
How an Independent Paging Carrier Migrated Critical Paging Infrastructure to AWS Customers in Under Six Weeks, with Zero Downtime for 45,000+ customers
Read Case Study

Modernizing a payment platform’s legacy 1,111-asset VMware Tanzu environment to a cloud-native, PCI-scoped AWS architecture—eliminating $1M in annual licensing fees while boosting deployment speed and service reliability.
Key Benefits
Industry
Financial Services/Payments
Segment
Enterprise
Location
United States
Services
Cloud Migration
DevOps
Application Modernization
VMware Exit
Database Modernization
FinOps
With aging infrastructure across multiple data centers running its flagship payment product, processing millions of payments per day, the company faced rapidly rising licensing and operational costs on a VMware Tanzu and Oracle stack.
Key challenges included:
A hard end-of-2026 Broadcom contract cliff: the entire VMware Tanzu footprint had to migrate or incur a major license renewal.
Large, growing VMware Tanzu (VMware Kubernetes) spend that the company wanted to eliminate.
A highly regulated, PCI DSS compliant payment application with strict data center and data-security practices that any new platform had to preserve.
The provider wanted to pivot to a standard, broadly supported cloud platform, eliminate licensing fees, and increase its ability to scale and innovate.
The customer's biller payment platform operates inside a PCI DSS compliance boundary. UTurn replatformed and modernized the platform from VMware Tanzu in corporate data centers onto AWS, a true modernization rather than a lift-and-shift of virtual machines. The landing zone was defined entirely in Terraform across more than twenty AWS accounts, with account and network design built around PCI segmentation rather than a generic reference architecture.
To enforce PCI separation, UTurn split production and non-production tiers across dedicated accounts and AWS Cloud WAN segments, steering all north-south and cross-segment traffic through Palo Alto VM-Series inspection via Cloud WAN service insertion. Workload VPCs run “dark,” with no direct internet egress; traffic exits through inspection and AWS Direct Connect into the customer's corporate network. Amazon Route 53 Resolver with selective forwarding modernized hybrid DNS while keeping Active Directory authoritative for corporate domains.
The data tier moved to managed services in PCI-scoped subnets, with managed patching, backups, and encryption: Amazon Aurora PostgreSQL, Amazon RDS for SQL Server, Amazon RDS for Oracle, Amazon ElastiCache for Redis, and Amazon EFS for shared file storage. The container platform runs on Amazon EKS with Calico networking for IP conservation and PCI segmentation, fed by an Amazon ECR artifact pipeline and scanned by Amazon Inspector. Hardened Amazon Linux 2023 images built with Packer replaced a large legacy Ansible estate.
Some application tiers run temporarily on Amazon EC2 as a migration bridge while containerization on EKS completes, but the infrastructure beneath is a greenfield, PCI-scoped, fully automated build. The result reduces the company’s dependence on corporate data centers, removes VMware and Broadcom licensing exposure for the container and data tiers, and gives the platform team operational independence over its own delivery pipeline.
UTurn modernized the company's payment platform into a secure, cloud-native AWS platform, improving automation, security, and operational independence.

Eliminated $1M in annual Broadcom (VMware) licensing.
Reduced the platform’s cloud run rate by $800K per year.
Modernized 1,111 VMware Tanzu assets to Amazon EKS.
Migrated a 25TB on-premises Oracle database to Amazon RDS for Oracle.
Secured $2.3M in AWS funding for the effort.
Increased build and deployment speed by 80%.
Completed the migration with zero downtime.
Networking: AWS Cloud WAN, AWS Direct Connect, Palo Alto VM-Series, AWS Gateway Load Balancer, Amazon Route 53 Resolver, Amazon Route 53 private hosted zones, VPC Reachability Analyzer
Compute & Containers: Amazon EKS (Calico/Tigera), Amazon EC2, Amazon EBS, Bottlerocket, Amazon Linux 2023, Packer
Data: Amazon Aurora PostgreSQL, Amazon RDS for SQL Server, Amazon RDS for Oracle, Amazon ElastiCache for Redis, Amazon EFS, Amazon S3, Amazon S3 File Gateway
Security & Governance: AWS Control Tower(Account Factory), AWS IAM, AWS IAM Identity Center, AWS Secrets Manager, AWS KMS, Amazon GaurdDuty, Amazon Inspector, Amazon Macie, AWS Security Hub, AWS CloudTrail, Amazon CloudWatch, Amazon EventBridge, AWS Backup
Artifacts & IaC: Amazon ECR, Terraform
The company chose UTurn for its proven track record building large, enterprise-grade environments for highly regulated financial services products, making UTurn an ideal partner to deliver a reliable solution against aggressive timelines and objectives. As an AWS Premier Tier Services Partner, UTurn’s ability to work alongside AWS and bring the right specialists for the customer's specific technology requirements made for a smooth engagement.
Facing a Broadcom deadline or a regulated cloud migration of your own? UTurn modernizes mission-critical, compliance-bound platforms on AWS without sacrificing uptime or control. Email info@uturndata.com to start the conversation.

Read Case Study


MedTech Marketplace
Read Case Study


Insurance Technology
Read Case Study