Home / Architecture PLATFORM ARCHITECTURE

Cloud-native. Event-driven.
Region-pinned.

Built for the room with the architecture review. Microservices on Kubernetes, an event spine on Kafka, an API-first surface for every Micro AI, HSM-backed key management, and data residency that defaults to where your regulator wants it. This is the page that closes the CTO’s questions.

99.99% SLA target Active-active multi-region
Event-driven Kafka event spine Every change is a replayable event
API-first Every module exposed REST + GraphQL + webhooks
HSM Backed key management No soft-key fallback
HIGH-LEVEL ARCHITECTURE

Six layers. One ledger of truth.
Every decision replayable.

The platform is structured as six logical layers. Each layer exposes a versioned API. Data flows up; events flow across. Region pinning lives in the data plane, so the same application code runs in every region with no fork.

L1 · Edge / Public API API Gateway · OAuth 2.0 · Rate limiting · WAF REST + GraphQL + Webhooks + Server-Sent Events L2 · Module services (microservices on Kubernetes) Compliance PS25/12 · AML · sanctions KYC / KYB Identity · UBO · biometrics Banking Ledger · VIBANs · sub-ledgers Payments CHAPS · FPS · SEPA · SWIFT Cards Issuance · 3DS2 · disputes CRM / Engagement Upsell · churn · BI L3 · AI substrate · 95 Micro AIs AI Models · Confidence · Audit trail · Replay Risk-adaptive KYC · UBO mapping · SAR drafting · routing · churn · breach predictor · regulatory scanner L4 · Event spine Apache Kafka · Event sourcing · Replayable from any timestamp Every decision, payment, reconciliation, alert, and KYC outcome is a signed event with full lineage. L5 · Data plane (region-pinned) UK · live London · FCA Europe · live Frankfurt · ECB GCC UAE · CBUAE Africa Nairobi · CBK Singapore Singapore · MAS India Mumbai · RBI L6 · Security base · HSM · Zero-trust · Audit HSM-backed key management · mTLS service mesh · AES-256 at rest · TLS 1.3 in transit · signed immutable audit log
ARCHITECTURE PRINCIPLES

Six commitments.
Hardwired into every decision.

01

Cloud-native microservices.

Kubernetes-orchestrated. Each module is an independently deployable service. No monolith, no in-flight migration risk.

02

Event-driven by default.

Apache Kafka event spine. Every change is an event. The platform is replayable from any point in time.

03

API-first.

Every module exposes a versioned REST + GraphQL API. SDKs maintained alongside the API surface.

04

Zero-trust security.

mTLS service-to-service. No implicit network trust. Every call authenticated and authorised.

05

Region-pinned data.

Data residency is enforced in the data plane. Application code is region-agnostic; data never leaves its jurisdiction.

06

99.99% SLA target.

Active-active multi-region. In-region failover in seconds. Cross-region failover within a minute.

TECH STACK

Mature primitives.
No bleeding-edge dependencies.

Every load-bearing component is mature, well-supported, and widely understood. This is not the place to chase novelty.

LayerPrimaryPurpose
Compute & orchestration
Container runtime Kubernetes (managed · EKS) Orchestration with multi-region failover
Service mesh Istio · mTLS Zero-trust service-to-service auth
API gateway Kong / AWS API Gateway Auth, rate limiting, WAF, request routing
Data & events
Event spine Apache Kafka (MSK) Event sourcing & cross-service messaging
Primary store PostgreSQL · Aurora Per-region · multi-AZ · point-in-time recovery
Cache Redis · ElastiCache Session, rate-limit, hot data
Search / audit OpenSearch Audit log + full-text search across decisions
Warehouse Snowflake · BigQuery Optional client analytics integration
AI & ML
Model serving BentoML · Triton Low-latency inference with model versioning
Feature store Feast Shared feature pipelines across models
Training Internal pipelines · MLflow Versioned training + decision auditability
Security & observability
Keys / HSM AWS KMS · CloudHSM Hardware-backed key custody
Secrets HashiCorp Vault (managed) Just-in-time secret access, rotation
Observability Datadog · Sentry Logs, traces, metrics, errors
SIEM Datadog Cloud SIEM Threat detection on log + audit stream
PRE-BUILT INTEGRATIONS

Already wired up.
So you don’t have to.

PAYMENT SCHEMES

Visa · Mastercard · UnionPay.

Card scheme connectivity, 3DS2 authentication, tokenisation (Apple Pay / Google Pay).

UK RAILS

CHAPS · FPS · BACS.

UK payment rails through Pay.UK. Confirmation of Payee on the roadmap.

EU RAILS

SEPA · SEPA Instant · TARGET2.

EU payment rails including SEPA Instant for real-time euro transfers.

CROSS-BORDER

SWIFT GPI · ISO 20022.

Cross-border SWIFT with GPI tracking. ISO 20022 message standard support.

CORE BANKING

Temenos · Finastra · Thought Machine.

Pre-built connectors for major core banking systems. Coexist or replace.

AFRICA

M-Pesa · Airtel Money.

Mobile money rails for Africa expansion. USSD payment channel on the roadmap.

INDIA

UPI · NACH · NEFT · IMPS.

India payment rails. RBI PA/PSO reporting. Aadhaar eKYC on the roadmap.

IDENTITY

UAE Pass · Kenya Huduma · eIDAS 2.0.

Regional digital identity wallets, region-by-region.

API SURFACE

Versioned. SDK-backed.
Sandbox-first.

Every Micro AI is reachable via the same API surface. SDKs are first-class — not afterthoughts. Sandbox access is granted with the first demo.

01

Protocols

REST · GraphQL · Webhooks · SSE.
REST for transactions. GraphQL for complex queries. Webhooks for event subscriptions. SSE for live streams.

02

Auth

OAuth 2.0 · OIDC · mTLS.
OAuth 2.0 for clients, OpenID Connect for federated identity, mTLS for service-to-service.

03

SDKs

iOS · Android · JS · Python · Java.
Five first-class SDKs maintained alongside the API. Generated from the same OpenAPI spec.

DEPLOYMENT OPTIONS

Private cloud or on-prem
for regulated firms.

01

Private cloud

Dedicated tenancy — dedicated infrastructure in your chosen region. Available on AWS, Azure, or GCP.

02

On-premise

In your data centre — for regulated firms whose supervisor requires it (for example DIFC, ADGM). Scoped per engagement.

Brief your CTO in 60 minutes.

We’ll walk your engineering team through every layer of the stack, answer architecture-review questions on the record, and provide a written architecture brief afterwards.