"APPWRK IT Solutions Private Limited has demonstrated high confidence in their commitment..."
Highlights
- DocuGuardian helps people organize, protect, and share their most important information so that nothing is lost, missed, or left unclear, keeping life’s critical documents secure and ready for the people who matter most.
- As organizations sought to offer the service to their own clients, the existing self-service onboarding could not support them, routing every new user through payment and treating all accounts alike.
- DocuGuardian engaged APPWRK as a dedicated engineering team to build an organizational onboarding capability into its cloud platform, with the service strengthened to run securely on AWS at scale.
- The work delivered a payment-free signup route for referred clients, a clear line between individual and organizational accounts, and a stronger security posture backed by SOC2 compliance and penetration testing.
Executive Summary
DocuGuardian, a secure cloud service for storing and sharing life’s most important documents, set out to extend its product to organizations that serve their own clients. Its self-service onboarding required every user to pay and could not tell one account type from another. APPWRK, an AWS Partner, built a dedicated organizational onboarding capability and strengthened the way the service runs on Amazon Web Services (AWS), giving DocuGuardian a payment-free signup route, clear separation between individual and organizational accounts, and a monitored, hardened security posture.
Tech Stack
- Visualization & User Interface: React
- Application Layer: Java
- Database: Amazon RDS with Read Replica
- Authentication: Amazon Cognito
- Networking and Security: Amazon VPC, AWS WAF, Amazon Route 53, AWS KMS
- Monitoring and Logging: Amazon CloudWatch
- Email: Amazon SES
- Version Control: GitHub
Tools & Technologies
React JS
Java
AWS S3
AWS RDS
AWS VPC
AWS ALB
Overview
DocuGuardian is a United States based software company, registered in Delaware, that operates a secure cloud service for organizing, protecting, and sharing the documents families rely on during major life events, serving both individuals and the professionals who advise them. To open the service to organizations that wanted to extend it to their own clients, the company engaged APPWRK as a dedicated engineering team that owned delivery, quality assurance, and day-to-day management of the work. The existing self-service onboarding could not support that model, since it routed every user through payment and could not separate a direct customer from someone an organization had referred, so the engagement extended the registration, account, sign-in, and billing layers to serve both audiences while strengthening how the service runs on AWS with a separated network, protected database access, and centralized monitoring.
Challenges: Closing the Gaps Between a Product and a Business Channel
-
Payment Gate Blocked Referred Onboarding
Self-service onboarding required every user to pay before activation, so people referred by an organization had no way to join without first passing through checkout.
-
Account Types Could Not Be Distinguished
The platform could not separate an individual paying member from someone an organization had referred, nor connect that account to the firm responsible for it.
-
Organization Hierarchy Went Unsupported
Nothing in the system represented a client organization, named its administrators, or produced the unique signup links needed to route its people into the correct account.
-
Team Onboarding Remained Manual and Insecure
Administrators at a referring firm could not invite colleagues through secure, expiring links, and the platform had no logic to register newcomers or connect existing accounts on acceptance.
-
Billing Could Not Charge an Organization
Billing offered no way to charge an organization for the people it sponsored, so those individuals would otherwise face payment screens that had no relevance to their access.
-
Permissions Lacked Clear Role Separation
Each kind of account needed its own permission level, and the service had to guarantee that one organization could never view or alter records belonging to another.
-
Sensitive Records Demanded Secure Infrastructure
Holding sensitive personal records, the service had to run on infrastructure that safeguarded that data, repelled hostile traffic, and scaled steadily as its audience expanded.
-
Database Access Required Strict Isolation
Administrators needed safe access to the production database and a clear view of system behavior, without ever exposing the data store or the servers to the open internet.
APPWRK Solution: A Business-Ready Product Delivered
-
Dedicated Onboarding Registration Path
A separate signup route, opened from a unique link, skips the plans and checkout pages and forwards the new member’s details to the back end to create their account.
-
Account-Type Aware Identity Model
Every record now carries a reference to the organization a member belongs to and a marker of account type, so direct customers and sponsored users stay cleanly distinguished.
-
Organization Model and Onboarding Links
A new data structure represents each client organization and issues the unique links that bring its people onto the platform and settle them into the correct account.
-
Secure Invitation and Acceptance Flow
Administrators invite colleagues by email through secure links that expire, opening accounts for newcomers and linking those who already exist, with each role assigned the moment an invitation is accepted.
-
Role-Based Access and Data Isolation
Separate permission levels govern administrators, everyday members, and direct customers, while ownership checks ensure that no organization can ever reach into the records of another.
-
Organization-Routed Billing Logic
Charges flow to the sponsoring organization when a member belongs to one and to the individual otherwise, while payment details stay hidden from anyone an organization already covers.
-
Cloud-Native Application Delivery
The front end is delivered globally from Amazon S3 through CloudFront, while back-end services run on Amazon EC2 behind a managed load balancer, deployed from a version-controlled codebase.
-
Secure-by-Design Network Architecture
A private cloud network divides public and internal zones, AWS WAF screens incoming traffic for threats, and a guarded access point lets the team reach the database safely.
-
Centralized Cloud Observability and Monitoring
Application and security logs collect centrally through Amazon CloudWatch, with alerts for errors and unusual activity, giving the team a clear view of system health without signing into the servers.
Services Involved
Impact: A Governed Business Channel on a Hardened Platform
Conclusion
By committing a dedicated engineering team that owned the work from development through testing, APPWRK gave DocuGuardian a way for advisory firms to bring their own clients onto the platform alongside its established individual experience, supported by account data, a registration flow, and billing rules that keep every type of user distinct. The work also strengthened how the service runs on AWS, with a separated network, protected database access, and centralized monitoring, reinforced by SOC2 compliance and a completed penetration test. Delivered as outsourced software product engineering, the work positioned the company to grow its commercial relationships, with a roadmap ahead that includes automated deployment, auto-scaling, and centralized secrets management.















