Financial Technology In development. Not operating. Confidential commission. Client, business model and product design withheld.

Regulated Financial Services Estate

A client asked us to build a regulated financial services estate on Technology DNA, with no off-the-shelf core system underneath it. This is the heaviest set of obligations we have carried. The client permits us to describe our engineering practice. The client withholds their name, their business model and their product design, and those items cover some of the most complex parts of the build. This page describes the part that transfers to any organisation with heavy obligations.

Two points of accuracy. The estate is in development, and it does not operate. A regulated financial services business needs FCA authorisation to operate, and the client is working towards that. Separately, software work is not a regulated activity in the UK. The FCA and the PRA regulate the operation of financial services, and they do not regulate the software builder. Anyone planning a complex financial technology commission should note that distinction.
229
Named acceptance tests, re-checked on every change
TRL 8
System complete and qualified, on the Innovate UK scale
2 years
Simulated operation, reconciled daily at zero divergence

What Technology DNA Supplied

One division runs through the estate. Technology DNA supplies the machinery that every application inherits by contract, and the client's own rules sit on top as application software.

The DNA runs on engage.re, in production since December 2025. On the Technology Readiness Level scale used by Horizon Europe and Innovate UK, it sits at Level 9. It supplied the following on day one.

  • A signed record. Every change is a signed, time-stamped event, chained to the event before it. The queryable database is a replayable projection of that log. No operator, host or administrator can insert, alter, reorder or delete history without breaking the chain, and a verifier checks the chains continuously in production.
  • One access gate. Every request passes exactly one authorisation decision. Access arrives as a signed, scoped grant that the owner can cancel, and the cancellation takes effect on the next call. Every authorised access is itself a recorded event.
  • Custody by cryptography. Each participant holds their own keys, so the gate and the keys enforce data sovereignty instead of a contract clause.
  • Personal data machinery. Per-record encryption, erasure by key destruction, declared retention classes, and legal hold.
  • Outcome measurement. Every domain emits a subject-free fact for each change. The fact carries the kind of thing, the amount, the place and the time, and it never carries a name, the content, or the person concerned.
  • Sealed messaging. The sender's device seals private message content per recipient, and the operator cannot read it at any point.

Read Technology DNA in full on the engage.re project page.

Records a Supervisor Can Rely On

A regulator asks for orderly records, held for years, in a form that lets it reconstruct each stage of a transaction. This estate meets that by construction instead of by procedure.

Every material decision writes a decision record, and that record carries its reviewer, its rationale and its case linkage. Where software assists a decision, it records its version, its inputs and its outputs as signed events, so any assisted decision reproduces by replay. No adverse decision completes without a named human reviewer.

The estate audits read access at institutional volume. Staff access to a customer file is answerable per customer: when, who, and under which authority. Full detail is retained for writes, for denials and for sensitive scopes.

Every record class carries a declared retention class. The platform refuses deletion before expiry, and it records the release at expiry. A legal hold suspends deletion outside any schedule, under recorded authority. Accelerated-clock tests verify the enforcement logic, so a long-horizon rule proves itself now.

Connect with us about your project. Message on WhatsApp Replies within 24 hours

Staged Permissions

A regulated firm's permissions change shape as it moves through authorisation. This estate encodes that journey.

A stage record gates every service line in the server, and the operations team switches a service on at exactly the tier the regulator has approved. Where a stage carries a numeric constraint, the server enforces that constraint at the point of action and displays the remaining headroom.

A move up a tier is a ceremony rather than a setting. Two authorised officers must act separately, and they attach the authority document itself as evidence. The estate records every change with who, when, and under what authority.

One read-only screen then shows every service line, its current stage and mode, the evidence reference, the next milestone, the remaining headroom and the full transition history. The firm and its supervisors can see every live service line on one screen.

Figures that regulation moves are configuration rather than code. One value renders everywhere, so a change in the rules becomes a data change.

Switching a Service Off

Switching a service on is half of readiness. The other half is switching it off mid-operation, with customers in the loop.

Each service line carries a service mode alongside its stage: open, closed to new business, run-off, or suspended. A reduction in service takes effect immediately on one authorised instruction, with the reason recorded. A restoration requires the full two-officer ceremony. A requirement to stop new business therefore takes effect, and produces its evidence, within minutes of receipt.

No mode at any stage can block one protected class of operation. That class covers a customer's access to their own money, their own records, their complaints and their rights. The software cannot cut a person off from what belongs to them.

Every reduction in service also opens a transition workbook. That workbook lists the customers in flight and applies recorded dispositions, each with its communication. The estate abandons nothing, and every disposition leaves a record.

Obligations as Enforced Software

Each obligation with operational content runs as enforced workflow instead of sitting in a procedures manual.

  • Gating ceremonies. The server refuses to progress a journey without the prescribed disclosure and declaration. Regulation prescribes some wording, and tests pin it exactly.
  • Registers with controlled surfaces. A public surface cannot show unapproved material, and a withdrawal takes effect on the next load.
  • Notice clocks. Clocks enforce advance-notice periods before a change takes effect, in a durable medium.
  • Daily reconciliation. Reconciliations run daily to zero tolerance, and each day's result files as a record. Discrepancy escalation runs on its own clock.
  • Sensitive handling. A coarse flag reaches serving staff and the detail stays under restricted scopes. Staff surfaces then prompt the recorded adjustments.
  • Structural separation. Static gates on every build stop one part of the estate initiating actions that belong to another part.

Outcomes Measured From Live Records

A regulator asks a firm to monitor and evidence the outcomes its customers receive, and to find any group receiving worse outcomes. This estate measures that from live records instead of assembling the figures from management reports.

Every figure computes from live records, segmented by product, by area and by vulnerability, and every figure drills to the exact records it counts. A deterministic test estate with known expected figures verifies the measurement machinery.

The board report composes from the same queries that the dashboards run, so an assessment is a dated reading of live data. A group faring worse becomes visible directly, because the platform counts every change exactly at every level of aggregation.

Governance and Accountability

  • Accountability as live registers. The estate maintains senior appointments, statements of responsibility and the responsibilities map as records, and it flags any unallocated responsibility. Certification runs as an annual workflow, and a lapsed certification suspends the holder's system authority until renewal.
  • Roles are capabilities. Each role is a set of scoped grants that the firm can cancel, enforced at the server on every operation. Least privilege proves itself, and the estate records every denial.
  • Regulator access, mechanised. Supervisory access arrives as a scoped read capability. The grant binds to the engagement, it expires, and one recorded act cancels it. Every access logs and attributes. The property that prevents falsification also guarantees faithful production, so what the firm produces to a supervisor is verifiably what it recorded.
  • Third parties on the record. The third-party register holds each material provider. Each entry carries due-diligence evidence, a sub-processor chain, an exit plan and a review date.

Resilience and Deployment

The estate registers its important business services with impact tolerances, and it generates dependency mapping from the platform's own architecture documentation. Scenario test results become records with owners and due dates. Incident management runs as a workflow, and a notifiable incident cannot close without a post-incident review.

Drills produce the recovery time and recovery point figures. Each figure states the deployment and load of its measurement, and it cites the drill run that produced it. Because the signed chain is the record, a restore verifies itself: the recovered store replays and matches.

The target deployment is a single-tenant instance of the graph in the client's own estate. The client's data sits under the client's keys, hosted where the client chooses, and no standing vendor administrative access exists. Sense Future signs and versions each engine release, and a published conformance suite proves a deployment correct.

The estate also deploys at any point in the authorisation journey. Stages and modes govern what a customer can reach, and the deployment itself governs nothing. A deployed system with every line switched off is a compliant, inert system.

How We Proved Readiness

Every capability carries named acceptance tests. Every phase closes with a proof suite and a signed report. The security properties re-prove themselves continuously in production.

  • 229 named acceptance tests across the estate's completion programmes, each re-checked on every change.
  • Recorded golden snapshots of all 61 graph operations and 39 query types, under a zero-difference policy on every change.
  • Accelerated-clock tests of every time-based rule, so a long-horizon obligation proves its enforcement logic now.
  • Access-control and boundary regression suites on every commit. An adversarial suite also speaks to the system as a hostile caller does.
  • A generated reachability matrix and scripted operating-day runs per role, so every capability is reachable and operable in the shipped applications.
  • Two simulated years of operation at the permitted scale. The whole population's state reconciled every simulated day against independent models, at zero divergence, with faults injected at every seam.
  • Drilled ceremonies for restore, failover, switch-off and exit, with the evidence filed.
What only operating time can produce. We separate the two honestly. We have proven the machinery. Operating history accrues only from live operation, and several things need it: filed regulatory returns, the daily reconciliation history, the annual cycles, recovery figures under sustained production load, and real-population outcome data. Each of those has its evidence surface built and armed, so the record accrues automatically. Independent certification runs on an external audit calendar that auditors control.

What ESRE Media Offers Your Sector

We build this class of estate for organisations outside financial services, and the mechanisms carry across unchanged.

A stage record and a protected operation class are general mechanisms. So are an enforced register, a notice clock, a daily reconciliation, an accountability register and a scoped regulator capability. Your sector's rules supply their content.

A care provider, a school, a charity, a recruitment agency and a local authority all carry obligations of this shape. The record, custody, access, erasure, retention, audit and exit disciplines that consume compliance budgets are properties of the graph, and Sense Future maintains them once for every participant. Your own obligations then ride on top as application work.

We build that work at whatever weight your obligations need. Where we build it wrong, we fix it at no cost and with no time limit, and the contract says so.

Tech Stack

React 18 · TypeScript · Vite · Node.js · engage.re Graph API · Key-based authentication with session timeout · Monorepo (pnpm workspaces)

Building in a Regulated Industry?

Complex compliance requirements and bespoke logic are exactly what we build for.

Get in Touch