A Zero Trust networking foundation that lets a fast-growing insurer launch in new markets without opening a single port.
50% Faster market launches
40% Reduction in operational overhead
172 hrs To deploy secure microservices across clouds
300k+ Policies sold in year one
Ready to get started?
As Ominimo scaled its business across the EU, VPN-centric architecture created bottlenecks, attack surface exposures, and compliance risks.
NetFoundry Cloud’s identity-bound overlay networking replaced VPNs across Ominimo’s multi-cloud stack.
50% faster market launches, 40% lower operational overhead, and audit-ready compliance.
Ominimo is an AI-powered digital insurer, founded in Serbia and launched in Hungary. It sold more than 300,000 policies in its first year, enough to capture roughly 7% of the market. Its proprietary low-code platform prices policies using AI across hundreds of variables, an approach that’s attracted backing from Zurich Insurance Group and DA Direkt.
But Hungary was just the start. Ominimo is now expanding into Poland, Sweden, the Netherlands, and more than a dozen other EU markets, each with its own compliance regime and infrastructure quirks. Growing that fast meant its core insurance systems, pricing engines, data pipelines, and analytics needed to move just as quickly, without opening the business up to new security risks.
“As CTO of an insurtech operating in several regions, I value solutions that reduce complexity without compromising security. NetFoundry delivered exactly that. Their product streamlined our environment setup across markets, and their support has consistently exceeded expectations.”
Kevin Day, CTO, Ominimo
As Ominimo expanded rapidly across European markets, its infrastructure needed to balance agility, security, and control at the same time. Every new market added a unique layer of complexity its legacy connectivity model wasn’t built to absorb.
Core pricing and calculation engines needed to talk constantly with transactional data stores and downstream analytics — both across cloud data centers and within them — without exposing any of that traffic to the public internet, or leaning on a flat network that couldn’t tell one service from another.
Ominimo runs on containers, and containers need to be managed. That meant giving Portainer secure, reliable access to interact with container runtimes and workloads across environments. It’s a job that’s awkward at best for a VPN, which is designed to secure a network’s perimeter, not the individual services living inside it.
Traditional VPN-centric models introduced exactly the bottlenecks you’d expect: slower provisioning, a wider attack surface from public IP exposure, and no real way to enforce service-level isolation. For most companies, that’s inconvenient. But for an insurer navigating EU insurance directives and regional data protection mandates, it’s a compliance gap. In this industry, identity-aware, least-privilege access isn’t optional; it’s the baseline regulators expect.
Rhapsody had already tried a competitive Zero Trust offering before finding NetFoundry, and it didn’t hold up — bugs and gaps kept forcing the team back to old-school IPSec VPNs and manual allowlisting. When Rhapsody’s engineers discovered OpenZiti and started exploring NetFoundry, they quickly saw the difference. It worked in their stack exactly how Zero Trust should: broad-based, secure, and fast to deploy.
Rhapsody embedded NetFoundry’s Zero Trust SDK directly into Envoy Edge, giving the product secure remote access and full lifecycle management without customers having to do anything differently on their end.
With NetFoundry, every connection Rhapsody establishes (whether to a cloud environment, an on-prem site, a specific server, or directly inside an application) is outbound-only. No inbound ports, no port-forwarding rules, nothing for a customer’s IT team to configure or for an auditor to flag. Provisioning that used to require a custom build now happens fast, by default.
Ominimo adopted NetFoundry Cloud as an application-centric Zero Trust networking layer, connecting core insurance services across Hetzner and AWS through identity-driven, policy-based access instead of VPNs. The shift let Ominimo deploy several containerized services (pricing engines, data pipelines, analytics, admin portals) as a secure, scalable private overlay in under 72 hours.
Pricing engines, data services, analytics pipelines, and supporting platform services now communicate over an identity-bound overlay, enforcing east-west and north-south microsegmentation everywhere they run. Instead of trusting anything inside the perimeter, every connection has to prove who it is first.
Portainer now operates as a trusted service inside the Zero Trust overlay, giving Ominimo secure, policy-driven container lifecycle management across clouds without VPNs or shared credentials to manage. Log and telemetry data flows the same way, moving securely from application and platform services into Ominimo’s centralized ELK monitoring environment over that same overlay, so visibility never comes at the cost of security.
NetFoundry Cloud’s geo-scalable, self-healing overlay lets Ominimo onboard new regions without re-architecting the network each time. Expansion becomes a configuration change, not a rebuild.
“We moved beyond the perimeter with NetFoundry. It delivers a strictly ‘least-privileged’ access model that is incredibly easy to deploy. The management console turns what used to be a tangle of firewall rules into a streamlined, visual command center.”
Viktor Szabó, Deputy CTO, Ominimo
Replacing VPNs with NetFoundry Cloud didn’t just close a security gap; it gave Ominimo room to grow without adding risk every time it entered a new market.
Deployment and launch timelines dropped by half, accelerating Ominimo’s push into new EU markets. The upgrade gave the company a meaningful edge in a category where being first to market with a new pricing model matters.
Automation and Zero Trust design cut operational overhead by 40%. No VPNs to provision, no inbound firewall rules to manage, no IP conflicts between customers or environments to untangle by hand.
Identity-based, microsegmented access keeps Ominimo aligned with EU insurance and data protection mandates in every market it enters. Regulators get the auditable trail they expect, rather than a patchwork of manual controls assembled after the fact.
But this story is less about VPN replacement and more about business model enablement. Ominimo’s entire competitive edge is speed: pricing risk faster and smarter with AI, and getting that pricing in front of customers in a new market ahead of competitors. A network that couldn’t scale as fast as the business would have capped how fast Ominimo could grow. Instead, centralized monitoring, granular DevOps reporting, and a network that treats every new market as a configuration change rather than a rebuild means Ominimo’s infrastructure now moves at the same pace as its pricing engine: fast.
“NetFoundry enabled us to deploy a highly secure environment with remarkable ease. The low maintenance overhead and the team’s outstanding support made a significant difference for us.”
Dušan Janković, Lead Developer, Ominimo
NetFoundry helps insurers and financial platforms eliminate open attack surfaces, ditch VPN complexity, and launch in new markets faster. All without rebuilding their architecture from scratch.
NetFoundry is a leader in Secure Workload Connectivity, founded by the inventors and maintainers of OpenZiti, the world’s most widely used open source Zero Trust platform. NetFoundry enables enterprises to secure and connect AI agents, MCP servers, LLMs, APIs, OT/IoT infrastructure, and traditional enterprise workloads, all with no open inbound ports, no VPNs, and no firewall changes. NetFoundry secures billions of sessions for critical infrastructure on three continents and supports Fortune 10 companies across regulated industries including healthcare, financial services, and energy.