top of page

SSC-Cleared, 5-Minute Onboarding: Digital App Rebuild for a Tier-1 Vietnamese Fund Manager

Updated: Aug 20


Built for Scrutiny. Built for Scale.


A tier one Vietnamese fund manager asked us to fix risk exposure while lifting customer experience. We delivered a new Flutter app, microservices on Azure, and end to end eKYC and AML with immutable audit trails. Onboarding time dropped below five minutes, MAU grew more than seventy percent, and an independent pen test found no critical issues.


Project Snapshot


Client: Leading Vietnamese Fund Manager

Scope: Mobile app rebuild · eKYC/AML · Pension portals · Brand system · Cloud migration

Duration: 12 months

Value: AUD $1.5M

Outcome: SSC audit cleared on first pass · Onboarding <5 minutes · 4.8★ app rating



The Challenge


  • Modernise digital channels and fix compliance exposure under time pressure.

  • Legacy app at risk of app store removal

  • Manual KYC, fragmented AML monitoring, incomplete audit trails

  • Pension platform missing tax and vesting logic and self service

  • Need to scale without downtime or regulatory findings



What we delivered


  • Rebuilt Mobile and Brand System: 200+ screens in VN/EN with an accessible design system; crash free sessions 99.95% post launch.

  • Next Gen Stack on Azure: Flutter front end; microservices (.NET and Node) on AKS and App Service; Azure SQL, Blob, Redis, Key Vault; WAF with OWASP CRS.

  • eKYC and AML at Scale: OCR, NFC CCCD chip read, liveness and face match; real time PEP and sanctions screening; immutable case logs; 98% first pass verification.

  • Pension Portals: Employer and employee self service with tax rules, vesting schedules, payroll import, and configurable statements.

  • DevSecOps and IA: Terraform IaC, CI and CD in Azure DevOps, SAST and DAST gates, blue green deployments; 2 week sprints with a release train.


Governance and Assurance


  • Compliance mapping to Vietnam SSC requirements with controls aligned to ISO 27001 and NIST CSF.

  • Independent pen test CREST aligned with zero critical findings prior to go live.

  • Observability: App Insights and Log Analytics; SLOs at p95 latency <350 ms and availability ≥99.98% 90 day verified.

  • Change control: Executive steering, RACI, risk register, and staged cutovers with rollback plans.


Business Impact


  • Faster growth: +72% MAU, app rating to 4.8★, onboarding time <5 minutes 86% reduction.

  • Audit ready: SSC audit cleared on first submission; complete audit trails; encryption at rest AES 256, in transit TLS 1.3.

  • Zero downtime: No Sev 1 incidents during migration; release cadence faster.

  • Efficiency: Manual KYC workload 70% reduction; support tickets 30% reduction within 90 days.

“Bellica turned a regulatory risk into an advantage. Faster onboarding, a stronger control environment, and a product our clients love.” — Chief Digital Officer

Tech Snapshot


Flutter Dart · .NET and Node microservices · Azure AKS and App Service · Azure SQL · Blob · Redis · Azure AD B2C · Key Vault · App Gateway WAF · Terraform · Azure DevOps and Jira


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.

Bellica is your trusted partner for integrated IT, cloud, cybersecurity, and industrial automation — all under one roof. We’re here to help you innovate, protect, and grow with confidence.

© 2025 Bellica.
All rights reserved.

Got a project in mind? Start the conversation.

bottom of page