XXImo's migration to AWS with Amazon Payment Cryptography
To meet growing demands and improve flexibility, XXImo, Europe’s leading B2B mobility and payments platform, migrated its core systems from on-premise infrastructure to AWS. Faced with rising costs and scalability limitations, XXImo partnered with CloudNation to design a secure, cloud-native architecture. A key milestone in this migration was becoming the first company in Europe to implement Amazon Payment Cryptography (APC), enabling secure, compliant cloud-based payment processing.
.png)
This successful transformation has equipped XXImo with a scalable, cost-effective, and future-ready cloud environment, positioning the company at the forefront of innovation in mobility and financial services across Europe.
About XXImo
Founded in 2011, XXImo is a leading European B2B platform for mobility access and payments management. Their mission is to simplify business travel, fleet management, and expense control through smart, integrated solutions. With their Milo app, extensive partner network, and innovative technology, they help companies navigate mobility challenges, electrify fleets, and reduce complexity, making every journey seamless, efficient, and future-ready.
The Challenge
XXImo was running its application on on-premise service providers, which proved to be both expensive and inflexible. Scaling up or down to meet demand was slow and inefficient. A critical requirement for the migration was the integration of AWS Payment Cryptography (APC), allowing XXImo to run all its services, including payment processing, on the cloud. As the first company in Europe to implement APC, this presented an unprecedented challenge.
The solution
CloudNation designed a robust cloud architecture and successfully migrated XXImo’s mobility transaction provider platform, which processes cardholder data with VISA, to AWS. To meet the stringent PCI-DSS compliance requirements, we implemented a combination of AWS Payment Cryptography, a restricted networking model using a hub-spoke setup, and centralized governance through AWS Landing Zone Accelerator (LZA). Additional security controls were integrated to ensure the highest level of protection and compliance.
The results
XXImo now operates all its services entirely on AWS, benefiting from enhanced scalability, cost efficiency, and a secure cloud-based payment infrastructure. This transition has positioned them at the forefront of cloud-based financial services innovation in Europe.
Technologies used:
- AWS Transit Gateway
- AWS Network Firewall
- AWS Web Application Firewall
- VPC Endpoints
- Amazon Payment Cryptography (APC)
- AWS Landing Zone Accelerator (LZA)
- Tenable (Cloud Security)
- Wazuh (SIEM Solution)
Through this transformation, XXImo has gained a secure, scalable, and cost-efficient cloud infrastructure, setting a new benchmark in cloud-based payment processing.
