A wallet app shipped in 12 weeks, secure to the core

A fintech startup needed a consumer wallet that handled real money correctly and felt effortless. We built it end to end: payments, a ledger with transaction integrity, KYC, and a polished mobile experience, all engineered to the security and correctness bar finance demands.

12 wk
To launch
99.99%
Uptime
256-bit
Encryption

What they came with

The licence window had a fixed date on it, and until there was a working app with transfers, cards and identity checks behind it there was nothing to take through that window. Money movement had to reconcile exactly from the first transaction, because a ledger corrected after the fact is a ledger that cannot be audited. Onboarding had to collect and verify documents to the same standard on day one, not once volume arrived. It also had to be on iOS and Android together rather than one and then the other.

What the engagement covered

  • Ledger with transaction integrity and full audit trails
  • KYC/AML and identity verification integrated
  • Polished, accessible mobile experience on both platforms

Technical detail

Append-only double-entry ledger

Every movement is written as balanced debit and credit rows and balances are derived from them rather than stored and mutated. Corrections are compensating entries, so the history of an account stays intact and readable end to end.

Idempotency keys enforced in the database

Each transfer carries a client-supplied key stored with the transaction under a unique constraint. A retry after a dropped mobile connection settles once, and the guarantee sits in PostgreSQL rather than in application code that can be bypassed.

Reconciliation raises breaks, not adjustments

A scheduled job compares ledger positions against external balances and opens a flagged break when they differ, instead of writing a silent correcting entry. Nothing quietly self-heals, which is what makes the reconciliation record usable in an audit.

Device binding and secure storage

Session and refresh material is bound to the device and held in the iOS Keychain or Android Keystore, with biometric unlock gating local access. An unrecognised device is treated as a new enrolment and sent back through verification rather than issued a session.

The stack

Mobile

React NativeTypeScriptiOS KeychainAndroid Keystore

Backend

NestJSNode.jsTypeScript

Data

PostgreSQLRedis

Infrastructure

AWSDockerAWS KMS
Practice
FinTech App
Sector
Consumer Finance
Shape
Client engagement
Stack
React Native, Stripe, PostgreSQL