🚀 Key Takeaways at a Glance
✅An MSP case modernizing a legacy .NET and MSSQL OCR environment with Vue, PostgreSQL, and Amazon ECS
✅Expanded unstructured document extraction with LLM OCR powered by Amazon Bedrock
✅Template-based extraction for batch processing of similar documents
✅Real-time monitoring of LLM token usage and a framework for cost optimization
✅A secure generative AI environment using Bedrock Guardrails
✅Ongoing architecture optimization and cost monitoring across ECS and RDS
Company
Dongwon Group is an integrated food company that has grown from its roots in the fisheries industry and has strong capabilities across global marine resource development, food production, and distribution.
Large volumes of documents—including invoices, shipping documents, and certificates—are generated throughout global seafood procurement and food distribution. Reviewing these documents accurately and entering the information into business systems are repetitive tasks. To automate this work, Dongwon Group had been operating an OCR application based on AWS Textract.
Doosan Corporation Digital Innovation BU (DDI) carried out a project to advance the existing OCR environment into a generative-AI-based AI OCR platform. Since then, DDI has served as the managed services partner for the overall AWS account, responsible for container-based operations, LLM token governance, security guardrails, and cost optimization.
Engagement Overview
-
Customer:
Dongwon Group
-
Industry:
Integrated food production and distribution
-
Preceding modernization project:
July 1, 2025–November 30, 2025 (delivered directly by DDI)
-
Managed Services (MSP) contract start date:
December 1, 2025
-
Managed Services (MSP) contract end date:
November 30, 2027 (24-month contract; operations are ongoing)
-
Country of service delivery:
South Korea (implementation and operations)
-
Scope of MSP services:
Operations across the AWS account; ECS and RDS architecture optimization; LLM token usage monitoring and optimization; generative AI guardrail operations; security reviews; cost optimization; and monthly operations reporting
-
Delivery model:
Managed Services
Challenge
Dongwon Group sought to expand the document-processing capabilities of its existing OCR environment, improve the operational efficiency of its legacy architecture, and strengthen the cost and security governance required for generative AI adoption.
-
Expanding OCR coverage to include unstructured documents.
The AWS Textract-based OCR environment had operated reliably for structured forms, and Dongwon Group sought to extend its coverage to unstructured documents without predefined templates and to new invoice formats. LLM-based capabilities were needed to enhance extraction by interpreting document context and identifying the required fields.
-
Strengthening template capabilities for efficient processing of similar documents.
Many documents varied slightly by trading partner while sharing a similar field structure. A framework was needed to let administrators register and reuse frequently used formats as templates, streamlining the process of defining extraction fields for each document.
-
Enhancing the LLM usage monitoring framework.
Token usage can vary depending on call volume and input-document length. A framework was needed to provide more granular visibility into token usage and costs by user and function, enabling proactive management of cost fluctuations.
-
Strengthening scalability and deployment efficiency to support business growth.
The existing .NET and MSSQL service had been operating reliably on EC2. To accommodate future traffic growth and accelerate feature releases, its deployment approach and scaling model needed to be enhanced. A transition to a container-based architecture was required to enable elastic scaling during peak document-processing periods and automate deployments.
-
Strengthening the environment for secure generative AI use.
Business documents contain information that requires protection, including commercial terms, unit prices, and contact details. Safeguards were needed to systematically manage LLM inputs and outputs, protect sensitive information, and support appropriate content use.
-
Strengthening the integrated operating model across the AWS account.
To operate an environment combining containers, managed databases, and generative AI reliably and efficiently, a dedicated operating model was needed to cover infrastructure monitoring, incident response, change management, and security reviews.
As-Is Architecture
Before the MSP contract, Dongwon Group’s OCR environment was configured as follows.
Existing (As-Is) Textract-Based OCR Architecture
-
Amazon Textract-based OCR processing:
AWS Textract was used to extract text and table data from document images.
-
Amazon EC2-based OCR application:
The application handling OCR requests and result management was deployed and operated directly on EC2.
-
.NET and MSSQL architecture:
The application was developed in .NET, with operational data stored in MSSQL.
-
Manual deployment and fixed capacity:
Manual deployments and fixed instance capacity constrained the ability to respond to workload fluctuations and release new features.
Solution
DDI preserved and extended the existing OCR environment by adding generative-AI-based extraction and modernizing the application stack with containers. After migration, DDI established an integrated operating model across the AWS account, including LLM token governance and guardrail management.
New (To-Be) Architecture for MSP Operations, LLM Governance, and Container Modernization
-
Amazon Bedrock-based LLM OCR extraction.
Using text and table recognition results from Textract, generative AI in Amazon Bedrock interprets document context and identifies and extracts required fields. This supports unstructured documents and new formats without predefined templates. Textract and the LLM are used together, preserving the stability of the traditional approach for structured documents and applying LLM flexibility to unstructured documents.
-
Template-based extraction-field management.
Frequently used document formats can be registered as templates, with extraction fields and prompts managed by template. Similar documents can be processed in batches by reusing templates, enabling business teams to respond to new formats without additional development.
-
Migration to Vue and PostgreSQL with ECS-based container modernization.
The front end was migrated to Vue, the database to Amazon RDS for PostgreSQL, and the application was containerized and deployed on Amazon ECS on AWS Fargate. Amazon ECR manages container images, enabling zero-downtime deployment by service and automatic scaling. RDS Multi-AZ removes the database single point of failure.
-
LLM token usage monitoring and optimization.
Token usage and call counts by user, function, and template are collected as CloudWatch metrics, aggregated daily, and visualized in dashboards. AWS Budgets thresholds trigger immediate alerts. Prompt length, document chunking, and model selection were also reviewed to reduce tokens per call while maintaining extraction quality.
-
Secure LLM operations with Bedrock Guardrails.
Amazon Bedrock Guardrails controls both LLM inputs and outputs to block sensitive-data exposure, inappropriate content, and prohibited topics. Blocking events are logged for operational review.
-
Stronger security controls and auditability.
AWS WAF protects the external-facing ALB, AWS CloudTrail records and tracks account API activity, and AWS Secrets Manager separates database credentials and API keys from code and configuration. Security groups and IAM permissions were aligned with least-privilege principles.
-
ECS and RDS architecture optimization.
ECS task CPU and memory allocations and autoscaling policies were tuned to actual document-processing patterns. RDS instance classes and storage were reviewed, and S3 lifecycle policies reduced long-term storage costs for source documents and extraction results.
-
Continuous cost monitoring and monthly reporting.
Cost Explorer and budget alerts provide ongoing visibility, while regular Well-Architected Framework reviews validate the architecture. Monthly reports cover resource utilization, incidents and events, LLM token usage, guardrail blocks, security findings, cost trends, and optimization recommendations.
AI OCR Operating Model Built on Core AWS Services
-
Amazon ECS + AWS Fargate:
Containerized application execution and automatic scaling
-
Amazon ECR:
Container image storage and deployment version management
-
Amazon RDS for PostgreSQL (Multi-AZ):
Operational data management for users, templates, and extraction results
-
Amazon Bedrock:
Generative-AI-based document analysis and LLM OCR extraction
-
Amazon Bedrock Guardrails:
LLM input/output safety controls and sensitive-data blocking
-
Amazon Textract:
Recognition of document text and table data for structured-document processing and preprocessing
-
Amazon S3:
Storage of uploaded source documents and extraction results, with lifecycle-based cost optimization
-
Elastic Load Balancing (ALB):
Service traffic distribution
-
AWS WAF:
Web-layer attack protection and enhanced security for externally exposed services
-
AWS Secrets Manager:
Secure storage and rotation of credentials and authentication keys
-
AWS CloudTrail:
Auditability through recording and tracking account activity
-
Amazon CloudWatch:
Metrics, logs, and alerts, including LLM token usage
-
AWS Cost Explorer / AWS Budgets:
Cost visibility and function-level budget alerts
-
AWS Well-Architected Tool:
Identification and remediation tracking of architectural risks
DDI Support Services
As both the modernization delivery partner and the managed services partner, DDI provided continuous support from implementation through transition and recurring operations.
-
Pre-transition support.
DDI analyzed the existing .NET and MSSQL environment and Textract-based OCR flow to define the modernization scope and transition approach. It compared extraction quality and token cost across LLM models, established template and prompt design standards, reviewed account-wide security settings, IAM permissions, network configuration, and cost structure, prioritized post-transition improvements, and agreed incident-response and escalation procedures with the customer.
-
Transition support.
DDI migrated to Vue and PostgreSQL and deployed ECS containers in phases while running the legacy OCR service in parallel, enabling a transition without business disruption. MSSQL-to-PostgreSQL data migration included pre-validation and reconciliation. WAF and CloudTrail deployment, Bedrock Guardrails configuration, token-usage metrics, and budget alerts were implemented during low-impact windows with rollback procedures prepared for each activity.
-
Post-transition operational support.
DDI provides continuous monitoring, incident detection and response, container deployment support, change management, and regular reviews across the AWS account. Token usage and cost are checked daily, threshold breaches trigger immediate action, and guardrail blocking history is reviewed regularly to adjust policies. Monthly reports, Well-Architected reviews, and continuous cost-optimization recommendations are also provided.
Benefits
Through MSP-led modernization and integrated operations, Dongwon Group expanded its document-processing coverage while improving deployment and scaling efficiency and strengthening control over generative AI operations.
-
Broader coverage of unstructured documents.
Combining LLM-based extraction enables processing of documents without predefined templates and new formats. Business teams can respond by registering templates, reducing dependency on development teams.
-
Control of generative AI cost risk.
Visibility into token usage by user and function, combined with budget-threshold alerts, enables excessive LLM usage to be identified and controlled early. Prompt and document-chunking optimization reduces token costs while maintaining extraction quality.
-
A secure generative AI environment.
Bedrock Guardrails blocks sensitive-data exposure and inappropriate content in LLM inputs and outputs, enabling safer use of generative AI for business documents.
-
Improved deployment efficiency and scalability.
Container deployment on ECS on Fargate enables zero-downtime releases and automatic scaling, shortening feature-release cycles and supporting peak document volumes reliably.
-
Higher service availability.
Multi-Availability Zone ECS placement and RDS Multi-AZ remove single points of failure and help services remain available during instance or database failures.
-
Stronger security response and auditing.
WAF, CloudTrail, and Secrets Manager provide web-attack blocking, account-activity tracking, and separated credential management, while regular security reviews identify and remediate vulnerabilities early.
-
Reduced operational burden.
With DDI operating the overall AWS account, the customer can focus on document operations and data quality instead of infrastructure management.
Metrics for Success
The following key operating metrics compare the environment before and after the MSP transition.
-
Supported document formats:
12 structured templates → 40 templates plus unstructured-document support
-
Document extraction accuracy:
Approximately 82% with Textract alone → approximately 95% with Textract + LLM
-
Average processing time per document:
Approximately 6.5 minutes, including manual validation → approximately 1.8 minutes, a reduction of about 72%
-
LLM token usage:
100% baseline before optimization → approximately 66%, a reduction of about 34%
-
LLM usage visibility:
No aggregation framework → daily aggregation and dashboards by user and function
-
Bedrock Guardrails blocks:
Not applied → approximately 120 blocks per month for sensitive information and prohibited topics
-
Deployment time:
Approximately 50 minutes for manual deployment → approximately 7 minutes for zero-downtime ECS deployment, a reduction of about 86%
-
Rollback time after deployment failure:
Approximately 30 minutes manually → approximately 3 minutes automatically
-
Mean time to detect (MTTD):
Approximately 40 minutes → within 5 minutes
-
Average monthly WAF blocks:
Not applied → approximately 3,500 blocks
-
Well-Architected high-risk items:
8 → 0 (medium-risk items: 15 → 3)
-
Monthly cloud cost:
100% baseline → approximately 84%, a reduction of about 16%
-
Operations reporting cadence:
Ad hoc → scheduled monthly reporting
Current Activities Following the MSP Transition
DDI did not end its engagement after implementation and transition. As the managed services partner, it continues to perform the following activities.
-
Ongoing ECS and RDS architecture optimization:
Container resource allocations, autoscaling policies, and database configurations are continuously adjusted to usage patterns.
-
LLM token usage optimization and monitoring:
Token usage and cost are monitored continuously, and improvements to prompts and document chunking are identified and proposed.
-
Guardrail policy operation and review:
Bedrock Guardrails blocking history is reviewed regularly, policies are adjusted, and a secure LLM environment is maintained.
-
Comprehensive security review and validation:
CloudTrail and WAF configurations are reviewed, and architecture validation based on the Well-Architected Framework is performed regularly.
-
Continuous cost monitoring and optimization:
Usage and resource status are monitored continuously, optimization opportunities are identified, and recommendations are provided through monthly reporting.