We build the
boring infrastructure
everyone else assumes already exists.
And then we built the machine that builds it.
Founded in London in 2016, Coreal works with telcos, banks, exchanges and regulated fintechs that need a fintech operating system they can show to a regulator without flinching.
Coreal group — coreal.io regulated infrastructure + minctrl.com AI-native workflow builder. Two products, one team.
Two products. One team.
One builds things. The other runs them.
The platform
that runs.
Regulated fintech infrastructure for telcos, banks, and licensed fintechs. Core banking ledger, wallet stack, KYC/AML, payment orchestration, BPM engine — everything audit-grade and regulator-ready out of the box.
The machine
that builds.
The AI-native workflow builder for regulated operations: a tiered pipeline of Claude agents — Opus for judgement, Sonnet for steps, Haiku at runtime — executes a process end-to-end, while a governance layer of risk-tiered gates and a tamper-evident audit trail decides when a step pauses for human sign-off. Used internally to build and run Coreal. Now available externally.
Minctrl is the AI-native workflow builder we run internally to build and operate Coreal — and now available to regulated teams externally. When you commission a Coreal integration, Minctrl is what's running behind the human team. minctrl.com →
Numbers from the
actual deployments.
We don't show operator names — partner agreements come first. The numbers below are anchored to public filings or already-published engineering field notes. The links lead to the long-form versions in /insights.
Wave-1 corridor live in 87 days
Read-only on the operator's billing event bus. Reverts in a single config change. The CTO's biggest concern — "you're replacing our billing system" — answered by design, not by promise.
Year-3 uplift target +23–28%
Anonymous read of public FY2025 filings — operating profile, ARPU, OIBDA margin, capex intensity — translated into a defensible wave-by-wave deployment plan.
EU AI Act–compliant from spec
A regulated bank pipeline where the customers are AI agents themselves. Mandatory EU AI Act + DORA gates run inside the build, not after. Currently in closed beta with two design partners.
Operator profiles anonymised. Numbers anchored to public FY filings, EU mobile sector reports and our own engineering field notes. Reference checks on request, under NDA.
The window is regulatory,
not theoretical.
Three forces converged in 2024–2025.
- DORA enforcementICT risk evidence is now mandatory across financial entities. Audit trails are no longer best-effort.
- MiCA liveCrypto + traditional payment perimeter is finally one regulatory frame. Ring-fenced CASP architecture is shippable.
- AI agents pass mandatory gatesSTRIDE + CWE checks now run inside the build pipeline, not after. Compliance shifts left, by design.
EU telcos sit on €600B+ in service revenue. Embedding finance no longer requires acquiring a banking licence — and the regulator finally has the framework to read the result.
Three options usually fail. Coreal is option #4.
- Hire a consultancy€2M, 18 months, no IP transferred. The slides survive; the code rarely does.
- License a vendor stackCheap upfront, but you don't own the ledger. Vendor lock-in becomes a regulator finding.
- Build it yourself3+ years. First DORA audit lands before the second deploy. Bus factor of 1.
- Coreal: own everything from day oneCode · tests · audit log · ADR — the operator owns each Minctrl artefact. Not a black box you rent.
The work, in five phases.
5 ENGAGEMENT PHASES · APPLIED PER MINCTRL PIPELINE BUILD (NOT TO BE CONFUSED WITH THE 9 PIPELINE STAGES BELOW)
Perimeter
Map flows, postings, providers, controls. Write the brief.
Ledger design
Double-entry posting model. Idempotency. Reconciliation.
Provider contract
Banks, PSPs, BaaS, schemes — behind one gateway.
Operator surface
Cases, queues, journals. The cockpit your team uses.
Hardening
SRE · DR/BCP · pentest · DORA-ICT · regulator dry-runs.
Led from London
since 2016.
The pipeline runs deterministically. The decisions don't. A senior operator approves every Minctrl stage before the next one starts — two of those gates (Security · Compliance) are mandatory and cannot be skipped.
“We watched three telco × bank JVs collapse in the EU between 2018–2022. Always the same pattern: vendor consortium, no clear ledger ownership, regulator can't reconstruct flows. Coreal is what we wished existed for those projects.”
Telecom CFO → fintech operator → built Coreal in 2016 to stop watching the same integration fail every two years. Read the field notes →
We treat compliance
as a feature.
Three lines of defense, written down — and enforced in every Minctrl build via a mandatory security gate. Risk register predates the codebase. Regulator evidence on demand.
An AI agent workforce,
governed on the risky steps.
GOVERNED FLOWS FOR FINTECH + TELECOM — ONE 7-STAGE GOVERNED PIPELINE.
Our delivery runs on Minctrl — the AI-native workflow builder for regulated operations. A tiered pipeline of Claude agents (Opus for judgement, Sonnet for steps, Haiku at runtime) executes a process end-to-end, with a tamper-evident audit trail a regulator can read.
A governance layer — risk-tiered gates and calibrated confidence — decides exactly when a step pauses for human sign-off. The high-risk steps never run unattended; a human owns the decision, the agents own the execution.
Every run leaves six artefacts: a tamper-evident audit trail · execution graph · run console · Kanban board · wiki · analytics dashboard.
Model the process once — steps, data, risk tiers, and which gates apply.
The audit trail comes automatically. Not a checkbox — an artefact, per governed run.
Governed from day one
Every flow runs behind risk-tiered gates. The DORA evidence a regulator asks for is generated as you operate — not reconstructed after the fact.
Human on the risky steps
Agents execute; a human owns every high-risk decision. Calibrated confidence decides when a step pauses for sign-off — nothing critical runs unattended.
No black box
Audit trail, execution graph, run console — all yours. Replay any run and see every judgement and override; you own the record, not rent an opaque service.
Fintech and Telecom.
Governed the same way.
Coreal runs Minctrl across the two verticals it operates in — fintech and telecom. These are the flows we run most, each carrying production-grade domain knowledge — FIX protocol, MiFID II, KYC/AML, PSD2, DORA, and telecom billing / BSS. Every flow runs the same 7-stage governed pipeline, with a tamper-evident audit trail a regulator can read.
Each pipeline carries production-grade domain knowledge: FIX protocol · MiFID II · KYC/AML · PSD2 · DORA.
A regulated bank
where AI agents
are the customers.
The ai-agent-bank pipeline (via Minctrl) ships a full design including DID-based agent identity, agentic KYC, stablecoin payment rails, and multi-sig governance — with a mandatory EU AI Act + DORA compliance pack generated automatically.
What comes after neobanks for humans. The infrastructure for the agentic economy — built on the same ledger, same compliance perimeter, same audit trail as everything else we ship.
ONE OF MINCTRL'S FINTECH FLOWS — AND THE ONLY ONE WHERE THE CUSTOMERS ARE AI AGENTS.
W3C DID + Verifiable Credentials for every AI agent. did:web primary, eIDAS 2.0 wallet.
Tiered onboarding: model fingerprint → capability proofs → behavioural monitoring.
USDC / EURe stablecoin + CBDC adapter + SWIFT fallback. IVMS101 Travel Rule built in.
6 AI-specific scenarios: prompt injection, runaway loop, hallucination, capability creep, model drift, supply-chain.
m-of-n threshold-sig over agent decisions. Timelock. Append-only audit log. Kill-switch.
Mandatory compliance review: Articles 6, 9–15. DORA ICT risk. MiCA. AML5/6. Evidence pack generated.
The calendar
doesn't lie.
Bring a flow, a ledger question, a license puzzle, or a regulator letter. In four hours we map the perimeter, the postings, the providers and the controls. You leave with a written brief — not a sales deck.
remote rooms worldwide.
71-75 SHELTON STREET · LONDON WC2H · COVENT GARDEN