Fintech and BFSI
Payment flows, onboarding, ledgers and reporting built so the money side is auditable and the security review is passed rather than argued.

What we build for financial services
The interesting problems in this sector are not on the screen. They are in what happens when a payment is retried, when a webhook arrives twice, when a customer disputes a charge from four months ago, and when an auditor asks how a figure in a report was produced.
Ledgers that reproduce themselves
Balances are derived from append-only entries rather than stored and updated. A statement for last quarter is recalculated from the same records that produced it at the time, which is what makes a dispute answerable and an audit short.
Keeping the security review short
Card data goes to the gateway rather than to your servers, credentials are short-lived, environments are separated in code, and access is logged. Most of a security questionnaire is then answered by showing how the system is built.
Typical engagements
The systems Tankar builds for fintech and bfsi, as deliverables rather than adjectives.
- Customer onboarding with document capture, verification states and an audit trail
- Payment and payout flows with idempotent writes, reconciliation and dispute handling
- Ledgers written as append-only entries, so a statement can be reproduced for any past date
- Lending, collections and servicing back-office systems with role-based access
- Dashboards and regulatory reporting drawn from the same records as the operational screens
- Integrations with payment gateways, banks, card networks and credit data providers
Compliance notes
The rules that shape a build in this sector and how they are handled in the system rather than in a policy document.
| Requirement | How we build for it |
|---|---|
| PCI DSS | The cheapest way to handle card data is not to hold it. Payment pages are built so card details go directly to the gateway and only a token reaches your systems, which keeps most of the standard out of scope. Where card data must be stored, the scope, segmentation and evidence are agreed with your assessor. |
| GDPR, UK GDPR and India DPDP Act 2023 | Financial records carry long statutory retention periods that sit alongside a customer's right to erasure. The data model separates what must be kept for the regulator from what must be deleted on request, so both obligations can be met. |
Representative work
Case studies relevant to this sector. Only outcomes with a source are shown.
Tell us what you are building.
NDA on request. Written estimate within 48 hours of a scoped call. Reply within one business day.
