, processes payments across dozens of countries on a regulated, multi-account AWS environment. Like most fast-moving fintechs, it innovates constantly. Engineering ships quickly, adopts new cloud services, and increasingly builds with AI, which means new resources, identities, and attack paths appear all the time. The security team’s job is to keep that pace safe without becoming the thing that slows it down.
This is the story of how Rapyd moved from detecting and remediating the same cloud risks over and over to building secure-by-design cloud environments: preventive guardrails enforced as native AWS controls that give engineering safe speed and give security a stronger, enforced defense baseline. Here is what that looked like in practice.
The prevention gap that slows fast-moving cloud teams
Rapyd already had strong visibility. A mature CNAPP program built on Wiz surfaced issues quickly and reliably. The problem was what happened next. The same classes of findings kept coming back: public network exposure through internet gateways, over-broad IAM permissions, and unencrypted data. Each one meant another remediation cycle, another ticket, and another conversation with an engineering team.
Detection operates downstream of the event. It tells you what is wrong, but it does not stop the next risky change from reaching production. For recurring issues, the fix is not faster triage. It is a control that makes the risky pattern impossible to recreate in the first place. In a regulated payments environment, that distinction is the difference between security that enables the business and security that becomes a bottleneck.
What secure by design means for a regulated cloud environment
Secure by design means preventive controls are built into the environment as safe defaults, so risky configurations cannot be created in the first place. Instead of detecting and remediating issues after they appear, native cloud guardrails such as AWS Service Control Policies (SCPs) and Resource Control Policies (RCPs) block risky actions before they execute.
The advantage for a fast-moving team is compounding. When safe defaults are enforced at the organization level, every new account, workload, and AI service inherits them automatically. Engineers do not have to remember a checklist, and security does not have to review every change by hand. The guardrail does the work.
How Rapyd turned Wiz findings into enforced guardrails
With Blast’s Preemptive Cloud Defense Platform, Rapyd turned its Wiz backlog into a prioritized prevention program. Blast connected agentlessly to Rapyd’s AWS Organization through a read-only, metadata-only role. Rather than adding another detection layer, it operationalizes the native controls AWS already offers and turns them into safe defaults engineering can build on:
- Model. Map cloud behavior, existing controls, and blast radius across the AWS Organization.
- Plan. Prioritize guardrails against Rapyd’s actual Wiz findings and its innovation and AI roadmap, not boilerplate policy.
- Simulate. Test the business impact of every SCP and RCP against the real environment before enforcement, so engineering velocity is never surprised.
- Enforce. Apply native AWS controls, including VPC internet gateway restrictions, IAM hardening, and KMS-backed encryption, at the organization and OU level, with no agents and no middleware.
- Monitor. Track coverage and drift across organization, OU, and account, keeping the secure-by-design posture intact as the environment changes.
A Security Control Effectiveness view tracked coverage across organization, OU, and account, while Accepted-Risk management handled auditable exceptions and a Jira integration kept enforcement inside the developer workflow. The simulation step was the unlock: it answered “will this break anything?” with evidence instead of guesswork, which is what earns trust for enforcement in a zero-tolerance payments environment.
My team can now categorically solve complete classes of issues, rather than just fixing the same kind of problems over and over, stopping threats before they turn into incidents.
Nir Rothenberg, CISO, Rapyd
Speed for engineering, stronger defense for security
With guardrails enforced as safe defaults, Rapyd’s engineers move faster. Whole classes of misconfiguration are prevented automatically, so there are fewer security tickets, fewer blocked deployments, and less back-and-forth on the same recurring issues. Security, meanwhile, raised its defense baseline across the AWS Organization, containing the highest blast-radius risks like public network exposure and over-broad identity paths, with auditable Accepted-Risk handling for the exceptions a regulated environment always needs.
Because Blast enforces through Rapyd’s existing AWS-native controls, there are no agents, sensors, or added runtime to operate, and the simulation-first rollout delivered enforcement with zero business disruption. Rapyd procures Blast through the AWS Marketplace, drawing down against its existing AWS commitment.
Prevention that enables innovation and AI
The result is a secure-by-design cloud where prevention enables innovation rather than blocking it. As Rapyd adopts AI and new cloud services, Blast maps preventive guardrails to that roadmap and enforces them as native controls, so new resources, identities, and attack paths inherit safe defaults from the start. In an AI-driven era, that preventive layer is no longer optional. It is foundational to shipping fast without expanding risk.
Frequently asked questions
What does secure by design mean for a cloud environment?
Secure by design means preventive controls are built into the environment as safe defaults, so risky configurations cannot be created in the first place. Instead of detecting and remediating issues after they appear, native cloud guardrails such as AWS SCPs and RCPs make whole classes of risk impossible to recreate.
How do preventive guardrails give engineering more speed?
When safe defaults are enforced automatically, developers can ship on new cloud and AI services without waiting on manual security review, and without the friction of repeated remediation tickets. Prevention removes the back-and-forth, so security accelerates delivery instead of slowing it.
How does prevention raise a security team’s defense level without blocking developers?
Blast simulates every control against real environment behavior before enforcing it, then enforces native AWS controls at the organization and OU level. Rapyd’s team raised its enforced baseline and contained high blast-radius risks while engineering kept moving, with Accepted-Risk management for auditable exceptions.
How does Blast help secure AI and new cloud services?
As Rapyd adopts AI and new cloud services, Blast maps preventive guardrails to that roadmap and enforces them as native controls, so new resources, identities, and attack paths inherit safe defaults automatically.
See it in your own environment. Learn how the Preemptive Cloud Defense Platform enforces preventive guardrails on your native AWS controls, or get a demo.