Build a Landing Zone on AWS
Galen Simmons, a Y Combinator alumnus, established Accolade with a distinct goal: to assist property management firms in reaching top-quartile growth through operational improvements. Their platform enhances communication flows and complex processes within multifamily operations, boosting ROI in leasing, resident involvement, and delinquency management. To target NMHC Top 50 multifamily operators—clients with strict vendor criteria—Accolade required an infrastructure as strong as their software. With his development team concentrating on essential features, Galen collaborated with Towards the Cloud to create an AWS foundation that would align with enterprise security standards from the outset.
**The Challenge**: Accolade needed an AWS environment that would:
- Comply with enterprise security standards immediately
- Support SOC 2 compliance certification
- Scale reliably with business growth
- Enable developers to work swiftly without sacrificing security
Their previous setup, a single AWS account with manual configurations, was inadequate for these needs.
**The Solution**: A Comprehensive AWS Landing Zone
In partnership with Accolade's Head of Engineering, Mohit Aggarwal, we developed and implemented a multi-account AWS architecture following the Well-Architected Framework. Our solution integrated extensive security features directly into the foundation:
**Security-First Architecture**:
We established a six-account structure:
- Management Account for AWS Organizations
- Security Account for centralized security services
- Log Archive Account for audit trails and centralized storage of aggregated logs
- Dedicated Development, Staging, and Production Accounts for various workloads.
This architecture achieved a perfect score of 100% on the CIS AWS Foundation Benchmark and 96% on AWS’s foundational security best practices, effectively positioning Accolade for SOC 2 compliance.