Zero-Trust by Design: Turning One e-Commerce API into Condor’s Enterprise Backbone
Speaker: Maximilian Friedrich, Product Owner Condor API Program at Condor Airline (Condor Flugdienst GmbH)
Condor Airlines transformed a fragile legacy interface into a Zero Trust API platform that now powers nearly every booking, finance, and customer-touch point across the airline. The journey shows how a self-hosted AWS stack can satisfy Europe’s rising demands for data sovereignty and security while staying agile for upcoming AI workloads
Why it matters Airlines are pouring record budgets—US $37 billion in 2024 alone—into digital backbones and cybersecurity, yet most still rely on perimeter auth and siloed portals that leak sensitive flight data. Condor proves you can go Zero Trust-by-design without vendor lock-in or latency trade-offs.
What it covers:
• From perimeter to policy-as-code — OAuth 2.0 + API keys enforced in the pipeline.
• Quality gates as an “immune system” — Qualys, Veracode and fail-fast rules that slashed defect escape rates.
• Self-hosted AWS stack — API Gateway, Lambda and IaC patterns that keep costs predictable and migration paths open.
• Twin developer portals, one trust model — identical auth for staff and travel-agency partners cut onboarding from 12 weeks to four.
• Business impact — 90 % of digital workflows ride the backbone; credential-leak incidents dropped to zero; ancillary-revenue APIs ship twice as fast.
Who it’s for and Key Takeaways:
Platform engineers, API product owners, and security architects will leave with:
• A build-vs-buy decision tree for Zero Trust API platforms.
• Reusable CI/CD templates and cost/latency benchmarks to plug into their own pipelines.
• A playbook for selling API-first culture to ops and finance—proving security and speed aren’t trade-offs. Attendees walk away ready to turn a “simple API” into a verifiable, enterprise-grade backbone—without losing agility, budget, or sovereignty.