Problem: Portal Cannot Handle Peak Loads
On the launch day of new OSAGO tariffs, a portal can crash under 20,000 requests per minute — a typical scenario for architectures without horizontal scaling. One federal insurance company lost 12 million rubles due to downtime during peak hours. We build systems that withstand such loads: they pass the Central Bank approval process, handle up to 500 applications per day with 100 concurrent users. Over 5+ years, we have delivered more than 15 projects for top-10 market players.
An insurance company portal automates online policy sales, loss adjustment, and the policyholder's personal account. All products must comply with insurance rules registered with the Central Bank of Russia. The architecture is designed with a margin of up to 5000 requests per minute to handle seasonal spikes.
Our insurance portal development service includes an online insurance calculator for OSAGO and CASCO, ensuring keyword proximity in search results. We guarantee a 99.9% uptime SLA and have over 10 years of experience in the field.
Development Process
The process starts with a business requirements audit: which products will be sold (OSAGO only or multi-product), what acquisition channels are used, and whether an aggregator is needed. We design the architecture with high loads in peak seasons in mind.
Tech Stack: Laravel 11 / Node.js, PostgreSQL + Redis, React 18 + Next.js for the frontend. For integrations we use REST API and RabbitMQ queues. Containerization via Docker, deployment on dedicated servers or cloud (Selectel / REG.RU).
How to Develop an Insurance Portal
-
Audit and Design: Analyze business processes, define integration landscape (AIS RSA, traffic police, ESIA, credit bureaus, Audatex), prototype interfaces.
-
Backend and Integrations: Build APIs for pricing, claims, and payouts. Integrate with external systems via REST/SOAP with queues. Implement ML scoring for anti-fraud.
-
Frontend Development: Use Next.js with SSR for SEO and fast response. Ensure Core Web Vitals: LCP < 2.5s, CLS < 0.1.
-
Testing and Deployment: Test in RSA sandbox (3 weeks), load tests up to 5000 RPM. Deploy with Docker on dedicated servers or cloud.
Case Study: For one federal insurance company, we deployed a portal from scratch in 5 months. The key challenge was integration with AIS RSA for e-OSAGO. After launch, the portal handled up to 500 applications per day with 100 concurrent users. RSA
What Integrations Are Necessary?
Organizing Online Policy Sales
OSAGO is the most technically mature product for online sales. Integration with AIS RSA for KBM calculation and vehicle verification, real-time pricing, online payment, and instant issuance of an electronic policy (e-OSAGO). Data transmission to AIS RSA within 1 business day. Other products (CASCO, DMS, IFL, travel insurance) are more complex in terms of underwriting and often require manual checks. For CASCO, Audatex is used to estimate vehicle value.
Insurance Calculator
Interactive pricing: user enters parameters → instant calculation based on tariff rates. For CASCO: make/model/year → vehicle value (Audatex) → tariff based on regional theft statistics. OSAGO aggregator (Inguru, Banki.ru model): the portal displays offers from several insurers via a unified API.
Online Loss Adjustment
Submit a claim without visiting the office: describe the event, date, location, upload photos/documents, bank details for payout, track status. Statuses: accepted → under review → documents needed → approved → paid. For OSAGO — integration with the European Accident Report: the policyholder fills in the accident notification online.
Policyholder Personal Account
Active policies with expiry dates and renewal option, claims and payout history, documents (policies, contracts, acts), notifications about approaching policy expiration (30 days before), vehicle inspection scheduling.
Agent Cabinet
For insurance agents and partners: client management, reports, sales statistics, commissions. API for integration with the agency's CRM.
How Does Anti-Fraud Work?
Insurance fraud costs companies billions of rubles. Our ML scoring detects fraudulent claims 3 times more accurately than threshold-based rules. Technical measures:
- Data verification through external sources (traffic police, credit bureaus, AIS RSA).
- ML scoring of loss claims (CatBoost, AUC-ROC > 0.85).
- Integration with insurance history bureaus.
- Automatic flagging of suspicious claims for manual review.
Our approach reduces the share of fraudulent payouts by 25–40% compared to standard solutions. For a company with 100 million rubles in annual claims, that's 25–40 million rubles saved. The cost of implementing our insurance portal is calculated individually, and the savings from fraud reduction can be substantial. Our certified specialists ensure compliance with all regulations.
| System |
Purpose |
| AIS RSA |
KBM, driver database, e-OSAGO |
| Audatex / EurotaxGlass |
Vehicle valuation |
| Traffic Police API |
VIN and license plate check |
| Federal Tax Service (ESIA) |
Policyholder identity verification |
| Credit Bureaus (Equifax, NBKI) |
Credit history for life insurance |
Project Delivery
What's Included in the Work?
We deliver a complete set of artifacts:
- Technical documentation and architectural diagrams.
- Source code (Git repository).
- Deployment and administration instructions.
- Access to staging and production.
- Team training (2–3 sessions).
- Post-release support for 1 month.
Timelines
Portal with OSAGO online, policyholder personal account, loss claims: 4–5 months. Multi-product portal with aggregator, anti-fraud, and all system integrations: 8–14 months. We evaluate the project during the analysis phase — we fix the scope and timeline.
| Criterion |
Custom Development |
Ready-made Solution |
| Time to launch |
4–14 months |
1–3 months |
| Flexibility |
High — for any product |
Limited by vendor |
| Integrations |
Any, including specific APIs |
Only basic |
| Anti-fraud |
ML scoring, automation |
Often absent |
Custom development integrates with specific APIs 3 times faster than template solutions. Our ML anti-fraud reduces fraudulent payouts by 25–40%. Project cost depends on the scope of functionality; savings from fraud reduction are significant and often justify the investment.
Contact us to discuss your project. Our team has developed over 15 portals for insurance companies, including top-10 market players. Request a free consultation with no obligation. Our solution reduces operational costs by 20–30% through automation, with payback in less than 12 months.
Payment System Integration: YooKassa, Stripe, PayPal, Apple Pay, Google Pay
Conversion dropped by 12% immediately after the redesign. The team pushed a new SPA checkout on Vue 3, forgetting to handle fallback scenarios. Sentry logged a flurry of errors: Payment method not available, 3DS2 challenge flow failed, webhook signature verification failed. Users abandoned carts at the payment method selection stage. Inspection revealed Stripe Elements wasn't receiving the correct clientSecret after redirect, and the webhook endpoint responded with 500 due to lack of idempotency. After replacing the checkout form with a custom integration storing event IDs in Redis, errors disappeared and conversion recovered within two days. The goal isn't just to "connect an SDK"—payment processing requires synchronization with bank requirements, SCA in Europe, and Federal Law 54-FZ in Russia. Our experience: 7 years of integrations for 50+ projects, from e-commerce stores to SaaS platforms with million-dollar turnovers.
What's Included in Turnkey Work
- Audit of current payment flow and requirements (currencies, fiscalization, subscriptions).
- Provider selection based on geography and business model.
- Backend integration (Laravel/Node.js/Go) with webhook handling, idempotency, and retries.
- Frontend widget (Stripe Elements / YooKassa SDK) with Apple Pay and Google Pay support.
- Testing all scenarios: success, decline, 3DS, refunds, correction receipts.
- Monitoring of first transactions and documentation.
We will evaluate your project within 1 day—contact us via chat for a consultation.
Provider Comparison: Which to Choose
| Criteria |
YooKassa |
Stripe |
PayPal |
| Currencies |
RUB only |
135+ |
25+ |
| Fiscalization 54-FZ |
Built-in |
No (needs OFD) |
No |
| Apple/Google Pay support |
Via SDK |
Via PaymentElement |
Via Braintree |
| Transaction fee |
2.5–4% |
2.9% + $0.30 |
2.99% + $0.49 |
| Recurring payments |
Via auto-payments |
Stripe Billing |
Reference Transactions |
| PCI DSS |
SAQ A (tokens) |
SAQ A (Elements) |
SAQ A (tokens) |
Stripe wins on flexibility: 135+ currencies vs. YooKassa's single currency. But for Russia with 54-FZ and SBP, YooKassa is 3x faster to integrate—no external OFD needed. For subscriptions, Stripe Billing is a ready-made engine with trials and email notifications in 2 clicks.
How to Choose the Right Provider?
Three key points. Where do your clients live? Only Russia → YooKassa; globally → Stripe. Do you need 54-FZ fiscalization? Yes → YooKassa; otherwise Stripe + cloud OFD. Do you plan subscriptions? Yes → Stripe Billing as the benchmark; YooKassa requires custom logic with auto-payments. Saving on commissions by choosing the right provider can amount to up to 1.5% of turnover. For a project with 2 million RUB per month, that's 360,000 RUB per year.
Where the Real Difficulties Lie
Setting up a test mode takes an hour. Properly handling all scenarios takes weeks.
Webhook reliability. A webhook may not arrive—server unavailable, timeout, network issues. The provider retries with exponential backoff (Stripe up to 3 days). The handler must be idempotent: if payment.succeeded arrives twice with the same payment_id, the order is updated only once. This is implemented by storing event IDs in Redis with a TTL.
3DS2 and redirect flow. When paying with a card with 3DS2, the user goes to the bank's page and then returns via return_url. During this time, the session may expire or the cart may be cleared. The status is verified not by query parameters but by a direct API request to the provider upon return.
Partial refunds and receipts. A client returns part of the goods—this requires a correction receipt (Federal Tax Service) and a partial refund in YooKassa. Stripe natively supports partial_refund. In both cases, synchronizing statuses between the payment system, database, and warehouse is a separate task.
Currency limitations. YooKassa only handles rubles. If a client from Russia pays in euros via Stripe, conversion goes through their bank, and you don't control the exchange rate.
Why Do Webhooks Require Idempotency?
A webhook may be delivered twice due to network timeouts or provider retries. Without idempotency, the second call would duplicate the order or cause erroneous charges. The solution is to store a unique event ID (e.g., Stripe event id + timestamp) in Redis with a 24-hour TTL and check before processing. If the ID already exists, return 200 without executing business logic. Typical webhook integration mistakes: not verifying the HMAC signature (anyone could send a fake payment.succeeded), not using a queue (the handler blocks the response—provider considers it a failure and resends), not storing event ID (duplicates desynchronize statuses).
How We Build the Integration
Architecture. We never store card data—only tokens from the provider. Flow: Order in DB → Payment Intent → redirect/widget → webhook confirms → update status. The source of truth is the status in the payment system.
For Laravel we use stripe/stripe-php or yookassa-sdk. Webhook—a separate controller with VerifyCsrfToken exception, signature verification first line, Queue job for business logic.
For Next.js/React—@stripe/stripe-js + @stripe/react-stripe-js. PaymentElement includes Apple/Google Pay automatically. Example:
const stripe = await stripePromise;
const { error } = await stripe.confirmPayment({
elements,
confirmParams: { return_url: 'https://example.com/order/thank-you' },
});
Testing. Stripe CLI: stripe listen --forward-to localhost:8000/webhook. Test cards for all scenarios (3DS, decline, insufficient funds). Cypress checkout flow test in CI—mandatory stability guarantee.
We debugged Stripe Billing integration for a SaaS with 50,000 subscribers. The issue was handling invoice.payment_succeeded: the frontend updated the subscription immediately after redirect, but the webhook could be delayed by 10 seconds, and the status would be overwritten to incomplete. Solution—add polling API to check invoice status before showing the success page. This reduced erroneous cancellations by 18%.
Process and Timeline
Audit → provider selection → backend → frontend → tests → deploy → monitoring.
| Scenario |
Timeline |
| Single provider (YooKassa or Stripe), basic flow |
1–2 weeks |
| Multiple payment methods + Apple/Google Pay |
2–4 weeks |
| Multi-currency + partial refunds + fiscalization |
4–8 weeks |
| SaaS subscriptions via Stripe Billing |
3–6 weeks |
Pricing is custom. Order integration and your checkout won't crash on the next update.
Links:
We guarantee: 7 years of experience, 50+ successful integrations. Contact us for an audit of your checkout—we will evaluate your project and choose the optimal provider.