Coreal.
Book a working session →
01Company

We build the
boring infrastructure
everyone else assumes already exists.

And then we built the machine that builds it.

Founded in London in 2016, Coreal works with telcos, banks, exchanges and regulated fintechs that need a fintech operating system they can show to a regulator without flinching.

Coreal group — coreal.io regulated infrastructure + minctrl.com AI-native workflow builder. Two products, one team.

OPERATORS SHIPPED
8
TIME TO WAVE-1
90 days
PRODUCTS · LIVE
7
02The group

Two products. One team.
One builds things. The other runs them.

COREAL.IO · REGULATED INFRASTRUCTURE
Founded 2016

The platform
that runs.

Regulated fintech infrastructure for telcos, banks, and licensed fintechs. Core banking ledger, wallet stack, KYC/AML, payment orchestration, BPM engine — everything audit-grade and regulator-ready out of the box.

Double-entry core banking ledger
Wallet · cards · IBAN · SEPA
KYC / KYT / AML perimeter
EU EMI passport · telco-billing-adjacent
Operator workspace + AI orchestrator
MINCTRL.COM · AI-NATIVE WORKFLOW BUILDER
minctrl.com →

The machine
that builds.

The AI-native workflow builder for regulated operations: a tiered pipeline of Claude agents — Opus for judgement, Sonnet for steps, Haiku at runtime — executes a process end-to-end, while a governance layer of risk-tiered gates and a tamper-evident audit trail decides when a step pauses for human sign-off. Used internally to build and run Coreal. Now available externally.

3
AGENT TIERS · OPUS/SONNET/HAIKU
7
GOVERNED STAGES
2
VERTICALS · FINTECH + TELECOM
<$0.30
PER GOVERNED RUN
6
ARTEFACTS PER RUN
14
COMPLIANCE FRAMEWORKS

Minctrl is the AI-native workflow builder we run internally to build and operate Coreal — and now available to regulated teams externally. When you commission a Coreal integration, Minctrl is what's running behind the human team. minctrl.com →

03Proof — partner outcomes

Numbers from the
actual deployments.

We don't show operator names — partner agreements come first. The numbers below are anchored to public filings or already-published engineering field notes. The links lead to the long-form versions in /insights.

TIER-1 EU/CIS MOBILE · 15.4M subs

Wave-1 corridor live in 87 days

Users on Day-90
100k
Cumulative volume
$20M
Reconciliation drift
0.00%
BSS write-path
zero
KEY SIGNAL

Read-only on the operator's billing event bus. Reverts in a single config change. The CTO's biggest concern — "you're replacing our billing system" — answered by design, not by promise.

Read the full field note →
TIER-1 EU/CIS · FY2025 ANALYSIS

Year-3 uplift target +23–28%

Service revenue base
€620M
Wallet attach (Y3)
62%
X-border attach (Y3)
28%
Wave-1 → 3 plan
36 months
METHOD

Anonymous read of public FY2025 filings — operating profile, ARPU, OIBDA margin, capex intensity — translated into a defensible wave-by-wave deployment plan.

Read the analysis →
AI-AGENT BANK · BETA

EU AI Act–compliant from spec

Agent identity
W3C DID
Sanctions / KYC
tiered
Compliance pack
auto-gen
Mandatory gates
2
BETA · EXPERIMENTAL

A regulated bank pipeline where the customers are AI agents themselves. Mandatory EU AI Act + DORA gates run inside the build, not after. Currently in closed beta with two design partners.

Explore at minctrl.com →

Operator profiles anonymised. Numbers anchored to public FY filings, EU mobile sector reports and our own engineering field notes. Reference checks on request, under NDA.

04Why now / Why us

The window is regulatory,
not theoretical.

● WHY NOW

Three forces converged in 2024–2025.

  • DORA enforcement
    ICT risk evidence is now mandatory across financial entities. Audit trails are no longer best-effort.
  • MiCA live
    Crypto + traditional payment perimeter is finally one regulatory frame. Ring-fenced CASP architecture is shippable.
  • AI agents pass mandatory gates
    STRIDE + CWE checks now run inside the build pipeline, not after. Compliance shifts left, by design.

EU telcos sit on €600B+ in service revenue. Embedding finance no longer requires acquiring a banking licence — and the regulator finally has the framework to read the result.

● WHY THIS APPROACH

Three options usually fail. Coreal is option #4.

  • Hire a consultancy
    €2M, 18 months, no IP transferred. The slides survive; the code rarely does.
  • License a vendor stack
    Cheap upfront, but you don't own the ledger. Vendor lock-in becomes a regulator finding.
  • Build it yourself
    3+ years. First DORA audit lands before the second deploy. Bus factor of 1.
  • Coreal: own everything from day one
    Code · tests · audit log · ADR — the operator owns each Minctrl artefact. Not a black box you rent.
05How we approach a build

The work, in five phases.

5 ENGAGEMENT PHASES · APPLIED PER MINCTRL PIPELINE BUILD (NOT TO BE CONFUSED WITH THE 9 PIPELINE STAGES BELOW)

P1

Perimeter

Map flows, postings, providers, controls. Write the brief.

P2

Ledger design

Double-entry posting model. Idempotency. Reconciliation.

P3

Provider contract

Banks, PSPs, BaaS, schemes — behind one gateway.

P4

Operator surface

Cases, queues, journals. The cockpit your team uses.

P5

Hardening

SRE · DR/BCP · pentest · DORA-ICT · regulator dry-runs.

06Leadership

Led from London
since 2016.

The pipeline runs deterministically. The decisions don't. A senior operator approves every Minctrl stage before the next one starts — two of those gates (Security · Compliance) are mandatory and cannot be skipped.

M.T.CEO
M. TYMOSHENKO · CEO · COREAL
“We watched three telco × bank JVs collapse in the EU between 2018–2022. Always the same pattern: vendor consortium, no clear ledger ownership, regulator can't reconstruct flows. Coreal is what we wished existed for those projects.”

Telecom CFO → fintech operator → built Coreal in 2016 to stop watching the same integration fail every two years. Read the field notes →

07Compliance posture

We treat compliance
as a feature.

Three lines of defense, written down — and enforced in every Minctrl build via a mandatory security gate. Risk register predates the codebase. Regulator evidence on demand.

ISO 27001
In progress · audit Q3 2026
SOC 2 Type II
Continuous monitoring
PCI-DSS L1
Via card partners
DORA-ICT
Roadmap aligned
GDPR
DPIA per flow
MiCA-readiness
Ring-fenced CASP arch
08How we ship

An AI agent workforce,
governed on the risky steps.

GOVERNED FLOWS FOR FINTECH + TELECOM — ONE 7-STAGE GOVERNED PIPELINE.

Our delivery runs on Minctrl — the AI-native workflow builder for regulated operations. A tiered pipeline of Claude agents (Opus for judgement, Sonnet for steps, Haiku at runtime) executes a process end-to-end, with a tamper-evident audit trail a regulator can read.

A governance layer — risk-tiered gates and calibrated confidence — decides exactly when a step pauses for human sign-off. The high-risk steps never run unattended; a human owns the decision, the agents own the execution.

Every run leaves six artefacts: a tamper-evident audit trail · execution graph · run console · Kanban board · wiki · analytics dashboard.

PIPELINE
7 stages
AGENT TIERS
3
HUMAN SIGN-OFF
risk-tiered
PER GOVERNED RUN
<$0.30
ARTEFACTS
6 / run
VERTICALS
2
MINCTRL · GOVERNED RUN
1design2validate3rungate5park6resume7audit
Claude OpusDesignFintech · KYC/AML

Model the process once — steps, data, risk tiers, and which gates apply.

Audit trail
Empty — step the case to build the trail.
6 ARTEFACTS PER GOVERNED FLOW · AUDIT TRAIL IS ONE OF SIX
Audit trail
Tamper-evident
Execution graph
Every step + branch
Run console
Live run state
Kanban
Cases + queues
Wiki
Auto-generated docs
Analytics
Flow metrics

The audit trail comes automatically. Not a checkbox — an artefact, per governed run.

COMPLIANCE FRAMEWORKS · BUILT INTO EVERY PIPELINE
EU AI ActDORAMiCAMiFID IIAML5/6GDPRNIS2PSD2SOC2ISO27001BaFinFCATFReIDAS 2
WHAT A PARTNER BUILD LOOKS LIKE

Governed from day one

Every flow runs behind risk-tiered gates. The DORA evidence a regulator asks for is generated as you operate — not reconstructed after the fact.

Human on the risky steps

Agents execute; a human owns every high-risk decision. Calibrated confidence decides when a step pauses for sign-off — nothing critical runs unattended.

No black box

Audit trail, execution graph, run console — all yours. Replay any run and see every judgement and override; you own the record, not rent an opaque service.

09What Minctrl ships

Fintech and Telecom.
Governed the same way.

Coreal runs Minctrl across the two verticals it operates in — fintech and telecom. These are the flows we run most, each carrying production-grade domain knowledge — FIX protocol, MiFID II, KYC/AML, PSD2, DORA, and telecom billing / BSS. Every flow runs the same 7-stage governed pipeline, with a tamper-evident audit trail a regulator can read.

● FINTECH + TELECOM13 FLOWS
full catalogue at minctrl.com →

Each pipeline carries production-grade domain knowledge: FIX protocol · MiFID II · KYC/AML · PSD2 · DORA.

10What comes next
NEW · BETAEXPERIMENTAL

A regulated bank
where AI agents
are the customers.

The ai-agent-bank pipeline (via Minctrl) ships a full design including DID-based agent identity, agentic KYC, stablecoin payment rails, and multi-sig governance — with a mandatory EU AI Act + DORA compliance pack generated automatically.

What comes after neobanks for humans. The infrastructure for the agentic economy — built on the same ledger, same compliance perimeter, same audit trail as everything else we ship.

ONE OF MINCTRL'S FINTECH FLOWS — AND THE ONLY ONE WHERE THE CUSTOMERS ARE AI AGENTS.

🪪
Agent Identity

W3C DID + Verifiable Credentials for every AI agent. did:web primary, eIDAS 2.0 wallet.

🔍
Agent KYC

Tiered onboarding: model fingerprint → capability proofs → behavioural monitoring.

Payment Rails

USDC / EURe stablecoin + CBDC adapter + SWIFT fallback. IVMS101 Travel Rule built in.

🛡️
AI Risk Engine

6 AI-specific scenarios: prompt injection, runaway loop, hallucination, capability creep, model drift, supply-chain.

⚖️
Multi-sig Gov.

m-of-n threshold-sig over agent decisions. Timelock. Append-only audit log. Kill-switch.

📋
EU AI Act ready

Mandatory compliance review: Articles 6, 9–15. DORA ICT risk. MiCA. AML5/6. Evidence pack generated.

11Book a session

The calendar
doesn't lie.

Bring a flow, a ledger question, a license puzzle, or a regulator letter. In four hours we map the perimeter, the postings, the providers and the controls. You leave with a written brief — not a sales deck.

NEXT WORKING SESSION
Hosted from London,
remote rooms worldwide.

FORMAT
4 hours
OUTPUT
Written brief
COST
No fee
RECIPIENT
Architect · Risk · Founder

71-75 SHELTON STREET · LONDON WC2H · COVENT GARDEN