
Exness is one of the world’s largest trading technology companies, serving global financial markets with high-performance trading infrastructure, data-driven analytics, and proprietary algorithms. As a regulated financial services provider, Exness treats security as a core business priority — foundational to protecting client trust, platform reliability, and compliance with standards such as PCI DSS, SOC 2, and ISO 27001 certifications. With rapid expansion into new regions, the company has doubled its infrastructure footprint in recent years and opened new data centers to support increasingly low-latency trading needs. To support this growth and maintain the highest security posture, Exness undertook a multi-year initiative to enhance and optimize its entire infrastructure security model. Teleport became a critical pillar in this transformation, enabling unified identity and secure access to Kubernetes, databases, hosts, and sensitive internal applications across a large, globally distributed environment.
*Exness does not offer services to residents of certain jurisdictions including the U.S., Canada, Iran, North Korea, Europe, the United Kingdom, Russia, Belarus and others.
As Exness expanded, so did the complexity of its infrastructure:
These challenges underscored the need for an Infrastructure-as-Code-compatible, Kubernetes-native solution. Exness required full automation, GitOps readiness, SSO support, and machine identity — all in one platform. Teleport was the only evaluated solution that met every requirement.
Before Teleport, Exness faced several critical barriers:
Exness began with Teleport Community Edition, validating the platform in full production conditions using the open source license before shifting to the Enterprise Edition. Teleport was deployed via Helm and Terraform across two high availability (HA) data centers, backed by Postgres and fronted by active-active load balancers.
Teleport became the unified access layer for:
Teleport is a flexible solution and one that provides a solid foundation for building unified access-control, thanks to its IaC- and automation-native design.
Team Based Just-In-Time (JIT) Access
The biggest improvement was the creation of team-approved JIT access, eliminating permanent write privileges for developers and shifting approvals from a bottlenecked security team to the team closest to the workload.
This dramatically reduced operational load, improved response times, and tightened security.
Teleport eliminated hundreds of manual approvals every week. Security and DB teams finally regained their time because access became peer-approved instead of bottlenecked.
Removal of All Permanent Database Credentials
Using Teleport Database Access, Exness eliminated all local DB credentials. Development teams now execute their own database write operations under Teleport-mediated, JIT-approved sessions, freeing the DB team from dozens of weekly manual tasks.
Unified Access Provisioning
Teleport became the first security-owned, unified platform to grant access across Kubernetes, servers and databases — removing the need to orchestrate changes among other internal departments.
More Secure CI/CD Push Model
Teleport Machine ID replaced permanent Kubernetes tokens used in GitLab pipelines, enabling secure short-lived credentials for push-based deployment workflows.
Elimination of Shadow Access Paths
Security now enforces Teleport as the exclusive access method for several types of infrastructure assets, with SOC alerts triggered whenever bypass attempts occur. This significantly elevated auditability and reduced risks.
Stronger Compliance Posture
Exness continues to prove its compliance with global regulatory requirements such as PCI DSS, SOC 2, and ISO 27001 certifications, with Teleport providing the fine-grained auditability, JIT controls, and identity-driven access required for regulated FinTech environments.
Exness plans to deepen its Teleport deployment by:
Teleport remains a foundational component of Exness’ long-term infrastructure security roadmap.
Before Teleport: Manual workflows, fragmented access tooling, permanent credentials, shadow access paths, operational bottlenecks.
After Teleport: Unified, identity-driven access across critical assets; team-based JIT; reduced operational load; stronger security posture; improved auditability.
Impact: Faster incident response, elimination of credential sprawl, more secure CI/CD pipelines, and a scalable foundation for rapid global growth.
Looking Ahead: Continued integration of assets, improved logic of K8s “deny” rules andmanaged sessions, and licensing optimization.
HQ
Industry