Our work

Engineering Deprisa’s cloud backbone for logistics at scale.

A cloud platform that connects customers, partners, and logistics operations without coupling every service together.

Deprisa couriers beside a truck at their logistics hub.
The operation behind every shipment.César Melgarejo / EL TIEMPO

The project

Deprisa’s digital platform connects shipment tracking, quotations, content, and partner integrations. As that ecosystem grew, application logic, access controls, and third-party dependencies needed clearer boundaries. Wagner rearchitected the Azure foundation so the platform could evolve with the business.

What we delivered

We separated presentation from integration, established Azure API Management as the governed entry point, and connected the platform to identity, secrets management, and telemetry. Protected edge services, container delivery, and independent application workloads turned the architecture into an operable cloud platform.

Services

  • Azure cloud rearchitecture
  • Network & perimeter security
  • API governance & integration
  • Identity & secrets management
  • Observability & resilience
  • Container delivery & CI/CD

Outcomes & value created

Lower latency
40%
Faster responses across core service flows.
Traffic capacity
3×
More capacity for concurrent demand.
Service availability
99.9%
A more dependable cloud foundation.
Cloud cost savings
25%
A leaner infrastructure footprint.

Independent services, shared governance

Frontend, backend, and content workloads have distinct responsibilities. API policies provide a common control point for consumers and integrations.

A platform built for more channels

Tracking, shipment events, and quotations are available through focused service contracts, giving web and partner channels a reusable integration layer.

Production with operational context

Request correlation, dependency telemetry, health checks, and repeatable QA and production pipelines connect delivery to day-to-day operations.

Objectives & challenges

The objective was to modernize the cloud foundation while keeping Deprisa connected to the logistics systems it already depended on. We needed to separate workloads, govern access, and make failures diagnosable without treating every new channel as another bespoke integration.

  • Decouple frontend, APIs, and CMS so each can evolve independently.
  • Protect public entry points and apply access policies consistently.
  • Integrate existing logistics providers behind stable service contracts.
  • Make deployment, request tracing, and recovery part of the architecture.

Engineered from edge to operations.

Protected ingress, isolated application responsibilities, governed integrations, and a shared operational foundation. Each layer has a clear job and a visible connection to the next.

Azure platform architectureMicrosoft Azure
Web · App · B2B partners · OperationsHTTPS request path

Edge & perimeter

Azure Front DoorCDN · WAF · Routing
Network firewallTraffic inspection

Virtual network · Application workloads

FrontendPresentation layer
BackendIntegration layer
CMSContent management

API governance

API ManagementShared gateway

JWT validation · Traffic limits · Transformation

TrackingEventsQuotations

Logistics systems

Shipment servicesTracking & quotations
Delivery servicesExpress services
Workload identity · Governed API access

Identity, data & observability

  • Managed IdentityWorkload identity
  • Key VaultSecrets & configuration
  • Application InsightsTraces & dependencies
  • Azure StorageContent & files
  • Azure MySQLManaged data
Azure DevOps
Container Registry
Continuous deliveryBuild → Registry → App Service deployment

The channel calls a governed API. The BFF transforms logistics responses into current shipment status and event history, keeping provider formats out of the presentation layer.

Quotation requests use the same gateway and a dedicated service integration. The backend translates logistics contracts and applies resilience to upstream calls.

Conceptual view of platform capabilities. It does not represent production topology or configuration.

Tech Stack & Partners

The cloud platform, infrastructure, and engineering tools behind the delivery.

  • Microsoft Azure
  • Azure Front Door & WAF
  • Azure App Service
  • API Management
  • Managed Identity
  • Key Vault
  • Application Insights
  • Azure DevOps
  • Container Registry
  • Azure MySQL
  • Azure Storage
  • .NET
  • Docker

Our approach

  1. Map the platform before changing it

    We traced the application, content, tracking, and quotation dependencies. That map defined the workload boundaries, trust model, and migration sequence for the Azure platform.

  2. Build the cloud and service boundaries

    We connected edge protection, application hosting, and API governance. The .NET integration layer normalizes logistics responses, while managed identity and Key Vault separate service access from embedded credentials.

  3. Make every release operable

    Container builds move through QA and production pipelines. Health checks validate deployments, and Application Insights connects application logs to upstream dependencies and request correlation.

Key activities & takeaways

Make boundaries explicit

Separating presentation, integration, and content reduces the number of places a channel change needs to touch.

Put governance in the request path

Central routing, traffic policies, and identity validation give API consumers a consistent contract and operations a clear control point.

Trace the whole dependency chain

A request needs context across the gateway, application, and logistics provider. Correlation and dependency telemetry belong in the design from the start.

Treat delivery as infrastructure

Container registries, deployment pipelines, and post-deploy health checks make the platform repeatable beyond its initial release.

Ready to stabilize and scale your cloud?

Start with a technical conversation about the infrastructure issues creating risk, instability, or friction for your team.

Talk to an expert