Hospitality and Tourism · TheByke
Embeds Security Across Software Delivery
The Byke is one of India’s leading hotel chains with a diverse portfolio of properties, both operational and under development across various destinations in India. The company is run by professionals who have gained immense experience and expertise in the hospitality industry.
Results at a Glance
- 94% Vulns Blocked
- 40+ Pipelines Secured
- <8 min Feedback Time
- DevSecOps Framework
The Challenge
The customer required a secure software delivery capability to prevent vulnerable code and third-party dependencies from reaching production. Existing CI/CD pipelines lacked integrated security testing, mandatory policy enforcement, and centralized visibility into application security findings.
After a known-vulnerable open-source dependency package was identified in a production workload, the customer engaged AxiomIO to implement a DevSecOps platform that embedded automated security controls throughout the software development lifecycle and established consistent governance across all application releases.
Our Solution
AxiomIO designed and implemented a standardized DevSecOps platform that embedded automated security controls throughout the customer's software delivery lifecycle. The solution established a common CI/CD pipeline using AWS CodePipeline and AWS CodeBuild, ensuring every application was built, tested, scanned, and deployed through a consistent and centrally governed process.
Security testing was integrated as mandatory pipeline stages and executed automatically for every code change. The solution combined secrets detection, static application security testing (SAST), software composition analysis (SCA), container image scanning, and dynamic application security testing (DAST) to identify vulnerabilities before software could be promoted to production.
To ensure consistent governance, AxiomIO implemented policy-based security gates that evaluated scan results against customer-defined risk thresholds. Builds containing Critical or High severity vulnerabilities were automatically blocked unless an approved, time-bound security exception had been granted.
Security findings from all scanning tools were normalized into the AWS Security Finding Format (ASFF) and imported into AWS Security Hub using a custom AWS Lambda integration. This provided the security operations team with centralized visibility into application security risks across the customer's entire software portfolio while enabling automated notifications, triage, and remediation workflows.
The resulting platform provided the customer with a repeatable and scalable DevSecOps capability that embedded security into every software release while maintaining a consistent governance model across all development teams.
Results
The implementation established a standardized and secure software delivery capability across the customer's application portfolio, replacing manual and inconsistent security practices with automated, policy-driven controls.
Key outcomes included:
- A standardized CI/CD pipeline adopted across development teams, ensuring every application follows a consistent software delivery process.
- Automated security testing integrated into every build, enabling earlier identification of vulnerabilities in source code, third-party dependencies, container images, and deployed applications.
- Policy-based security gates preventing applications containing Critical or High severity vulnerabilities from progressing to production unless an approved security exception exists.
- Centralized visibility of application security findings through AWS Security Hub, providing the security operations team with a single view of software delivery risks across all applications.
- Automated notification and remediation workflows that improved vulnerability triage and reduced the time required to identify and respond to security findings.
- A formal security governance process, including documented release policies and time-bound waiver approvals, replacing ad hoc security decisions within development teams.
Beyond the technical implementation, AxiomIO worked with development and security teams to establish operational processes for managing pipeline security. Developers received training on the standardized pipeline, security teams assumed ownership of release policies and exception management, and remediation activities were integrated into the customer's existing security operations workflow. This ensured the DevSecOps capability became an operational practice rather than simply a technical deployment.