Innovation and compliance are often considered contrary to each other: —investing in one typically means ignoring the other. Unfortunately, building in compliance inevitably leads to GTM slowdowns.
Welkin, an application platform developed by Swedish cloud-native company Elastisys, addresses that challenge by building compliance and security directly into the platform itself. This turns existing infrastructure into a secure, production-ready environment, whether it runs in the public cloud, private cloud, on-prem, or in fully air-gapped setups.
“Fintech is immensely competitive. If you can start with a ready-to-use platform that helps you achieve compliance easily, it’s far easier to obtain the necessary certifications and licenses to operate,” says Johan Tordsson, CEO & Co-Founder of Elastisys.
Regulatory complexity
The alphabet soup of regulatory frameworks can make one dizzy: GDPR, PSD3, DORA, PCI DSS, and MiCA are just a few of the frameworks active in Europe.
“The most significant one for European fintechs is DORA, which contains many directives that map directly to the ISO 27000 family of standards,” says Johan.
DORA (Digital Operational Resilience Act) is a European Union regulation that ensures financial institutions can withstand and recover from major IT-related disruptions. The ISO 27000 family is a set of technical standards that security professionals should implement to keep systems secure.
“If you can start with a
ready-to-use platform
that helps you achieve
compliance easily, it’s far
easier to obtain the
necessary certifications
and licenses to operate.”
Johan Tordsson
CEO & Co-Founder of Elastisys

One is a regulatory document, the other is a technical description.
Welkin translates regulatory requirements into code- and hardware-backed standards implementations, helping engineering enforce correct behavior by default.
“As a simple example, a common scenario we often see is when developers try to deploy containers configured with root privilege access. Welkin will reject the deployment,” says Johan.
Last chance: Get your tickets for Stockholm Fintech Week March 19
Avoiding deploying with root user access is cybersecurity 101, but developers can make mistakes. It might sound trivial to avoid this one mistake, but given the breadth of DORA, you end up with hundreds of “trivial mistakes” that developers must remember to avoid. Welkin automates that away.
Compliance and cybersecurity are first cousins
It’s impossible to discuss regulatory compliance without also discussing cybersecurity. Whereas the two topics aren’t the same, a hacked system that leaks financial and customer data is also a regulatory violation.
Welkin includes robust cybersecurity protections directly within the platform, and these protections are trusted by companies in some of the most restricted sectors, such as military defense.
For example, one of Elastisys’s customers, a well-known fintech, is frequently targeted by attempted hacks from threat actors belonging to a well-known belligerent power, yet Welkin’s platform has kept the fintech’s systems unbreached.
Last chance: Get your tickets for Stockholm Fintech Week March 19
All built-in compliance mechanisms are completely documented, allowing auditors to more easily provide certifications for fintechs that implement them.
“Almost jokingly, we say that the auditors and CISOs are the greatest beneficiaries of the tool because it’s so easy to document compliance,” says Johan.
Building a similar solution in-house typically takes about two years, says Johan. However, even if a company manages to do it well, maintaining, updating, and scaling it in a secure and compliant way over time is a major ongoing burden. Welkin removes that burden, so your team can focus on building what actually sets you apart.


