A wallet app shipped in 12 weeks, secure to the core
A fintech startup needed a consumer wallet that handled real money correctly and felt effortless. We built it end to end: payments, a ledger with transaction integrity, KYC, and a polished mobile experience, all engineered to the security and correctness bar finance demands.
- 12 wk
- To launch
- 99.99%
- Uptime
- 256-bit
- Encryption
What they came with
The licence window had a fixed date on it, and until there was a working app with transfers, cards and identity checks behind it there was nothing to take through that window. Money movement had to reconcile exactly from the first transaction, because a ledger corrected after the fact is a ledger that cannot be audited. Onboarding had to collect and verify documents to the same standard on day one, not once volume arrived. It also had to be on iOS and Android together rather than one and then the other.
What the engagement covered
- Ledger with transaction integrity and full audit trails
- KYC/AML and identity verification integrated
- Polished, accessible mobile experience on both platforms
Technical detail
Append-only double-entry ledger
Every movement is written as balanced debit and credit rows and balances are derived from them rather than stored and mutated. Corrections are compensating entries, so the history of an account stays intact and readable end to end.
Idempotency keys enforced in the database
Each transfer carries a client-supplied key stored with the transaction under a unique constraint. A retry after a dropped mobile connection settles once, and the guarantee sits in PostgreSQL rather than in application code that can be bypassed.
Reconciliation raises breaks, not adjustments
A scheduled job compares ledger positions against external balances and opens a flagged break when they differ, instead of writing a silent correcting entry. Nothing quietly self-heals, which is what makes the reconciliation record usable in an audit.
Device binding and secure storage
Session and refresh material is bound to the device and held in the iOS Keychain or Android Keystore, with biometric unlock gating local access. An unrecognised device is treated as a new enrolment and sent back through verification rather than issued a session.
The stack
Mobile
Backend
Data
Infrastructure
- Practice
- FinTech App
- Sector
- Consumer Finance
- Shape
- Client engagement
- Stack
- React Native, Stripe, PostgreSQL
Something like this to build?
Tell us what runs today and where it hurts. An engineer reads it and replies.