---
title: "Loop"
description: "Customer success story: Loop secures air-gapped cash deposit machines with Cerbos"
customer: "Loop"
canonical: "https://www.cerbos.dev/customers/withloop"
image: "/assets/use-case-files/social/withloop-case-study-url-thumbnail.png"
source: "https://www.cerbos.dev/customers/withloop"
---

# Loop secures air-gapped cash deposit machines with Cerbos

A fintech company offering financial operations software and physical cash deposit machines implements secure and scalable authorization wiht Cerbos and streamlines compliance certifications.

## At a glance

- Authorization rolled out in one week
- 6 months of upfront development saved
- Swiftly satisfied key regulatory requirements

> The Cerbos solution is battle tested, secure and it's doing what it's supposed to do. We have full trust in the product.
>
> — Mohsin Kalam, CTO & Co-founder, Loop

### Summary
Loop, a rapidly expanding B2B FinTech startup, streamlines financial operations and generates substantial working capital savings for businesses.
Cerbos is an authorization service that helps software developers implement fine-grained access control in minutes and save months in authorization maintenance.
Loop used Cerbos to implement authorization in their finance operations software products and their air-gapped cash deposit machines. And as a result, were able to speed up their release cycle, keep their authorization policies updated much easier, and meet crucial compliance requirements.

[Watch the video](https://www.youtube.com/watch?v=h4xdo8QmHwI)

## Introduction

### Building secure and compliant access control for software and hardware

As a fintech company Loop places the utmost importance on their security and compliance measures.

Their collections, invoicing, and cash management software solutions help businesses keep accurate records, and execute safe and secure transactions in both cash and credit systems. Their digital cash deposit machines, or “reverse ATMs” can be used for self-checkouts. Or they can be used for businesses to digitally record cash transactions and update their records in real time.

To meet regulatory requirements Loop needs to demonstrate that airtight privacy and security measures are in place in their software and their physical machines.

## Requirements

### Strict compliance, proven reliability and efficiency

Mohsin Kalam, CTO and Co-Founder of Loop, wanted a third-party solution for authorization because he knew it would serve them better in the long run.

“Authorization is something that we take very seriously because we deal with financial transactions. And **we wanted to make sure that we have something that's battle-tested** for our company and we didn't want to reinvent the wheel.”, Mohsin explains.

To Mohsin, a third-party solution not only helps ensure the quality of their authorization system but also helps save valuable time. He didn’t want his developer team to be spending time building and maintaining authorization when they could be working on feature development and product adoption.

“If we had to do it on our own we wouldn't have been able to scale, as we are now, with the confidence that we have. And we especially would not have been able to meet compliance requirements as quickly,” Mohsin adds.

### Evaluation - Set up and deployed in just one week
Loop’s engineering team defined policies for their use case with support from Cerbos. Developing policies in Cerbos’ YAML format allowed non-technical team members from Loop to be involved in the process as well, ensuring that their policies met their users’ needs, and their regulatory requirements. **Using the API documentation and the step-by-step instructions, the team at Loop was able to set up the architecture and roll out their authorization in just one week.**
“We have Java in our tech stack, we have NodeJS, we have ReactJS. Cerbos integrates with all of them really well because it works on an API basis. It does not matter what the consuming technology is,” Mohsin says.
For their machines, **they deployed separate Cerbos instances in air-gapped environments, giving each machine its own Policy Decision Point.**
“The thing I love about Cerbos, is that you can just work it as an open source dockerized container - just need to pull in the latest image and boom, you have a server deployed,” he shares.
After setting Cerbos up, Loop only touches their authorization when they need to add or update a policy. The automated comprehensive audit logs Cerbos provides are a constant source of information that Loop can rely on to give them confidence that their policies are working as they should.

> The ease of use, the cohesion between the overall system, the back and the frontend, they all talk to a single point. That's huge in terms of time saving and reliability for us, and maintenance wise as well.
>
> — Mohsin Kalam, CTO & Co-founder, Loop

## Result

### A trusted name in their security layer

When communicating with regulators, Mohsin shared that the Cerbos name in their security layer is recognized as a reliable solution for authorization.

“We use AWS Cognito for our authentication. Straight away, they know that it's a service that is used by millions of customers and it's the industry standard. Similarly, **when we say we are using Cerbos as our authorization layer, then people just say, okay, I know that your product has good authZ support as well.”** As a result, Loop was able to meet compliance requirements swiftly and smoothly.

With authorization and compliance solved, **Mohsin estimates that choosing Cerbos instead of building authorization saved them 3-6 months of development time** just on the initial setup process. That time was instead dedicated to serving customers, and the team was able to speed up their release process.

“We were actually able to focus on other parts of the pipeline and other parts of the software development life cycle. So, speed to release has been impacted, which meant that we could service more customers much faster,” Mohsin highlights.

#### Related links

- <a href="https://www.cerbos.dev/blog/how-loop-achieved-reliable-and-scalable-authorization-with-cerbos">Full interview with Mohsin Kalam</a>
- <a href="https://www.cerbos.dev/customers/debite">Debite accelerates compliance certification and ships products faster</a>
- <a href="https://www.cerbos.dev/customers/nook">Nook onboards 3x more users by implementing granular roles and permissions</a>

#### Learn more about Cerbos

- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/security-standards">Security and compliance</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/human-readable-authorization">Human-readable authorization</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/advanced-observability">Advanced observability</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/audit-logs">Audit logs</a>
