Exchange core
Crypto exchange development,
built for regulated launch.
We build spot and OTC venues for crypto startups, licensed VASPs and banks. One EU team owns the order book, the ledger, the wallets and the audit trail. You get a venue you can run, prove and hand to a regulator.
- EU-based engineers
- MiCA-ready architecture
- GDPR-compliant delivery
Scope
What we build inside the venue
An exchange is six systems that must agree with each other. We build them as one product, on one plan, with one team accountable for the whole.
-
01
Matching engine
A price–time priority order book that stays correct under load. Every fill is replayable from the event log.
- Limit, market, stop
- Deterministic replay
- Pre-trade risk checks
-
02
Ledger & settlement
A double-entry ledger holds the truth. Balances, fees and withdrawals reconcile against it daily.
- Double-entry core
- Fee schedules
- Daily reconciliation
-
03
Wallet & custody links
Hot, warm and cold tiers with signed approval paths. We build the links or wire up your custodian.
- MPC or HSM signing
- Withdrawal policies
- Deposit sweeps
-
04
Onboarding & KYC
Sign-up, identity checks and risk scoring in one flow. Vendor swaps stay cheap because the flow is ours.
- KYC/KYB vendor layer
- Sanctions screening
- Case review queue
-
05
Trading front end
Web and mobile clients over the same public API. Charts, order tickets and account views ship together.
- REST, WebSocket, FIX
- Market data feed
- Admin console
-
06
Ops & observability
You cannot run a venue you cannot see. Metrics, alerts and audit trails land on day one, not later.
- Latency dashboards
- Audit log
- 24/7 on-call runbooks
Delivery
The build sequence
Compliance work does not wait for the end. It runs beside the build, so nothing has to be unpicked before launch.
Need the rules mapped first? Read our compliance engineering practice.
- 01
Discovery
2–4 weeks
Target architecture, asset list, licence scope and a costed delivery plan.
- 02
Core build
Iterative
Matching engine, ledger and wallet paths built behind a hardened API.
- 03
Compliance hardening
Runs in parallel
Travel Rule, AML rules, data handling and evidence for your auditor.
- 04
Launch & support
Ongoing
Load testing, cut-over, then 24/7 cover with named engineers.
Architecture
The order path we ship
Ingress, risk and matching run as separate services. Each one can be replayed on its own. That is what makes a trading day provable.
Order path: ingress, then risk, then matching, then the ledger, then custody.
Engagement
Four ways to buy the work
Scope changes as you learn. The commercial model should change with it, not fight it.
-
Fixed-scope build
A defined venue, a fixed price, a dated plan. Best when the scope is settled.
-
Dedicated team
A standing squad with a lead. Best for long roadmaps and steady release cycles.
-
Staff augmentation
Senior engineers inside your team. Best when you own the plan and need depth.
-
CTO advisory
Architecture and hiring guidance. Best before you commit to a build.
Questions
Before you brief us
The four things buyers ask first. Ask the rest on the call.
Can you work with our existing exchange code?
Yes. We often take over a partly built venue. We start with an architecture and security review, then agree what to keep.
Do you handle the licence itself?
We are engineers, not a law firm. We build to a MiCA or VASP scope and hand your advisers the technical evidence they ask for.
Who owns the code?
You do. We build bespoke, client-owned systems. There is no white-label lock-in and no per-seat licence at the end.
How do we start small?
Begin with a discovery sprint or a two-person team inside your own squad. Scale up once the plan is proven.
Tell us what you plan to launch
Bring a rough scope. We come back with an architecture view, a risk list and a costed plan. No demo theatre.