Left pane: the Terraform code. Middle: the live AWS provision. Right: the complete underwriting workflow — application, browser-side obfuscation, enclave credit pull, lender portal, document review, decision model, funding, and audit trail. All three run in lockstep. Click any bubble to pause the entire demo.
# Biteris Funding — Global Direct Lending Platform # AWS Infrastructure · Managed by PING192 · Terraform 1.6+ terraform { required_version = ">= 1.6.0" required_providers { aws = { source = "hashicorp/aws", version = "~> 5.0" } } backend "s3" { bucket = "ping192-tfstate-prod" key = "biteris-funding/terraform.tfstate" region = "us-east-1" dynamodb_table = "ping192-tflock" encrypt = true } } # ─── NETWORK ───────────────────────────────────── module "vpc" { source = "terraform-aws-modules/vpc/aws" name = "biteris-funding-prod" cidr = "10.42.0.0/16" azs = ["us-east-1a", "us-east-1b", "us-east-1c"] private_subnets = ["10.42.1.0/24", "10.42.2.0/24", "10.42.3.0/24"] public_subnets = ["10.42.101.0/24", "10.42.102.0/24", "10.42.103.0/24"] database_subnets = ["10.42.201.0/24", "10.42.202.0/24", "10.42.203.0/24"] enable_nat_gateway = true enable_flow_log = true } # ─── DATA ──────────────────────────────────────── module "rds" { source = "terraform-aws-modules/rds/aws" identifier = "biteris-funding-prod" engine = "postgres" engine_version = "15.4" instance_class = "db.r6g.xlarge" allocated_storage = 500 storage_encrypted = true storage_kms_key_id = aws_kms_key.funding_data.arn multi_az = true backup_retention_period = 30 performance_insights_kms_key_id = "arn:aws:kms:...:key/████" parameter_group_override = { shared_preload_libraries = "████" } } resource "aws_elasticache_replication_group" "funding_cache" { replication_group_id = "biteris-funding-cache" node_type = "cache.r7g.large" num_cache_clusters = 3 at_rest_encryption_enabled = true transit_encryption_enabled = true } resource "aws_s3_bucket" "documents" { bucket = "biteris-funding-docs-encrypted" } resource "aws_s3_bucket_server_side_encryption_configuration" "documents" { bucket = aws_s3_bucket.documents.id rule { apply_server_side_encryption_by_default { sse_algorithm = "aws:kms" kms_master_key_id = aws_kms_key.funding_data.arn } } } # ─── COMPUTE ───────────────────────────────────── module "ecs" { source = "terraform-aws-modules/ecs/aws" cluster_name = "biteris-funding-prod" fargate_capacity_providers = { FARGATE = { default_capacity_provider_strategy = { weight = 1 } } } } resource "aws_lb" "funding_alb" { name = "biteris-funding-alb" load_balancer_type = "application" subnets = module.vpc.public_subnets drop_invalid_header_fields = true } resource "aws_lambda_function" "intake_handler" { function_name = "biteris-funding-intake" runtime = "nodejs20.x" handler = "index.handler" memory_size = 512 timeout = 30 } resource "aws_lambda_function" "credit_scoring" { function_name = "biteris-credit-scoring-v3" runtime = "python3.12" memory_size = 1024 timeout = 60 } # ─── SECURITY ──────────────────────────────────── resource "aws_kms_key" "funding_data" { description = "Biteris Funding — 512-bit data key" enable_key_rotation = true multi_region = true } resource "aws_wafv2_web_acl" "funding_waf" { name = "biteris-funding-waf" scope = "REGIONAL" default_action { allow {} } rule { name = "████████" priority = ███ action { block {} } } rule { name = "████████" priority = ███ action { count {} } } } resource "aws_secretsmanager_secret" "bureau_credentials" { name = "biteris-funding/bureau-credentials" kms_key_id = aws_kms_key.funding_data.arn } resource "aws_nitro_enclave_certificate_iam_role" "enclave" { role_name = "biteris-enclave-exec" attestation_endpoint = "https://████████████.amazonaws.com" } # ─── OBSERVABILITY ─────────────────────────────── module "observability" { source = "./modules/observability" log_retention_days = 365 xray_enabled = true } resource "aws_sns_topic" "oncall" { name = "biteris-oncall-24x7" } # ─── DELIVERY ──────────────────────────────────── resource "aws_cloudfront_distribution" "funding_cdn" { enabled = true aliases = ["api.biteris.net", "apply.biteris.net"] origin { domain_name = aws_lb.funding_alb.dns_name origin_id = "funding-alb" custom_origin_config { origin_protocol_policy = "https-only" } } } # ─── OUTPUTS ───────────────────────────────────── output "api_endpoint" { value = aws_cloudfront_distribution.funding_cdn.domain_name } output "db_endpoint" { value = module.rds.db_instance_endpoint } output "kms_key_id" { value = aws_kms_key.funding_data.id }
$ terraform apply Click "Run full demo" to begin. Click any bubble to pause. Click again to resume.
Left pane is code, middle is the provision, right is the full workflow — borrower → enclave → lender → decision → funding → audit. All three run on one synchronized timeline.
PING192 provides round-the-clock on-call coverage. Alerts route to PagerDuty, Slack, SMS, and WhatsApp. SLA for first response is 15 minutes, with pre-built runbooks for every failure mode. For crises, a senior engineer is paged directly.
The frosted PROPRIETARY blocks contain PING192's hardened parameters — WAF rule priorities, enclave attestation endpoints, decision weights, rotation secrets. The methodology is public; the specific hardening parameters are not.
Terraform, IaC, zero-knowledge architecture, full underwriting pipelines, and 24/7 ops from senior engineers.