Ageas France: DevOps & CI/CD Industrialisation
Industrialising the application delivery chain for life insurance.
A life insurance specialist since 1903, Ageas France turned to Adservio to modernise its CI/CD chain, with Solvency II and IFRS 17 anchored directly in the pipeline.

Project Context
With over a century of history in life insurance, Ageas France faced an impossible equation with its legacy delivery tooling: supporting the digital transformation of the business, absorbing regulatory pressure (Solvency II, IFRS 17, GDPR, NIS2) and shortening release cycles that had become incompatible with the pace of the market.
The legacy Jenkins pipelines, proprietary shell scripts and manual deployments accumulated over the years generated major operational technical debt. Each production release took several days, mobilised every team, and exposed the company to a non-conformity risk that was hard to trace for the ACPR.
The challenge: moving from an artisanal release logic to an industrialised, secure and compliant-by-design CI/CD chain, capable of absorbing regulatory changes without compromising the product cadence, and of durably training the 18 internal squads in this new discipline.
Strategic Objectives
CI/CD modernisation
Rebuild the continuous integration and deployment chain to accelerate the release of life insurance contracts, with automated quality gates and end-to-end traceability on every release (ACPR and IFRS 17 requirements by design).
Native compliance
Embed Solvency II, GDPR and NIS2 controls directly in the pipeline: every deployment passes through a compliance quality gate that automatically blocks production releases in the event of non-conformity or a critical vulnerability.
Standardisation & autonomy
Unify deployment practices across the 18 product squads, eliminate divergent manual configurations and upskill the Ageas teams on modern DevSecOps practices.
Solutions Delivered by Adservio
Adservio deployed a cross-functional DevOps team (DevOps Lead, Platform Engineers, Security Champion, Agile Coach) to transform the CI/CD chain over 22 months.
Initial DevOps audit
Comprehensive diagnosis of the existing CI/CD chains (legacy Jenkins, shell scripts, manual deployments), identification of priority automation areas and mapping of technical debt. Roadmap steered by the executive committee over 22 months.
Pipeline overhaul
Redefinition of the CI/CD pipelines in declarative YAML (GitLab CI + Azure DevOps), integration of automated tests (unit, integration, e2e) with a blocking coverage threshold at 80%, and quality gates per environment (dev, QA, pre-prod, prod).
IaC industrialisation
Deployment of Terraform and Ansible to standardise environments and eliminate manual configurations. Reusable modules, internal registries and a validation pipeline for IaC changes: no more snowflake servers.
Solvency II compliance gates
Direct pipeline integration of automated checks on the SCR ratio, IFRS 17 reporting and traceability of changes to the actuarial modules: each production release includes an auto-generated evidence file for the ACPR.
DevSecOps & native security
Integration of Snyk, Trivy and OWASP ZAP in every pipeline with automatic blocking of merges in the event of a critical vulnerability. Automatic notification of the Risk Officer for exceptions, and a centralised tracker for security debt.
Coaching & enablement
Continuous training of the 18 squads on DevSecOps practices, facilitation of communities of practice, blameless postmortems and the creation of an internal DevOps Academy to sustain upskilling over 3 years.
From a commit to production. In 6 days.
Solvency II compliant.
Every commit triggers a declarative pipeline: build, tests, security, compliance checks, deployment. The ACPR / IFRS 17 quality gates are native: a failing build never reaches production, and the Risk Officer is notified automatically.
Results
Lead time from commit to production cut from 21 days to under 6.
Release cadence across the 18 product squads.
Coverage up from 41% to 83%, with blocking quality gates.
Zero critical vulnerabilities in production, security by design.
Post-release incidents divided by 4 thanks to quality gates.
Autonomous product squads, trained via the internal DevOps Academy.
Impact
Time-to-market −72%
The average lead time from commit to production drops from 21 days to under 6, with a release cadence of 48 deployments per day across the 18 squads: a radical transformation of the product rhythm.
Quality on the rise
Test coverage up from 41% to 83%, critical vulnerabilities down to zero in production, and post-release incidents divided by 4. The quality gates do their job: quality is no longer a matter of discipline, but of tooling.
Native compliance
Solvency II, IFRS 17 and GDPR are now verified on every pipeline, with auto-generated evidence files for the ACPR. Internal and external audits passed without major reservation for 18 months.
Full standardisation
No more manual configuration, no more snowflake servers. Environments are 100% reproducible, and new services start on a standardised stack in under a day.
Autonomy & culture
The 18 Ageas product squads run their pipelines autonomously, with an internal DevOps Academy now led by former Adservio mentees. The transformation is embedded in daily practice.
Security by design
Snyk + Trivy + OWASP integrated into every build, with automatic blocking on critical vulnerabilities. Security moves from an annual review to continuous control, without slowing the product cadence.
More Client Work
Industrialise your DevOps chain in insurance
Let's discuss your CI/CD, compliance and quality gate challenges. An Adservio expert gets back to you within 24h.





















