How Deposit Book Cut Its API Footprint by 26% and Won FCA Approval with a Security-First Platform Overhaul

Ajackus audited, denormalised, and secured Deposit Book’s wholesale deposit marketplace platform, cutting REST API endpoints by 26% and resolving critical security vulnerabilities in 12 weeks — work that directly supported the company’s FCA approval.

Services

Managed Delivery

Platform Engineering

Security Audit and Remediation

Technologies

case-studies postgresql-image | Ajackus.com
deposit_box_macbook

26%

Reduction in API Endpoints

12 Weeks

Audit-to-Delivery Timeline

4

Critical Security Vulnerabilities Resolved

Overview

Executive Summary
Client
Challenge
Goals
Journey
Results
Technology
Takeaways
FAQ

Executive Summary

The Problem

Deposit Book’s wholesale deposit marketplace was held back by a slow, over-engineered backend and multiple unresolved security gaps that put user trust and platform efficiency at risk.

The Solution

Ajackus conducted a full codebase audit, denormalised the database and refactored redundant backend logic, cutting the platform’s REST API surface from 210 to 155 endpoints while resolving four categories of security vulnerabilities.

The Result

The engagement reduced API endpoints by 26% in 12 weeks and directly supported Deposit Book’s successful FCA approval in the UK, along with a new institutional partnership with Fintuitive.

Client

Deposit Book operates a global wholesale deposit marketplace, connecting Partner Banks, Depositors, Client Banks, and Custodian Banks to facilitate cross-border cash deposits. As the platform scaled, its backend architecture had accumulated technical debt that threatened both performance and regulatory credibility — a critical risk for a company operating in a heavily regulated fintech niche. Ajackus was engaged to resolve these issues ahead of a key regulatory milestone.

Company Deposit Book
Industry FinTech — Wholesale Deposit Marketplace
Platform Scale Connects Partner Banks, Depositors, Client Banks, and Custodian Banks globally
Engagement Type Codebase audit, performance optimisation, and security remediation

Challenge

The Bottom Line

Deposit Book needed to eliminate performance bottlenecks and close critical security gaps in its core platform without disrupting an active marketplace connecting banks worldwide.

As Deposit Book’s marketplace grew, the underlying platform had not kept pace. Years of incremental feature development had left the backend over-normalised and bloated with redundant logic, while unresolved security issues put both user data and platform trust at risk — a serious liability for a company pursuing regulatory approval in the UK.

Sluggish Platform Performance

Response times across the platform had become prolonged, degrading the experience for depositors and partner banks transacting in real time.

Unwieldy API Surface

Over-normalised database tables and redundant backend code had inflated the platform to 210 REST API endpoints, making the system harder to maintain and slower to extend.

Unresolved Security Vulnerabilities

The platform carried multiple security gaps, including sensitive information disclosure and insecure transport layer protection, that posed direct compliance and reputational risk.

Regulatory Exposure

With FCA approval on the horizon, unresolved security issues represented a business-critical blocker, not just a technical one.

Goals

The engagement needed to simplify the platform’s backend, resolve critical security vulnerabilities, and position Deposit Book for a successful FCA regulatory review — all without disrupting a live marketplace connecting banks worldwide.

Goal Success Criterion
Reduce backend complexity and redundant API surface Meaningful reduction in total REST API endpoint count
Improve platform performance Faster response times across core user flows
Close critical security gaps Zero unresolved instances of the identified vulnerability classes
Support Deposit Book’s regulatory approval process Platform security posture ready for FCA review
Preserve system stability during refactor No disruption to live marketplace operations during the engagement

Journey

The Ajackus team ran the engagement as a focused, two-track audit-and-remediation programme, embedding directly with Deposit Book’s platform to diagnose and fix issues at the source rather than patching symptoms.

Codebase Audit and Performance Enhancement

The Ajackus team began with a thorough codebase audit to identify the root causes of the platform’s performance issues. The audit traced the bottlenecks to an over-normalised database schema and redundant backend code paths that had accumulated across successive feature releases. Rather than optimising individual queries in isolation, the Ajackus team deliberately chose to denormalise key tables and refactor the underlying logic — a more invasive but longer-lasting fix than incremental tuning. This work reduced the platform’s REST API footprint from 210 to 155 endpoints, a 26% cut that simplified the system while improving response times.

Security Issue Resolution

In parallel, the Ajackus team addressed four categories of security vulnerabilities identified during the audit: sensitive information disclosure, insecure transport layer protection, insecure file upload handling, and sensitive information exposed in GET requests. Each fix was scoped and remediated with Deposit Book’s upcoming regulatory review in mind, ensuring the platform’s security posture would hold up under FCA scrutiny — a constraint that shaped prioritisation throughout the 12-week engagement.

Results

The engagement cut Deposit Book’s API footprint by 26%, resolved four categories of critical security vulnerabilities, and was delivered in 12 weeks — directly supporting the company’s FCA approval and a new Fintuitive partnership.

26%

Reduction in API Endpoints

155

Endpoints Remaining (Down from 210)

12 Weeks

Total Engagement Timeline

What went well:

Technical Achievements

  • Reduced REST API endpoints from 210 to 155, a 26% cut achieved through database denormalisation and code refactoring
  • Resolved four distinct categories of security vulnerabilities, including sensitive information disclosure and insecure transport layer protection
  • Delivered the full audit-to-remediation programme in 12 weeks without disrupting live marketplace operations

Business Impact

  • Directly supported Deposit Book’s successful FCA approval in the UK, clearing a critical regulatory milestone
  • Enabled a new partnership with Fintuitive, a UK-based fintech, giving Fintuitive’s institutional clients access to worldwide cash deposits through Deposit Book’s marketplace
  • Strengthened platform trust and reliability for banks and depositors transacting on the marketplace

Why It Worked

Audit Before Action

The Ajackus team started with a full codebase audit rather than assuming where the problems were. This surfaced the true source of the platform’s performance issues — an over-normalised schema and redundant logic — rather than treating individual slow endpoints in isolation.

Fix Root Causes, Not Symptoms

Denormalising the database and refactoring backend code was a more significant undertaking than surface-level query tuning, but it addressed the structural cause of the endpoint sprawl, cutting the API surface by 26% instead of masking the symptom.

Security Aligned to Regulatory Stakes

The Ajackus team treated security remediation as a regulatory-readiness exercise, not a generic checklist. Each vulnerability was fixed with Deposit Book’s FCA review in mind, directly contributing to a successful approval outcome.

Frequently Asked Questions

What caused Deposit Book's platform performance issues before the Ajackus engagement?

An over-normalised database schema and redundant backend code had accumulated over time, inflating the platform to 210 REST API endpoints and slowing response times across core user flows.

What security vulnerabilities did Ajackus resolve for Deposit Book?

The Ajackus team remediated four categories of vulnerabilities: sensitive information disclosure, insecure transport layer protection, insecure file upload handling, and sensitive information exposed in GET requests.

How did the API endpoint reduction improve the platform?

By denormalising database tables and refactoring redundant code, the Ajackus team cut the endpoint count from 210 to 155 — a 26% reduction that simplified the codebase and improved maintainability alongside performance.

How quickly can Ajackus embed engineers to run an audit like this?

Ajackus typically scopes and begins audit-and-remediation engagements within days of alignment on priorities, embedding engineers directly with the client's existing platform team rather than working at arm's length.

How does Ajackus handle security remediation for regulated fintech platforms?

Ajackus prioritises fixes based on regulatory exposure and business risk, not just technical severity — as with Deposit Book, where remediation work was scoped specifically to support an upcoming FCA review.

We're Ajackus
We combine design, engineering, and speed to deliver beautifully crafted, scalable products.