Built like a banking system, because it is one.
Money and identity are the platform's core, so the controls are structural, not bolted on.
Standards-based identity
OpenID Connect with PKCE against a dedicated identity provider; sessions, SSO and token lifetimes managed centrally.
Deny-by-default access
Nothing is allowed unless a role explicitly permits it, and every request is checked on the server, never just in the browser.
Dual control on the risky moves
Publishing a product, taking a provider live, approving a rebalance, reversing money: always two distinct people.
Double-entry money core
A dedicated ledger records every movement twice, to the thebe, and the platform checks that the books balance all day long.
Audited, never doubled
Every change lands in the audit trail, and a retried or repeated request can never move money twice.
Tenant isolation
Each operator's data is isolated at the database itself; brands, services and partners never mix.
Your settlement bank powers the rails
The platform orchestrates the services and records every movement; a regulated settlement bank you appoint holds and moves the money on the national payment rails. Its statements are the third leg of the daily match, the ledger against provider statements against the bank, so every thebe is provable.
Dedicated instance
Your own environment, in-country where regulation asks for it: full isolation, your release cadence, your data residency.
Shared platform
Multi-tenant from day one with row-level isolation: the economical shape for smaller networks, on the same codebase and controls.
Ask us the hard questions.
Bring your security, compliance and audit teams; the controls hold up under scrutiny because scrutiny is what they were built for.
Agency One