Coreal.
Book a working session →
01Platform

A control plane,
not a “stack”.

One financial ledger, one workflow engine, one identity layer, one payments backbone — wrapped in operator tools, real-time monitoring and a journaled AI layer. Every transaction is reconciled. Every decision is logged. Every flow is auditable.

SCHEMA · CTRL-PLN/V3● live
ChannelsPrimary telco app · Regional telco app · SME · Console
Operator workspace + AI orchestratorcases · journals · approvals
BPM — workflowsonboarding · review · disputes · settlements
Core banking — double-entry ledgeraccounts · postings · treasury · recon
Compliance perimeter — KYC · KYT · AMLOCR · liveness · sanctions · travel-rule
Provider gatewaybanks · PSPs · BaaS · CASP · schemes · SEPA
02Modules

Each module ships with its own contract, its own metrics,
and its own incident runbook.

CB-01module

Core Banking & Ledger

Hierarchical accounts, customer subaccounts, double-entry postings, balance history, blocked amounts, currency & rates. Audit-grade by default.

Throughput
14.2k tps
Drift
0.00 bps
WL-02module

Wallet & Mobile Backend

Transaction feed, balances, virtual cards, IBAN, SEPA, add-money, card-to-card, internal transfers, QR. Telco-aware identity.

Cards issued
100k
ARPU
$25
PG-03module

Payment Orchestration

Provider gateways: card issuer, payment acquirer, ACH / Open Banking provider, custody, schemes, SEPA. One contract, swap providers without touching the ledger.

Live providers
12
Failover p95
< 200ms
Idempotency
100%
BPM-04module

BPM & Workflows

Stateful process engine. Onboarding, KYC step-up, withdrawal approval, AML cases, card issuance, dispute handling.

Processes live
38
Avg cycle time
38s
Manual review SLA
< 4h
KYC-05module

KYC / KYT / AML

OCR, liveness, sanctions, PEP, KYT on crypto in/out via specialist provider. Tiered KYC, manual review, regulator evidence pack.

Auto-pass rate
88%
Sanctions sources
14
Case median
12 min
AI-06module

AI Orchestrator

Bounded-authority AI for ops: suggestions, not decisions. Human gates, replay, journaled actions, checkpointed state.

Cases assisted
1.4k/wk
Override rate
7%
IAM-07module

IAM & SSO

OAuth-based IAM. RBAC + ABAC, OAuth clients per tenant, role separation between Fin / BPM / Accounting / KYC / Treasury.

Tenants
6
Roles defined
42
MFA coverage
100%
OBS-08module

Observability & Audit

Replayable event log on AWS SQS/SNS. Decision journals, immutable audit trail, regulator evidence on demand.

Retention
7 yrs
Replay window
OPS-09module

Operator Workspace

One UI for payment ops, compliance, treasury. Cases, queues, journals, escalations. The cockpit your team actually opens.

Personas
3
Inboxes
11
03A request, end-to-end

One card auth, every hop, real timing.

Real production numbers from a Wave-1 Coreal deployment. Every hop is journaled with a reason code; the same trace is what an analyst sees when investigating any single transaction in the operator workspace.

HOP
SERVICE
WHAT IT DOES
p50
ISO-8583 IN
Provider gateway
Auth-request lands at the gateway over the scheme webhook. Idempotency-key required at the boundary; duplicates dedupe immediately.
12 ms
AUTH SERVICE
Wallet service
Validates the auth against open card state, the customer subaccount tree, and the active scheme rules. No state is held outside the service.
28 ms
RISK + TIER
Risk gate
Tier limits, velocity, KYT pre-flight if the merchant flagged high-risk MCC. Returns yes/no with a reason code, journaled.
14 ms
LEDGER POSTING
Core ledger
Double-entry write: Dr customer:available · Cr customer:blocked. The block carries the auth-id, scheme-ref, MCC and expiry.
18 ms
AUTH RESPONSE
Provider gateway
Approve / decline returned to the scheme. p95 end-to-end < 80 ms; target 50 ms under normal load.
8 ms
END-TO-END
p95 target
full authoriser including risk + balance check
< 80 ms
04Stack

Every named technology, with a reason.

No marketing names, no abstraction. The senior architect on the other side of the table needs to know what we run, what version, and why we picked it over the obvious alternative. Here it is.

LAYER
COMPONENT
WHY THIS AND NOT ALTERNATIVES
Ledger
PostgreSQL 16, double-entry constraints in-DB
ACID + RLS for tenant isolation; ledger correctness enforced at storage, not at application
Streaming
Kafka 3.7 with tiered storage
Replayable event log; 7-year retention without queue cost spiralling
BPM
Camunda 8.5
Versioned process definitions; the regulator can read the BPMN, not just our explanation of it
IAM
OAuth2 + OIDC, custom RBAC/ABAC
Per-tenant clients; role separation enforced at token, not at application code
Custody
Fireblocks (MPC)
Coreal holds the policy layer, never raw key material
KYT
Chainalysis + TRM
Two providers; results must agree on high-risk before a posting clears
Observability
OpenTelemetry → Grafana + Loki
Decision journals are first-class telemetry, not log lines
Runtime
Node 20 (BFF), Spring 6 (services), Rust (matcher)
Right tool per layer; ledger services in JVM for memory safety + ecosystem maturity
05Shipped · running · auditable

Seven products, in production.

Each system below runs on the same control plane — same ledger, same BPM, same KYC perimeter, same operator surface. Each one with a live ledger, audit trail and incident history we can show under NDA.

· LIVE · 2026-04 ·
P1 · Banking OS / Neobank

Neobank Super Wallet

Consumer mobile wallet on a double-entry ledger. IBAN issuance, Visa card issuing, multi-chain custody, fiat/crypto switching, SEPA rails and full KYC/KYT.

IBANVISASEPACRYPTO
LIVE
EU + UK
UPTIME
99.99%
TPS
10k
P2 · Banking OS / BaaS

Core Banking Platform

Multi-tenant banking infrastructure. Fincore backend, accounting, treasury, BPM workflows for money movement, sponsor-bank controls and on/off-ramp rails. White-label-ready.

LEDGERBPMTREASURYWHITE-LABEL
TENANTS
Multi
REGION
UK + EU
MODE
BaaS
P3 · Trading OS / Terminal

Multi-Chain Trading Terminal

Unified crypto execution surface across Solana and EVM chains. Wallet import, limit orders, watchlists, copy trading, anti-MEV runtime guards and embedded payment cards.

EVMSOLANACOPYRWA
TPS
10k
CHAINS
4
GUARDS
Anti-MEV
P4 · Trading OS / Hedge Fund

AI Consensus Hedge Fund

Multi-exchange consensus with minimum-consensus order gate, ML scoring and anomaly detection. HWM performance fee, automated risk budget, trailing stops — investor-visible P&L with audit trail.

CONSENSUSML GATEHWMAUDIT
SHARPE
4.67
EXCHANGES
4
HWM
5%
P5 · Wealthtech / Brokerage

Neobroker

Multi-asset retail investment app with broker integration, bank linking, fractional shares, auto-invest, MiFID II best-execution reporting and regulated onboarding.

BROKEROPEN BANKINGMIFID IIT+1
USERS
12k+
COST
$0 comm
REG
MiFID II
P6 · Compliance / KYC · KYT

KYC / KYT Platform

Graph-based transaction monitoring with wallet risk scoring, real-time alerts, tiered verification, OCR + FaceID, ML + rule-engine AML, PEP/sanctions screening and SAR filing.

OCRFACEIDPEPSAR
SPEED
91% faster
CYCLE
48h → 4h
OUTPUT
SAR-ready
P7 · Wealthtech / Advisory

Roboadviser 4.0

Values-aligned advisory with SEC-registered flows, curated collections, broker integration, mean-variance and Black-Litterman allocation, suitability-gated positions and goal-based planning.

SECBLACK-LITTERMANREBALANCE
ROI
+18%
RATING
4.5
REG
SEC
· NEXT BUILD ·

Your system, on the same rails.

Each of these started as a four-hour discovery brief. Map your perimeter — postings, providers, controls — and we'll show you what's already built and what's bespoke.

Book a working session →
06Tenant model

One incident.
One box.

Each licensed entity — primary telecom OpCo, regional telecom OpCo, EU EMI and a CASP perimeter — does not share tokens, secrets, environments or audit logs. Crypto risk cannot leak into telco wallet posture. Period.

Partner-led, primary market
Primary telco · OpCo
· Local wallet· Top-up & utilities· Family pay
tokens · isolatedlogs · isolated
Local PI / EMI
Regional telco · OpCo
· Regional wallet· SME QR· Remittance
tokens · isolatedlogs · isolated
EEA passport
EU EMI
· IBAN / SEPA· Cards· Diaspora flows
tokens · isolatedlogs · isolated
MiCA
CASP — ring-fenced
· Custody-light· Off-ramp· KYT + travel-rule
tokens · isolatedlogs · isolated
07Integration footprint

What Coreal touches.
What it never touches.

A CTO signing off on this integration needs one thing to be true: Coreal has read access to the signals it needs, write access only to the ledger it owns, and zero access to BSS billing balances, OCS quotas or subscriber records outside of consent scope. That is the contract. Here is exactly what it looks like.

TELCO SYSTEMS · READ SURFACE
BSS / CRM
Subscriber identity · SIM data · plan tier · payment history
Read-only API · consent-scoped · no write access
Billing / OCS
Real-time charging triggers · recurring payment mandate · usage events
Event subscription · idempotent ACK · no balance mutation
Identity / IAM
SIM-bound auth · biometric session tokens · device fingerprint
OAuth token bridge · telco IdP as upstream IDP · short-lived JWTs
Retail / Agent network
KYC support flow · cash on/off-ramp · SIM swap alerts
Webhook inbound · operator workspace case routing
Network / OSS
Roaming status · SIM age · recharge velocity (risk signals)
Consent-gated read feed · PII masked in transit
COREAL LAYER · WRITE SURFACE
Ledger API
Double-entry postings, balance queries, balance locks — the only write surface that touches money
Provider gateway
Card issuer, payment acquirer, SEPA, KYC, KYT — behind a single typed adapter contract
BPM engine
Process definitions, case journals, human gates — each step versioned and replayable
Operator workspace
Cases, queues, reconciliation — the only UI the telco ops team needs on day one
IAM perimeter
Tenant tokens, RLS predicates, cross-tenant boundary enforcement — audit log for every access

No BSS writes

Coreal never writes to the telecom BSS or OCS. Billing and subscriber record ownership stays with the operator. The integration is read + event, never mutate.

Consent-gated signals

SIM data, recharge velocity and device signals are accessed under explicit subscriber consent, scoped to the fintech product. Consent is revocable, logged and auditable.

One-day integration

The integration surface is designed to land in a single sprint. Standard OAuth OIDC for identity, webhook subscription for billing events, REST for ledger queries. No mainframe work required.

08Deployment models

One of three models.
Zero BSS changes.

The single most common CTO question: “does this replace our billing system?” The answer is no — not for any of the three models. Mode 1 (billing-adjacent) is explicitly read-only on the operator stack. Modes 2 and 3 are fully separate legal and technical perimeters. Your billing runs as it always has.

DEFAULT · TIER-1 MOBILE
30 days
Wave-1 to live

Billing-adjacent

No BSS writes. Ever.

Coreal subscribes to the billing event bus. It reads charging triggers, recharge events and plan-tier changes — and responds by posting to its own ledger. The BSS/OCS is never touched on the write path. Integration lands in a single sprint.

Operator owns
BSS / OCS — unchanged
Subscriber records
Billing balances
OCS quotas
Coreal owns
Wallet ledger
Card stack
Compliance perimeter
Operator workspace
OPERATOR BRAND · SPV
90 days
Wave-1 to live

Partner-led JV

Your brand. Your equity. Our rails.

A separate legal entity — operator-named — holds the financial product. Coreal contributes the regulated entity, ledger infrastructure and tech ops. The operator holds the majority stake and brand. Standard governance: operator CFO has board seat.

Operator owns
Brand on product
Majority equity in SPV
Distribution channel
Customer relationship
Coreal owns
Regulated entity
Ledger & tech ops
Compliance perimeter
Staffing
EU PASSPORT · LICENSED
60 days
Wave-1 to live

White-label EMI

EU licence. Partner skin. Fast.

Coreal issues wallets, IBANs and cards under its own EU EMI licence — branded end-to-end as the operator. No separate legal entity required. Fastest path to a compliant EU wallet product without licence acquisition.

Operator owns
Brand & UX skin
Distribution
Customer onboarding
Coreal owns
EMI licence
IBAN issuance
Card programme
Compliance & AML
BSS COMPATIBILITY · MODE 1 (BILLING-ADJACENT)
BSS PLATFORM
INTEGRATION SURFACE
COREAL CONNECTOR
EFFORT
Amdocs Kenan / OSM
Billing event webhook · subscriber API
Native Kafka connector + REST adapter
Config only — no code
Ericsson BSCS · CBIO
Online charging trigger · subscriber profile
DIAMETER Ro interface bridge → Kafka
1 sprint integration
Netcracker OSM / BSS
Order event bus · charging notification
Netcracker API gateway adapter
Config only — no code
Optiva Focis
Real-time charging event · plan-tier data
REST polling → internal event stream
1 sprint integration
The integration guarantee — mode 1

Coreal subscribes to billing events. It does not post to them. No write path touches the BSS, OCS or subscriber record store. The integration can be reverted in a single config change — there is no schema migration, no stored procedure, no mainframe patch. If the operator wants to disconnect, they remove the event subscription. Coreal stops receiving data. The billing system is untouched.

09Verticals

What this platform ships.

Eight production fintech verticals run on the same control plane. The architecture above is not abstract — it shows up as these concrete products.

See full Minctrl catalogue →