Engagement · enterprise partnership

Industry
Financial services
Solution
Blockchain · RegTech
Engagement model
Enterprise engineering partnership
Engagement length
12+ months
Market stage
Live & scaling
Team
6+ team members
Scope
End-to-end product engineering
Platform
iOS · Android · Web
100%
On-chain audit trail coverage

Every verification step generates a record written on-chain, so the evidence of a completed check cannot be edited after the fact.

Reported post-launch, across every verification step

98%
Verification layers covered in one flow

Organisation, officers and beneficial owners are all verified inside a single guided workflow rather than three parallel document exercises.

Reported post-launch, platform-wide

75%
Faster business onboarding

Invitation-driven verification with built-in guidance and real-time tracking, replacing weeks of document chasing by email.

Reported by financial institutions after launch

Context

The situation before the platform

Why a compliance function needed one verification system instead of emails, shared folders and spreadsheets.

The business

A technology provider serving financial institutions and other regulated organisations that must validate business entities, verify beneficial ownership structures and confirm authorised representatives before they can transact.

The starting point

Business verification was being held together with emails and spreadsheets. Compliance teams requested documents, someone else reviewed them, and a decision was made — often with no reliable way to confirm that what was submitted was accurate.

The trigger

Verification records lived somewhere fallible — an email thread, a shared folder, an editable internal system. When an audit or dispute surfaced months later there was no tamper-proof way to prove that verification happened, when, and who confirmed it.

What they wanted

One end-to-end ecosystem covering the whole verification lifecycle: business onboarding, identity verification, beneficial ownership disclosure, biometric officer attestation and compliance validation, with every event securely recorded.

Constraints

A legally complex process had to feel manageable to a non-compliance professional · corporate shareholders with their own ownership structures had to be verified through multiple tiers · verification depth had to differ by industry and relationship without changing the underlying platform.

System

What it runs at today

The platform as delivered, live across web and mobile.

Password-free attestation
98%
Biometric, QR-based authentication throughout, with no passwords required to complete a verification task
Entity types supported
6+
Corporations, LLCs, partnerships, trusts and nonprofits, each with their own officer and authority structures
Engagement length
12+
Months as an enterprise engineering partner, from compliance research to release
Team size
6+
Design, engineering and QA covering web, iOS, Android, backend and blockchain integration
The engineering problem

Six compliance gaps that shaped the build

Not vague pain points — the specific failures that made business verification slow and risky, each paired with what we did about it.

0 1
Due diligence was a manual document exchange

Onboarding a business customer meant requesting documents, having someone else review them and reaching a decision, usually without any real way to confirm that what was submitted was accurate. In industries where that matters legally, the gap was a genuine liability.

What we did

A structured invitation and onboarding flow: the inviting organisation searches by Tax ID or sends a manual invitation, and the invited business completes organisation details, terms acceptance and automated Middesk verification, tracked live from the inviter's dashboard.

0 2
Ownership structures no tool was built to hold

Regulations require businesses to disclose who actually owns and controls them, not just the name on the letterhead. Capturing that accurately — especially when corporate shareholders have ownership structures of their own — was a documentation exercise most platforms could not represent.

What we did

A full beneficial ownership flow capturing officers and roles, individual and corporate shareholders, ownership percentages and governing documents, with corporate shareholders that have no existing record triggering their own onboarding automatically.

0 3
Completed verifications could still be edited

Even when a verification finished, the record of it lived in an email thread, a shared folder or an internal system someone could change. There was no way to prove that verification happened, when it happened and who confirmed it once an audit or dispute surfaced months later.

What we did

Every significant verification event generates a signed compliance record and a verifiable digital token stored on-chain — organisation creation, officer attestation, ownership disclosure and authority verification — none of which can be altered after creation.

0 4
Verifications stalled waiting on the right person

Chasing documents and signatures from a business customer's officers and owners took weeks in some cases. There was no clear workflow, no visibility into where things stood, and no way to nudge the right person at the right time, so a lot of verifications simply stopped.

What we did

Invitation state management with role-based task routing and mobile task notifications, so each step is assigned to a named, verified person and the inviting organisation can see progress in real time.

0 5
Claimed authority was taken on trust

When an officer signed off on something, the compliance team generally had to accept that they had the authority to do so. Nothing checked that an individual's claimed authority matched the organisation's legal structure until it was built explicitly.

What we did

Role and authority assignment after the ownership flow completes: each authority role must be held by at least one individual, and authorised officers confirm their permissions through an attestation task before they can act.

0 6
Rigid checks collected too much or missed the point

Different industries and relationships require different depths of verification. What a financial counterparty needs is not what a logistics partner needs, and a fixed process either gathered more information than was justified or missed what actually mattered.

What we did

Configurable verification depth set per invitation — ownership disclosure thresholds plus add-ons such as PEP checks, SSN verification, criminal background checks, bank account verification and 501(c)(3) status, enabled independently for the business, its officers and its owners.

Architecture

How it fits together

Simplified — the shape rather than every service.

0 1 Clients
Next.js web dashboard · iOS · Android · HTML · CSS · JavaScript

A web dashboard for organisation management and verification configuration, with native iOS and Android apps carrying QR-based login, task notifications and biometric attestation.

0 2 Gateway
Nest.js REST API · Role-based access control · Invitation state management

A REST API layer built on Nest.js handles authentication, role-based access control, invitation state and task routing, and connects the clients to third-party verification and the on-chain record system.

0 3 Services
Onboarding & invitations · Beneficial ownership flow · Biometric attestation · Roles & authority · On-chain record generation

Each function is its own concern, so onboarding, ownership disclosure, attestation, authority management and record generation can run for many organisations in parallel without state bleeding between them.

0 4 Data & infra
PostgreSQL · On-chain token storage · Middesk verification API

PostgreSQL holds the entity, ownership and authority model, while verifiable digital tokens are written to the ledger and business verification data is pulled from Middesk.

On-chain record generation was designed into the architecture from the start rather than added later, because records had to be produced at specific, predictable points in the verification flow.
Solutions

Six systems doing the actual work

Not a features list — the specific things we built behind every number above.

Structured invitation & onboarding flow

Search a business by Tax ID or send a manual invitation. The invited organisation completes details, accepts terms, passes Middesk verification and claims its account through QR-based login, tracked live by the inviter.

Full-spectrum ownership disclosure

The ownership flow captures officers and roles, individual and corporate shareholders, ownership percentages and governing documents, keeping disclosure complete through multi-tier structures.

Biometric authority attestation

Officer attestation, ownership confirmation and authority assignment are all completed in the mobile app using face scan, so the person finishing a task is present and verified rather than just holding an email address.

Configurable verification with add-ons

The inviting organisation sets ownership thresholds and enables PEP checks, SSN verification, criminal background checks, bank account verification and 501(c)(3) status checks independently for the business, its officers and its owners.

On-chain audit trail

Organisation creation, officer attestation, ownership disclosure and authority verification each generate a signed record and a verifiable digital token stored on-chain, which cannot be altered afterwards.

Role-based authority management

After the ownership flow, the organisation admin assigns roles and legal authority. Every role must be held by at least one attested individual, so any action can be traced to a verified, authorised person.

Key features

What the platform does day to day

Five capabilities where the ledger and the verification flow do the work together.

Capability Runs Refresh What it does
On-chain business verification records Per event On write Records all verification activity on-chain for transparency, security and auditability
Ownership disclosure on the ledger UBO flow On disclosure Stores beneficial ownership information on the ledger with secure timestamps and ownership records
Biometric attestation for signers Mobile app Per task Authenticates authorised signers by biometrics and links verified identities to on-chain records
Immutable compliance audit trail Continuous Append only Maintains a permanent, tamper-proof history of all verification and compliance activity
Cross-platform credential portability Tokenised On reuse Tokenises verified credentials so they can be reused across platforms and verification processes
Integrations

How the moving parts plug in

Business data, biometrics and ledger records reach the platform through one API layer rather than sitting beside it as separate tools.

External systems & connected capabilities

Middesk verification
Automated business entity checks
Biometric identity
Face scan attestation in the mobile app
Blockchain record layer
Verifiable digital token storage
Compliance add-on checks
PEP, SSN, background, bank, 501(c)(3)
↓ through one REST API layer ↓

Platform integration layer

Nest.js API layer
One contract for web and mobile
Roles & authority control
Verifiers, signers, administrators
Invitation state engine
Parallel verification flows, no state bleed
↓ into the core services ↓

Core services

Onboarding
Ownership
Attestation
Authority
On-chain records

Because onboarding, ownership and attestation all resolve against the same services, configuring a verification, collecting it and holding the on-chain proof of it are three steps in one dashboard rather than three separate systems.

Security

What protects identity and compliance evidence

The platform handles legal identity, ownership disclosure and biometric attestation, so protection was designed in from the first architecture decision.

Biometric authentication, no passwords

Face scan and QR-based login authenticate every critical action, so there are no passwords to share or compromise and the person completing an attestation is physically present.

Immutable compliance records

Signed records and verifiable digital tokens are generated at every significant verification event and cannot be modified after creation, giving a trail that holds up to audit, dispute or regulatory review.

Role-based access and authority

Verifiers, signers and organisation administrators each reach only what their attested role allows, and every authority role must be assigned to at least one verified individual.

Isolated concurrent verifications

Many organisations progress through verification at the same time, with invitation state kept separate so no data or decision crosses between flows.

Process

How we got there

Five stages, starting with the regulatory landscape rather than a feature list, because every decision carried a compliance implication.

0 1
Discover

We mapped the KYB compliance landscape — the regulatory requirements behind ownership disclosure, the workflows compliance teams were actually using, and where existing tools created risk or friction — documenting each entity type and its authority structures before scoping.

0 2
Define

We defined a modular verification architecture covering different entity types, configurable ownership thresholds, optional add-ons and the distinct flows for new versus existing organisations, across the web dashboard, mobile app, Middesk integration and on-chain record layer.

0 3
Design

We designed both sides of the journey — the inviting organisation configuring and sending a request, and the invited organisation completing it — validating every screen against the compliance requirement it had to satisfy while keeping the experience guided.

0 4
Develop

Built as a layered system: the web dashboard for organisation management and verification configuration, a REST API layer connecting Middesk and the on-chain record system, and the mobile app for QR-based login and biometric attestation, with parallel flows and role-based task routing.

0 5
Validate

We ran the full flow end to end, including corporate shareholders without existing records, ownership totals exceeding 100%, authority role gaps, verification failures and multi-tier ownership chains. Compliance accuracy was treated as a hard requirement.

Business impact

What changed for the business

Beyond the headline numbers, three things compliance teams noticed first.

A primary verification tool, not a side process

Compliance teams that previously spent weeks gathering documents and chasing responses now work from an invitation-driven workflow with built-in guidance and real-time tracking.

75% faster onboarding
Verification as a living record

The on-chain trail turns a one-time check into a record that can be re-examined, shared with auditors or referenced in a dispute with no risk that it has been altered.

100% on-chain coverage
Regulatory obligations without the burden

A legally complex process was made manageable for non-specialists, meeting requirements without the operational overhead that usually comes with them.

Audit-ready by default
Commercial outcome

What the engineering choices are worth in operating terms

Every headline number traces back to a specific decision, not a vague platform effect.

Engineering decision Operating outcome Measured effect
Invitation flow with automated business verification Document chasing replaced by a guided, tracked onboarding request 75% faster onboarding
On-chain record generation at every event Compliance evidence that cannot be edited after the fact 100% audit trail coverage
Unified organisation, officer and owner verification One flow instead of three parallel document exercises 98% of layers in one flow
Biometric, QR-based authentication throughout No shared credentials in the attestation chain 98% password-free
Stack

What it's built on

The actual technologies, not feature names with icons attached.

Frontend

  • Next.js
  • HTML
  • CSS
  • JavaScript

Mobile

  • iOS
  • Android

Backend & data

  • Node.js
  • Nest.js
  • PostgreSQL

Integrations

  • On-chain token storage
  • Middesk verification API
Full case study

Get the complete write-up as a PDF

The same content on this page, plus the extended module breakdown and delivery phases, in a single document you can share internally.

Verification flow and on-chain record architecture
Compliance research to release, phase by phase
Biometric attestation and authority control in detail

Download the case study

No spam • unsubscribe anytime • we’re here when you need us

More work

Other platform builds

Hospitality

Every stay, extraordinary.

Hospitality group transformed guest experiences through IoT-enabled room automation, reducing service requests by 58%
Hospitality Group transformed Guest Experiences through IoT-enabled Room Automation, reducing Service Requests by 58%
Transportation & Mobility

Share the ride. Own the journey.

Mobility platform optimized commuter matching, increasing successful ride bookings by 48%
Mobility Platform optimized Commuter Matching, increasing Successful Ride Bookings by 48%
Sports & Entertainment

Fans in. Athletes up.

Sports engagement platform increased fan participation by 3x through gamified digital experiences
Sports Engagement Platform increased Fan Participation by 3x through Gamified Digital Experiences