October 10, 2026
Building a Small Bank to Learn Security From the Ground Up
Part 0 of the LedgerLite series: one small banking app on Google Cloud, every security fundamental that matters, and an AI assistant at the…

By Jay Srinivasan
3 min read
Part 0 of the LedgerLite series: one small banking app on Google Cloud, every security fundamental that matters, and an AI assistant at the end
I've spent more than twenty years in IT, and the last eight or so of them in security. If that time has taught me one thing, it's this: almost nobody really learns a security concept from a definition.
You can memorize "least privilege." You can nod along when someone says "defense in depth" in a meeting. But the idea doesn't truly land, not in your gut, until you watch it fail in a real system. One missing check, and someone is suddenly reading data they were never meant to see. One over-generous key, and a small mistake turns into a very bad week.
That's the moment it clicks. It always is.
So I decided to teach it that way.
The plan: build a small bank and watch where it bends
I'm building a small banking app on Google Cloud. I'm calling it LedgerLite, and I'm going to use it to walk through the security concepts that actually matter. Not by defining them, but by building the thing, finding exactly where a weak spot would let someone in, watching that show up in the logs, and closing it one careful step at a time.
LedgerLite isn't a real product. It's a thin scaffold, just enough app to make every concept real in code and in cloud configuration.
Why a bank? Because money makes everything honest. When I show you a missing permission check, it won't be "information disclosure" in the abstract. It'll be me reading your balance. When I show you a tampered record, it won't be a definition of integrity. It'll be someone quietly changing what you're owed. It's hard to stay vague about security when there's money in the room.
Here's what we're building
It's deliberately small. A client talks to an API service written in Go, running in a GKE cluster on Google Cloud. Behind it sit Cloud SQL for accounts and credentials, Cloud Storage for statements, and Secret Manager for keys. Off to the right is an external payee API, marked in coral because that's where trouble will come from later. And there's one grey box marked "later": the AI assistant. We'll get to that.
Every part of this series points back to this picture.
How each piece will go
We start with the groundwork: how you think before you build, and the secure home in the cloud the app will live in. Nothing gets attacked yet. You can't rob a house you haven't built.
Once we start adding real features, each part settles into the same rhythm. First, a real breach where that exact weak spot hurt a real company, Capital One, Okta, LinkedIn, the ones you've read about, so you know none of this is theoretical. Then how the thing actually works, in plain terms. And then over to LedgerLite, with the code and the cloud console right in front of us.
Here's the road, in order:
- The foundations. How to think before you write anything, and the house in the cloud that LedgerLite lives in.
- The front door. Storing passwords, sessions and tokens, and multi-factor authentication. Who gets in, and how we stop someone from simply becoming you.
- The rooms inside. Authorization, so you can only see your own money. Encryption. Defending the API against injection.
- The vault and the walls. Secrets, the network, and the server-side request forgery bug that took down Capital One. Then containers and Kubernetes.
- Everything we didn't build. The pipeline and the software supply chain: every library, image, and tool LedgerLite trusts without having written.
- The cameras and the spare key. Detection, logging, and recovery, because some day something will get through anyway.
- The house-sitter. The part almost nobody is teaching yet. That grey box gets filled in: I'll give LedgerLite a small AI assistant that can actually move money, and we'll see what happens when a stranger sweet-talks it into moving the wrong money. By then, you'll notice that almost everything keeping it safe is something we already built.
And at the very end, one checklist that ties every part together, so you can walk your own app through it.
Before we start
I want to be honest about why I'm doing this out in the open. Part of it is for you, if you build software and have always felt like the security side never quite clicked. But part of it is for me. I only ever learn a thing properly when I have to explain it, and when I have to make it actually work, not just describe it.
So take this as an invitation to learn it alongside me. We'll start next time not with code, but with the quiet decisions you make before any code exists, the ones that turn out to matter most.
Let's build a bank.