Delivery dossiers

Proof you can read.
Not a wall of logos.

Most of our work sits behind an NDA. So we publish the dossier instead of the client name. Each one shows the problem, the architecture we shipped and the rules it was built against. Read them as a spec sheet, not a story.

Three builds, three rulebooks

One EU group built all three. Same architecture standard, same evidence trail, different regime each time.

DOSSIER 01 Exchange core

Spot exchange rebuilt for audit

A trading venue outgrew its first matching engine. Fills were hard to explain after the fact.

We split ingress, risk and matching into separate deterministic services. Every order is written to an event log first. A trading day can be replayed and reconciled fill by fill.

Ingress Risk Match Ledger
Scope
Matching engine, risk, ledger reconciliation
Ingress
FIX 4.4 · REST · WebSocket
Standards
MiCA-ready records · GDPR
Model
Fixed-scope build, then dedicated team

Crypto exchange development

DOSSIER 02 Wallet & custody

MPC custody without a single key holder

A licensed VASP needed custody it could defend to an examiner. No single person may hold a key.

Signing runs on MPC (multi-party computation). Key shares sit in separate trust zones. Policy, quorum and withdrawal limits are enforced before a signature is ever requested.

Request Policy Quorum Sign
Scope
MPC signing, policy engine, hot/warm split
Controls
Quorum approval · address allow-lists
Standards
AML / Travel Rule · SOC 2 readiness
Model
Dedicated development team

Wallet & custody engineering

DOSSIER 03 Payment rails

Crypto gateway joined to card rails

A PSP wanted to accept crypto beside cards. Two ledgers had to agree at the end of every day.

We built one settlement ledger for both rails. On-chain and card events land in the same double-entry book. Payouts, refunds and chargebacks are handled by shared logic.

Capture Ledger Reconcile Payout
Scope
Gateway, settlement ledger, payout engine
Rails
On-chain · SEPA · card acquiring
Standards
PSD2 · PCI DSS readiness
Model
Fixed-scope build with support retainer

Payment gateway engineering

How a dossier is made

Every build follows the same four moves

A regulated product fails on evidence, not on features. So we produce evidence from day one. The steps below are the same whether you buy a fixed-scope build or a dedicated team.

Want the rulebook view instead? Read our compliance approach and compliance engineering practice.

  1. Discovery and threat model

    We map the product, the money flow and the rulebook it will be examined on. That map sets the architecture.

  2. Architecture on paper first

    Services, data ownership and failure modes are agreed before code. Clients keep the diagrams.

  3. Build with evidence attached

    Each release ships with tests, logs and a change record. Auditors get a trail, not a story.

  4. Hardening and hand-over

    Security review, runbooks and on-call training. Your team can run the system without us.

How these builds were bought

The work above ran under four commercial models. Pick the one that fits your stage.

Working on something else? See solutions, fintech infrastructure or staff augmentation. New teams often start with CTO advisory before a line of code is written.

Ask us about a dossier

Bring your scope and your regulator. We will tell you which of these builds yours looks like. First call is a working session, not a pitch.