Stax is a Melbourne-based management platform for AWS. With decades of collective experience delivering enterprise-grade AWS solutions, the Stax team provides companies with the tools and guidance they need to simplify cloud migrations and easily manage their online infrastructure.
Founded in 2015, Stax has grown to a customer base of over 200 companies across 3 continents. Their clients include fast food businesses, luxury brands, and corporations in the top 20 of the Australian Securities Exchange (ASX).
Security is core to Staxโs core platform, which helps customers manage cloud data and infrastructure. Stax follows strict industry guidelines like the Payment Card Industry Data Security Standard (PCI DSS) and SOC2 customer data management from the American Institute of CPAs. In addition to meeting these standards, Stax has its own stringent internal security standards.
โOur enterprise customers contractually require Stax to meet very specific compliance standards,โ says Ridgewell. โThat led us to enforce security controls like Zero Trust across our infrastructure.โ
Early on in its Zero Trust implementation, Stax experienced technical challenges and feature gaps with its prior vendor.
โThe old solution lacked support for our environment. The vast majority of our computer fleet runs MacOS, and many of our critical developers run Linux,โ says Ridgewell. โTheir limited Mac compatibility often delayed our releases, and their Linux functionality was non-existent.โ
Stax also had issues with the vendorโs instability and regular service interruptions. Staxโs developers frequently had their productivity limited by severe latency problems and delays โ especially when accessing company applications and databases.
Finally, Stax disliked that the solution required regular server maintenance โ a task that burdened administrators and ran contrary to the companyโs focus on low-maintenance serverless technology.
โOur old vendor required us to run their tunnel agent on a dedicated EC2 server,โ says Ridgewell. โThat was less than ideal for us. We didnโt want a critical part of our Zero Trust network infrastructure on equipment we needed to manually patch or maintain.โ
Looking for serverless, cloud-native security that met their performance expectations and supported all their operating environments, Stax contacted Cloudflare. For four weeks, Cloudflare collaborated with the company to develop a Zero Trust implementation that made sense for Stax.
โWe created proofs of concept and iterated through designs until we found the configuration that accommodated all of our admin interfaces,โ says Ridgewell. โCloudflare did exactly what we needed it to โ it protected our endpoints and locked down our security much more effectively than the solution it replaced.โ
Cloudflare Zero Trust is now the linchpin for how Stax secures application access, with secure, low-latency connections to company systems and SaaS services like Slack. Cloudflare has made it easy for Stax to apply identity and device posture checks, so Stax can make progress in its Zero Trust approach.
Rather than building and shipping custom workstations loaded with security controls, Stax contractors can securely access specific applications on their own machines using a single sign-on (SSO). Cloudflare integrates with the Staxโs identity provider (IdP) of choice and checks identity for every request before granting access to an application.
Cloudflareโs integration with Crowdstrike has helped Stax layer on device health as another key Zero Trust check. Stax checks for device health based on Crowstrikeโs software before allowing or denying access requests.
โWith Cloudflare and Crowdstrike working together, we know if a device on the network has malware,โ he says. โWe can instantly cut a connection, secure our important systems, and remediate an affected machine. The Cloudflare integration with Crowdstrike strengthens our overall security posture.โ
Stax has also seen an exponential improvement in the quality of employee access to internal systems. Database and administrative access latency has shrunk to less than 100 milliseconds from over 700 โ an 86% change. Further improving productivity, Cloudflare also provided compatibility for development on Linux and Mac, development environments that the previous vendor's solution did not support.
โWe have seen benefits like happier developers, and simplified maintenance,โ says Ridgewell. โAlthough we rarely have problems with Cloudflare, we can easily diagnose and resolve the few problems we do have by ourselves.โ
Finally, Stax solved the manual server maintenance issue that complicated their prior Zero Trust implementation by replacing the dedicated EC2 server with a serverless Cloudflare Tunnel โ lightweight software that runs without costly manually maintained hardware.
โNot needing to manage or patch the server OS also aligns with our goals for a completely serverless infrastructure. That is a huge win for Stax,โ says Ridgewell.
With the Cloudflare dashboard and built-in integration features like the Cloudflare Analytics API, Stax can pipe Cloudflare data directly into critical AWS management tools like Datadog to further improve their service offerings.
Going forward, Stax is interested in taking advantage of Cloudflareโs integration with Terraform to automate the process of deploying security policies for its customers.
โWe are looking into single-click AWS deployment models for Cloudflare and extended Zero Trust policy control via Terraform so that any Stax customer on Cloudflare can easily benefit from the work we are doing,โ says Ridgewell.
For Stax, Cloudflare support has been as significant as the functionality improvements provided by Cloudflare tools. From updates on new features and use cases to issue resolution, Cloudflare has impressed the company with its proactive service.
โA key benefit of choosing Cloudflare is how quickly issues get fixed. Even with obscure problems specific to our deployment, Cloudflare provides the right people for the right outcome,โ says Ridgewell. โI canโt speak highly enough about the partnership.โ
Reduced server and infrastructure access latency by 86% โ from >700 milliseconds to <100 milliseconds improving developer access to resources
Replaced costly and maintenance-intensive server implementation with a serverless Cloudflare Zero Trust solution
Integrated natively with Crowdstrike to ensure device health and strengthen security posture against malware
โCloudflare did exactly what we needed it to โ it protected our endpoints and locked down our security much more effectively than the solution it replaced.โ
Troy Ridgewell
Stax Head of Security
โA key benefit of choosing Cloudflare is how quickly issues get fixed. Even with an obscure problem specific to our deployment, Cloudflare always has the right people for the right outcome โ I canโt speak highly enough about the partnership.โ
Troy Ridgewell
Stax Head of Security