Upgrade to Pro — share decks privately, control downloads, hide ads and more …

apidays Paris 2025 | Zero Trust By Design

Sponsored · Ship Features Fearlessly Turn features on and off without deploys. Used by thousands of Ruby developers.
Avatar for apidays apidays PRO
February 07, 2026

apidays Paris 2025 | Zero Trust By Design

Zero-Trust by Design: Turning One e-Commerce API into Condor’s Enterprise Backbone
Speaker: Maximilian Friedrich, Product Owner Condor API Program at Condor Airline (Condor Flugdienst GmbH)

Condor Airlines transformed a fragile legacy interface into a Zero Trust API platform that now powers nearly every booking, finance, and customer-touch point across the airline. The journey shows how a self-hosted AWS stack can satisfy Europe’s rising demands for data sovereignty and security while staying agile for upcoming AI workloads

Why it matters Airlines are pouring record budgets—US $37 billion in 2024 alone—into digital backbones and cybersecurity, yet most still rely on perimeter auth and siloed portals that leak sensitive flight data. Condor proves you can go Zero Trust-by-design without vendor lock-in or latency trade-offs.

What it covers:
• From perimeter to policy-as-code — OAuth 2.0 + API keys enforced in the pipeline.
• Quality gates as an “immune system” — Qualys, Veracode and fail-fast rules that slashed defect escape rates.
• Self-hosted AWS stack — API Gateway, Lambda and IaC patterns that keep costs predictable and migration paths open.
• Twin developer portals, one trust model — identical auth for staff and travel-agency partners cut onboarding from 12 weeks to four.
• Business impact — 90 % of digital workflows ride the backbone; credential-leak incidents dropped to zero; ancillary-revenue APIs ship twice as fast.

Who it’s for and Key Takeaways:
Platform engineers, API product owners, and security architects will leave with:
• A build-vs-buy decision tree for Zero Trust API platforms.
• Reusable CI/CD templates and cost/latency benchmarks to plug into their own pipelines.
• A playbook for selling API-first culture to ops and finance—proving security and speed aren’t trade-offs. Attendees walk away ready to turn a “simple API” into a verifiable, enterprise-grade backbone—without losing agility, budget, or sovereignty.

Avatar for apidays

apidays PRO

February 07, 2026
Tweet

More Decks by apidays

Other Decks in Technology

Transcript

  1. Zero Trust By Design Product Owner Condor API ❘ Condor

    Flugdienst GmbH Maximilian Friedrich How Condor turned one legacy API into a 
 Zero Trust enterprise backbone
  2. Dogs don’t wear hats None of them is wearing a

    seatbelt They are not allowed to sit there, as they can’t open the door in case of emergency!
  3. Dogs don’t wear hats None of them is wearing a

    seatbelt They are not allowed to sit there, as they can’t open the door in case of emergency! z Power of APIs 🚀
  4. Today’s Flight Plan Act I The Check In Act II

    The Security Gate Act III The Take Off
  5. Neither should your APIs. Passing the control At the airport,

    you never get waved through because ‘you look trustworthy.’
  6. We had big topics on the table Legacy APIs Mixed

    Authentications Premise Infrastructure Scattered Teams Different Protocols Default Company in Re-Build-Up Outdated eCom Stack Mixed Consumers Diverse Fleet
  7. 3.5 years later A new eCommerce platform was born Completely

    renewed eCom stack Fully operational integrated agile release train Centralised IAM Auth eCommerce Platform 30 + fully automated business fl ows 80+ APIs 40+ Consumers One Condor API API
  8. And so does our API. Hence enforcing API-keys and OAuth

    2.0 using AW Cognito on every request, subject to data regulatory. Airports Trust No One Not even colleagues
  9. Our API reaches every department of Condor and beyond Flight

    Search & Booking Payments External APIs Flight Status Auxiliary Products Ancillary Products Mobile App Travel Agencies Flight OPS Service Center condor.com Aircrafts via Satelite
  10. Airport don’t just check passengers, they also scan baggage, run

    maintenance on planes and keep an “immune system” against risks. The Immune System Quality Gates
  11. Airports serve two types of passengers: frequent fl yers and

    tourists. They use the same passport control, same ID rules, but maybe different lanes. Two Portals One Trust Model
  12. Security didn’t slow us down, it speeds us up Credential-leak

    incidents 
 dropped to zero 90% Of core airline work fl ows now run on the backbone 0% Credential leaks