Fintech
money that moves,records that match
Payment flows, wallets, and regulated platforms where the charge, the ledger, and the audit trail agree. Built by the engineer who also runs them in production.
Illustration: sample payments moving from charge to ledger to audit log, each ending as matched.
- authenticated payments a day
- 500+
- active users on a financial platform
- 3M+
- venues on one payments engine
- 5
- infrastructure cost after migration
- −35%
01 · The hard part
Where fintech builds go wrong
Moving money is the easy part. The work is everything around the charge that has to stay correct afterward.
The charge and the record drift apart
Stripe, the app database, and the CRM each hold a copy of the same payment. When they disagree, support finds out before engineering does.
Sessions expire at checkout
A token that lapses between the cart and the charge turns into a failed payment and a customer who does not come back.
New platforms beside old identity
Regulated businesses rarely get to replace the directory they already run. The new system has to live next to it until cutover.
Reporting competes with checkout
A finance query on the live store slows the payment path. Analytics needs its own copy, so a dashboard cannot block a transaction.
02 · What I build
Solutions that shipped
Three kinds of financial work I have shipped and kept running, each tied to the project it came from.
Payment engines and marketplaces
Stripe for direct sales, Stripe Connect when money moves between users on the platform. One engine can serve several branded storefronts.
- Stored cards on the processor
- Gift certificates, credits, promo codes
- Connect invoicing and transfers
- Subscriptions and recurring billing
- Wallet modules
- Typed API clients with token refresh
Authenticated payment portals
Customers sign in, see what they owe, and pay. Staff hear about it without anyone forwarding an email.
- Cognito sign-in
- AppSync GraphQL API
- Lambda payment workflows
- DynamoDB records
- Trust Commerce processing
- Automated staff notifications
Regulated platforms on Azure
Hybrid builds that sit beside an on-premise directory, keep sensitive columns encrypted, and route every call through one gateway.
- Azure SQL with Always Encrypted
- Azure AD alongside on-prem AD
- API Management policies and throttles
- Key Vault for secrets
- App Service hosting
- Staged cutover plan
03 · Stack
The tools behind the work
The tools behind the projects above. Chosen per product, not carried from one build to the next out of habit.
Payments
- Stripe
- Stripe Connect
- Trust Commerce
Backend & APIs
- Node.js
- NestJS
- Django
- GraphQL
- AppSync
- PostgreSQL
Identity & secrets
- Cognito
- Azure AD
- JWT
- Key Vault
- API Management
Infrastructure
- AWS Lambda
- DynamoDB
- AWS SAM
- Azure App Service
- CloudWatch
- GitHub Actions
04 · Security & compliance
Built in, not bolted on
Controls built into the system from the first sprint, so a security review reads the code instead of a remediation plan.
Card numbers stay with the processor
Stored cards are processor references. The app database never holds a card number.
Encrypted where it is stored
Sensitive columns use Always Encrypted. The database can store what it cannot read.
Secrets out of the repo
Keys and connection strings live in Key Vault or the cloud's secret store, never in config files.
One identity provider
Cognito or Azure AD owns sign-in, so there is one place to enforce MFA and revoke access.
Least privilege and an audit trail
Scoped roles per service and a log of who touched what, the evidence reviewers ask for.
One gateway for every call
Throttles and policies live at the API gateway, not copied into each service.
These are engineering practices, not certifications. PCI DSS, SOC 2, and similar attestations come from your auditor; the system is built so that review goes faster.
Building something that moves money?
Tell me what the product charges for and where the money goes. I will come back with how I would build the payment path and what it would take to run it.