About This Architecture
Dual-VPC payment processing architecture separating internal payment logic from external bank integration using isolated network segments and encrypted channels. VPC 1 handles inbound SFTP ingestion, payment processing, and client-facing services across four firewalled VLANs, while VPC 2 manages outbound payment delivery to five Israeli banks via dedicated SFTP egress. Private key signing layer enforces cryptographic controls for payment authorization, with VPN gateway bridging VPCs and monitoring spanning both domains. This zero-trust network design minimizes blast radius, enforces least-privilege access, and meets financial regulatory requirements for payment system isolation and auditability.