Fintech and banking software development that survives reconciliation

Core integration, payment rails, a double-entry ledger, three-way reconciliation, KYC and AML, lending and card issuing. Built for banks and licensed fintechs across Oman, the UAE, Saudi Arabia and India.

  • ISO 20022 native, not MT
  • Three-decimal Gulf currency
  • Penny test in month one
  • Discovery before any number
See the short version

Get Your Free Consultation & We'll Reach Out Promptly!

By submitting this form, I authorize Zyneto to collect and process my personal data in accordance with theZyneto Privacy Policy.

We respond to all inquiries within 1 hour.

Trusted by
Global Industry Leaders

Al Amri Express
Cheer Sagar
MRO Supply
BankSathi
DoraDori
Kroolo
StyleBank
Hire Right
Cintas
Up in the Air
Famepilot
Swedishness
Corrib Coil
iCare Heal
TWAM
NDC: National Distribution Company Oman
Moneteo
Algora
Numerology
G4Girl

The short version

The commercial facts in one block, before you scroll. That covers fintech software development, banking software development and payment gateway development, which differ far more in licensing than in code. Those tiles are: Typical integration set, Phase one timeline, Rate band, Phase one range, with the arithmetic, Stack we actually use and Our commitment.

Typical integration set

01

A core such as Oracle FLEXCUBE, Infosys Finacle, Temenos Transact, TCS BaNCS or Azentio iMAL. One or more rails from Oman RTGS and MPCSS, UAE Aani and UAEFTS, Saudi sarie and mada, India UPI and NACH, or SWIFT through Alliance Access. Screening through World-Check or ComplyAdvantage, and identity through Mala'a, UAE PASS, Nafath or Aadhaar eKYC.

Phase one timeline

02

14 to 22 weeks, from a signed integration register to a penny test on one live rail. That assumes sandbox credentials exist on day one. Where they do not, the clock starts when they arrive rather than when the contract is signed.

Rate band

03

$40 to $100 per hour by role. QA and junior implementation near the floor, ledger design and rail integration near the ceiling. Mixed squads blend to roughly $60 to $70.

Phase one range, with the arithmetic

04

Onboarding 250, plus ledger 400, plus one rail 180, plus reconciliation 250, plus back office 300, equals 1,380 hours at the floor. QA and partner certification at 15 to 25 percent lifts it to 1,587. At the ceiling the same five modules reach 3,250 hours, so the band is $95,000 to $227,500 at a $60 to $70 blend.

Stack we actually use

05

Next.js, Node.js, PostgreSQL, Terraform, Grafana and Prometheus, across web and Android. That is the stack running on BankSathi, not an aspirational list.

Our commitment

06

No quote before discovery. Rail count and migration data quality move the total by more than double, and neither is knowable from a requirements document. Vendor pass-through costs for identity verification, credit bureau, KYB data and processing are quoted on a separate line and never folded into engineering hours.

Audience

Who this is for

Six operations, and the one system each is usually missing. Not a fit: pre-licence and pre-funding, with no sponsor relationship and no core to integrate against. Come back when you have a rail and a regulator, because until then there is nothing for us to build against.

01

Conventional bank, Oman or the UAE

Head of digital or CIO. The core is FLEXCUBE, Finacle or iMAL, and every channel change becomes a core change request. The gap is an orchestration layer that owns its own state instead of asking the core for permission.

02

Licensed or applying fintech

Founder or CTO with a sponsor relationship or a licence application in flight. You have no ledger of record that can prove whose money is whose without reading the sponsor bank's statement.

03

NBFC or digital lender, India

You sit inside the RBI Digital Lending Directions perimeter and your apps are reported on CIMS. Credit policy still ships as code, so every change waits on a release.

04

PSP, acquirer or issuer-processor

You route mada, Jaywan or RuPay, run an ISO 8583 switch and fight chargebacks against network deadlines. Nothing in the estate gives you a settlement break queue with an age and a named owner on every open item.

05

Islamic bank or takaful operator

Your products are Murabaha, Ijarah, Tawarruq or a participants' risk fund. Underneath sits a conventional loan engine with the labels changed, where the product needs a schedule engine built for profit rate and ibra'.

06

Wealth, brokerage or insurance

FSA Decision 80/2023 puts the platform itself in scope for approval in Oman. No positions and lot engine ties to the custodian file every night.

Find your operation

Fintech is six different businesses wearing one word. What breaks is different, so what we build is different. This page covers: Digital banks and BaaS, Lending and Islamic finance, Acquiring and PSPs, Card issuing, Wealth and takaful and AML and screening.

01 · Your operation

Digital banks and BaaS

What breaks

You run the app and the brand while a sponsor bank holds the deposits, so you operate the sub-ledger that says whose money is whose inside a pooled account. Sub-ledger drift against the bank core goes unnoticed for weeks. Returns arrive unmatched. There is no daily balance proof on the morning an examiner asks for one, and in Oman the licensing frame you are building against is CBO Decision 25/2025.

What we build

An append-only double-entry core ledger with balances derived from postings. Three-way reconciliation across the processor file, the bank statement and the internal ledger, running daily from the first transaction. A break queue with aging and one named owner per open item.

Where payment systems earn their keep

The stages a transaction moves through, and what we build at each one In sequence, the stages are: Onboarding and KYC, Screening and risk, Authorisation, Clearing and settlement, Ledger posting and Reconciliation and reporting. Each one is a place a system either holds the fact or loses it.

01Onboarding and KYC02Screening and risk03Authorisation04Clearing and settlement05Ledger posting06Reconciliation and reporting
Two band payments map covering onboarding, screening and authorisation, then clearing, ledger posting and reconciliation.

Systems we connect to, and how money becomes a ledger entry

A regulated build is mostly an integration project wearing a product costume. This is the estate we expect to meet, and the mechanics underneath it that cannot be bluffed. Grouped as: Cores and lending platforms, Rails, switches and hardware, Financial crime, screening and filing, Identity, bureau and decisioning and Issuing, BaaS and insurance platforms.

Cores and lending platforms

Temenos Transact, Oracle FLEXCUBE with OBDX, Infosys Finacle, TCS BaNCS, Finastra Fusion Essence and Loan IQ, Intellect Design iGCB, Azentio iMAL, ICS BANKS, Codebase Digibanc, Mambu, Thought Machine Vault, 10x Banking, Backbase, Nucleus FinnOne Neo, Lentra, nCino and TurnKey Lender. FLEXCUBE exposes SOAP gateways over JMS and MDB plus a Java and EJB layer, Finacle goes through Finacle Integrator, and BaNCS is web services. REST is usually a wrapper somebody built. Every core holds an end-of-day and beginning-of-day blackout window that rejects writes, and that window shapes the design more than the protocol does.

Rails, switches and hardware

SWIFT FIN, InterAct and FileAct through Alliance Access or Lite2, with mandatory annual attestation under the Customer Security Programme. Oman RTGS, MPCSS, OmanNet and the Direct Debit System. UAE Aani, UAEFTS, UAEDDS, Jaywan and the WPS payroll file. Saudi sarie, mada over SPAN and SADAD. Buna and AFAQ cross-border. India UPI, IMPS, NEFT, RTGS, NACH with e-mandate, Bharat Connect, AePS and RuPay. ISO 8583 over NFS, Thales payShield 10K and Utimaco hardware security modules, Visa VTS and Mastercard MDES. Each rail carries its own certification calendar, and that calendar belongs on the project plan before the architecture diagram does.

Financial crime, screening and filing

Oracle FCCM, NICE Actimize, SAS AML, FICO Siron, Fiserv AML Risk Manager, Eastnets, Temenos FCM, Tookitaki, Silent Eight, Napier AI, ComplyAdvantage and Azentio AMLOCK. Screening data from LSEG World-Check, Dow Jones Risk and Compliance, Moody's Grid and LexisNexis Bridger. Filing through goAML for the UAE and Oman financial intelligence units, and FINnet for India. The vendor gives you matches. Threshold tuning, disposition workflow and the audit trail are yours to build.

Identity, bureau and decisioning

Mala'a National Digital Onboarding Registry, UAE PASS with Emirates ID through ICP, Nafath and Absher, Elm Yakeen and Wathq, Aadhaar eKYC through AUA, KUA and ASA, DigiLocker, CKYCR at CERSAI, and video KYC built to the RBI process. Bureaus: SIMAH, Bayan, AECB, Mala'a, CIBIL, Experian, Equifax and CRIF High Mark. Decision engines: FICO Blaze Advisor, Experian PowerCurve, Provenir, ACTICO, GDS Link, and Drools or DMN where budget is tight.

Issuing, BaaS and insurance platforms

NymCard, Network International, Magnati, Geidea, HyperPay, PayTabs, Checkout.com, Tap Payments, Moyasar, MyFatoorah, Thawani, Marqeta, Galileo, Thredd, Nium, M2P Fintech, Zeta, Setu, Decentro, Razorpay, Cashfree and Juspay. Insurance and takaful: Guidewire, Duck Creek, Sapiens, Majesco, Socotra, INSTANDA, Novidea, Azentio Beyontec and EbixCash.

Origination against servicing

Origination ends at funding. Servicing starts at the first schedule. Different vendors build them, and the handoff is where product rules and payment allocation order get quietly reinvented by whoever writes the mapping.

Core against engagement layer

Temenos Transact, FLEXCUBE, Finacle and iMAL hold the accounts of record. Backbase is an engagement layer. Buying an engagement layer gives you channels, not a ledger, and the difference shows up at the first reconciliation.

Conventional loan engine against Islamic product logic

Murabaha, Ijarah and Tawarruq run on profit rates, not interest. Early settlement goes through an ibra' rebate, accrual may follow the Hijri calendar, and the schedule needs Sharia board sign-off. That is not a configuration change to a conventional engine.

Bilateral open banking against a central hub

The UK, the EU and Saudi Arabia connect third-party providers to banks bilaterally under a directory and a FAPI profile. The UAE routes every licensed financial institution and provider through Nebras Open Finance LLC, the CBUAE-owned hub. India has no PSD2 equivalent and uses the RBI Account Aggregator framework with a signed consent artefact and ReBIT schemas. Same product idea, three different integration estates.

The ISO 20022 message set, and what each one is for

pain.001 is customer initiation from your channel into the bank, and field-level validation happens there or it happens later as a rejection. pacs.008 is the interbank credit transfer, where the end-to-end transaction reference is minted and has to survive every hop. pacs.002 is the status report, and pending is a state rather than a failure, which is why treating it as one causes duplicate sends. pacs.004 is a payment return, an accounting event distinct from a new payment in the other direction. camt.052 is intraday and useful for liquidity but not authoritative. camt.053 is the end-of-day statement you actually reconcile against. camt.054 is advice, not proof of settlement. MT940, MT942 and BAI2 are the legacy statement formats you will still be handed, often as positional extracts from a mainframe.

The five fields that break implementations

Structured postal address: hybrid is permitted today, fully unstructured addresses are decommissioned in November 2026, and town name plus country code have to sit in structured fields. If your customer records store an address as three free-text lines, that is a data migration rather than a mapping exercise. The end-to-end transaction reference is your only trace identifier across gpi, and if it is not persisted on the posting you cannot answer where a payment is right now. Purpose codes are read by regulators and screening rules, so defaulting every payment to one code makes a screening ruleset useless. Structured remittance information is where reconciliation data lives or dies. Currency minor units carry ISO 4217 exponent 3 for OMR, KWD and BHD, so one rial is 1,000 baisa, and any code that multiplies by 100 corrupts Gulf money silently.

The payment state machine and idempotency

Money APIs need an idempotency key on every mutating call and an explicit state machine with terminal states. A retry loop is not a state machine. Duplicate callbacks, late reversals, UPI deemed-success and the return cycles on card rails all produce the same shape of incident: two debits, one intent, and no evidence about which attempt was real. A retry without an idempotency key is a double debit you cannot later prove was accidental.

The ledger of record

An append-only double-entry journal, with balances derived from postings rather than stored and updated in place. Corrections go in as reversing entries with effective dates, so a backdated dispute is representable rather than argued about. Every posting carries the external reference, the transaction reference where one exists, and an effective date separate from the booking date. At 400 to 800 hours this is the single highest-risk module on a regulated build, and it is the one teams try to shortcut into a balances table.

Three-way reconciliation and break management

Three sides: the internal ledger, the processor or switch file, and the bank statement as camt.053 or MT940. Daily and automated, from the first transaction rather than from the first complaint. A break queue with aging, one named owner per break, and a documented match rate you can show an examiner. Budget 250 to 450 hours. A commonly cited industry rule of thumb puts exception handling at 50 to 60 percent of all money-movement effort; we have not measured that ourselves, so treat it as a planning heuristic and not as our figure. Defer this module and month three arrives with thousands of unmatched items and nobody able to say which side is wrong.

Regional rail specifics that change the design

sarie is ISO 20022 native with alias resolution by mobile number or national ID. Aani and MPCSS resolve by alias and QR. Oman's RTGS runs 24/7 with no batch window, so batch-era reconciliation design does not work there. IBAN has been mandatory on inbound and outbound international transfers in Oman since 1 July 2025 and banks reject non-IBAN transfers, so validate structurally at capture rather than at submission. UPI runs JSON and XML APIs through a sponsor bank with X.509 signing. Card switching is still ISO 8583 over a persistent TCP socket with a two-byte message-length header and echo handling. AFAQ uses MT at the national interface and MX internally, so structured party data has to survive a translation hop without truncation.

Bring us your core, your rails and your regulator

We will come back with an integration register, not a proposal template. Discovery is paid, fixed fee, and nothing it produces is locked to us.

Standards and compliance

Five standards a financial buyer's procurement pack asks for by name, and one row for every regional rule that changes what the software has to do. Covered here: ISO/IEC 27001, SOC 1 and SOC 2, PCI DSS v4.0.1, GDPR and UK GDPR, DORA, Regulation (EU) 2022/2554 and The regional rules that change the build.

ISO/IEC 27001

The information security management certification procurement asks for first. It certifies the organisation running the system, not the software. We build to the controls and produce the evidence, and your assessor certifies you.

SOC 1 and SOC 2

SOC 2 covers security, availability and confidentiality of the service. SOC 1 covers controls that feed your customers' financial reporting, which is the one that appears once you are running settlement, custody or a sub-ledger that lands on someone else's books.

PCI DSS v4.0.1

All 51 future-dated requirements have been mandatory since 31 March 2025, including 6.4.3 payment-page script inventory and authorisation, and 11.6.1 tamper and change detection. Tokenise at the edge, keep a written scope map, and assume merchants who previously self-assessed lightly are now caught by it.

GDPR and UK GDPR

Reaches you through EU or UK customers and through data processed on their behalf. Lawful basis, subject access, erasure and breach notification have to be operable by a person rather than described in a policy document nobody has tested.

DORA, Regulation (EU) 2022/2554

Applying since 17 January 2025. Where it reaches you as an ICT third party, it wants a maintained register, contractual resilience terms, and tested evidence rather than an assertion that failover exists.

The regional rules that change the build

Oman: Banking Law Royal Decree 2/2025 defines a digital bank in primary legislation, CBO Decision 25/2025 effective 1 June 2025 sets category 1 at OMR 30m and category 2 at OMR 10m paid-up capital, the Open Banking Framework was approved on 29 December 2024, IBAN has been mandatory on international transfers since 1 July 2025, RTGS has been ISO 20022 native and 24/7 since 18 June 2023, PDPL Royal Decree 6/2022 became fully enforceable on 5 February 2026, and FSA Decision 80/2023 requires approval of the electronic insurance platform itself. Saudi Arabia: the Open Banking Framework launched in November 2022 with account information live in 2023 and payment initiation in September 2024, SAMA's Cyber Security Framework and NCA ECC-1:2018 cascade contractually to vendors, PDPL has been in force since 14 September 2023, and SDAIA's transfer regulation and standard contractual clauses were issued in September 2024 with no adequacy list. UAE onshore: Open Finance Regulation Circular 7 of 2023, updated by Circular 3 of 2025 in force 10 July 2025, adds service-initiation rights and routes everything through Nebras Open Finance LLC, under Federal PDPL 45/2021. DIFC runs Data Protection Law No. 5 of 2020 and ADGM the Data Protection Regulations 2021, both separate from onshore. India: payment data localisation from the April 2018 circular, card-on-file tokenisation since 1 October 2022, RBI Digital Lending Directions dated 8 May 2025 with CIMS reporting from 1 November 2025, the Authentication Mechanisms Directions from 1 April 2026, DPDP Rules notified 14 November 2025, and CERT-In six-hour breach reporting with 180-day in-country log retention. SWIFT CBPR+ MT and MX coexistence ended on 22 November 2025, so MX is the baseline and translation is contingency only.

Our work in this sector

One build in the sector and two adjacent engagements. We would rather describe real work and say where it stops than show a wall of logos.

India

BankSathi

A fintech platform where users browse, compare and apply for credit cards, savings accounts, loans, insurance and investments across multiple banks. The distinctive part is the advisor model: users earn commission recommending products with no initial investment, supported by financial education, live training and marketing tools. It demonstrates multi-partner product catalogues, application capture across several product types, an agent and commission model, and a production stack with infrastructure as code and metrics attached.

  • Next.js
  • Node.js
  • PostgreSQL
  • Terraform
  • Grafana
  • Prometheus

Financial reporting

Up in the Air

A web-based financial dashboard for data analysis and reporting, with real-time data integration and customisable reporting. Described by Paul Van Alfen, Managing Director, through TechBehemoths. The review reports a reduction in manual reporting time; we do not hold a verified figure for it and will not attach one.

  • Web application
  • Real-time integration
  • Reporting

Custom platform

Moneteo

A custom web platform for a financial services company, with modules for workflow automation, API integration and comprehensive testing. Described by Krystian Chlebek, Founder and CEO, through TechBehemoths. This was an internal operations platform rather than a customer-facing financial product, and it is listed as what it was.

  • Full-stack web
  • Workflow automation
  • API integration

What goes wrong

Ten failure modes we have hit or inherited. Naming them is more useful than a list of reasons to choose us. It starts with: Three-decimal currencies handled as two, The ledger is really a balances table and Reconciliation deferred until after launch.

01

Three-decimal currencies handled as two

OMR, KWD and BHD carry ISO 4217 exponent 3, and code that assumes two minor units corrupts Gulf money quietly while the error compounds through every downstream report. Hold the exponent in a data table, keep integer minor units end to end, and add a test that fails the build on a hardcoded 100.

02

The ledger is really a balances table

A running balance that gets updated in place cannot represent a backdated correction or a disputed transaction, so the first serious dispute becomes an argument rather than a lookup. Post append-only double-entry entries, derive balances from them, and record corrections as reversing entries with effective dates.

03

Reconciliation deferred until after launch

Build the three-way reconciliation before the first live transaction, not after the first complaint. Teams that defer it reach month three with thousands of unmatched items, no aged break queue and no way to say which of the three sides is wrong.

04

Money APIs that are not idempotent

A retried call double-debits, and nothing in the system afterwards proves which attempt was the real one. Every mutating call needs an idempotency key, an explicit state machine with terminal states, and reconciliation standing as the arbiter when the two disagree.

05

The exception catalogue arrives last

Returns, reversals, insufficient funds, chargebacks and provisional credit rewrite the data model after launch, because the happy path was specified and the rest was assumed. Model the full exception set before the first transfer and treat that catalogue as the specification.

06

Structured data truncated into legacy fields

ISO 20022 party and remittance data gets squeezed into 35-character legacy fields, or lost entirely at an MT and MX translation hop such as AFAQ. The fix is end-to-end field-level contract tests where truncation fails the build rather than logging a warning nobody reads.

07

Sanctions screening tuned only for Latin script

Arabic name transliteration produces false negatives and a false-positive queue no team can clear, and the vendor default threshold is rarely right for your book. Tune and back-test thresholds against your own history, with transliteration variants included in the test set.

08

Calendar and cutoff blindness

The UAE runs a Saturday and Sunday weekend, Saudi Arabia and Oman run Friday and Saturday, Islamic profit accrual may follow the Hijri calendar, and cores hold blackout windows that reject writes. Treat the settlement calendar as configuration, and record every blackout window in the integration register before design starts.

09

PCI and PII scope creep

Card numbers turn up in application logs, support screenshots and analytics payloads, and real customer data turns up in test environments, which under PDPL and DPDP is an exposure rather than a hygiene issue. Tokenise at the edge, keep a written scope map, assert log scrubbing in CI, and generate synthetic test data.

10

Certification lead time treated as a sprint

Regulator no-objection for cloud or outsourcing in Saudi Arabia and the UAE is measured in months, card network certification windows do not move for you, sandboxes do not reproduce production cutoffs, and mTLS certificates expire mid-project. Schedule backwards from the certification date and put every certificate expiry on the release calendar.

Build, buy, or buy the core and build the edge

The honest answer is usually the third one, and sometimes the answer is that you should not hire us for this part. Assessed below: Core banking platform, Ledger of record for your own product, Payment rail connectivity, Screening and sanctions data, Card issuing and processing, Reconciliation and break management, Credit decision and policy engine and Back office and operations console.

ComponentOur recommendationOur honest verdict
Core banking platformBuyTemenos Transact, FLEXCUBE, Finacle, BaNCS and iMAL give you the regulatory surface on day one. Building one is 6,000 to 12,000 hours and you own every certification. Buy it, and expect the channel roadmap to outrun the core release cycle.
Ledger of record for your own productBuildThis is where your differentiation and your audit evidence both live, and no vendor will sell you the version that matches your product. Cloud-native cores such as Mambu, Thought Machine Vault and 10x Banking give you a ledger primitive, but the orchestration around it is still yours.
Payment rail connectivityBuy the core, build the edgeTake the gateway or processor connection from a provider. Build the state machine, the idempotency layer, the return and reversal handling and the posting logic, because that is what the provider does not own and what breaks at three in the morning.
Screening and sanctions dataBuyWorld-Check, Dow Jones, ComplyAdvantage and Moody's Grid sell the list and the matching. Nobody sensible rebuilds that. Threshold tuning, disposition workflow and the audit trail remain yours to build.
Card issuing and processingBuy the core, build the edgeNymCard, M2P, Zeta, Marqeta, Galileo and Thredd get you to market fast, and the partner owns the economics and the roadmap. Their sandbox will not reproduce production settlement timing, so plan a limited live pilot rather than trusting the pilot environment.
Reconciliation and break managementBuildEvery vendor assumes someone else owns this, which is why four vendors each end up owning a slice of the audit trail and none owns the whole. It is 250 to 450 hours and it is the module that proves your numbers to an examiner.
Credit decision and policy engineBuy the core, build the edgeBlaze Advisor, PowerCurve, Provenir and ACTICO are worth buying where budget allows, with Drools or DMN where it does not. Either way, build the versioning, the champion and challenger harness and the shadow mode, because that is what lets policy change without a release.
Back office and operations consoleBuildThe module most often left out of a quote and the one your operations team lives in all day. Role-based access, maker-checker and dual control on every money action, with an audit log that survives examination.
e-invoicing transmissionBuyOnly an accredited Service Provider may transmit in the UAE, Oman and Saudi Arabia. We are not one and cannot become one on your behalf. We build the integration to your chosen provider and the evidence that the document was accepted.

Transparency

What fintech and banking software development costs, with the arithmetic shown

Every competitor publishes a total with no hours behind it. Here is the rate, the hours and the multiplication, so you can argue with any line of it. The drivers are: Number of money rails, Migration data quality, Core system and its integration surface, Conventional or Islamic product logic and Number of markets in scope.

Phase one range

$95,000 to $227,500

The control core at a $60 to $70 blended rate

Typical timeline

14 to 22 weeks

Signed integration register to a penny test on one live rail

Useful hours

1,587 to 3,250

The control core after the QA and certification uplift

What moves the number, ranked
DriverHours
Number of money railsPlus that rail's certification calendar, which is a schedule cost before it is a money cost180 to 350 each
Migration data qualityLegacy balances carry accrued interest, escrow, partial payments and memo codes nobody can currently explain300 to 900
Core system and its integration surfaceSOAP over JMS, a file drop or a modern API changes the work more than the vendor name does150 to 400
Conventional or Islamic product logicProfit rate, ibra' rebate and Hijri accrual are engine changes rather than configuration120 to 350
Number of markets in scopeEach regulator adds its own reporting, residency and consent obligations100 to 300 each
Hours by module
ModuleHours
KYC and KYB onboarding with identity orchestrationAdd 100 or more for a manual review console250 to 450
Double-entry ledger and posting engineThe highest-risk module on the page400 to 800
Payment rail integration, one railReturns and exceptions included. Each additional rail is the same again180 to 350
Reconciliation and break managementThree-way, daily, from day one250 to 450
Back office console with access control and audit logThe module most often left out of quotes300 to 550

The control core, and what sits outside it

  • These five modules are the control core: the smallest thing that can move money and prove it afterwards. At the floor that is 250 plus 400 plus 180 plus 250 plus 300, which equals 1,380 hours. At $40 per hour that is $55,200, at $100 it is $138,000, and at a $65 blend $89,700.
  • At the ceiling the same five reach 450 plus 800 plus 350 plus 450 plus 550, which is 2,600 hours.
  • QA, user acceptance testing and partner certification run at 15 to 25 percent of build and are not optional on a regulated rail. That adds 207 at the floor and 650 at the ceiling, so the control core delivered is 1,587 to 3,250 hours, or $95,000 to $227,500 at a $60 to $70 blend. That is the phase one band quoted at the top of this page.
  • Everything else is priced the same way and sits outside that example rather than hidden inside it. Lending origination with a decision engine is 400 to 700 and servicing with delinquency is 500 to 900. Customer web and mobile is 600 to 1,200. Card issuing with the authorisation stream and just-in-time funding is 350 to 650, and disputes and chargeback lifecycle is 200 to 400.
  • AML monitoring, alerts, case management and filing is 300 to 550. Regulatory and tax reporting is 150 to 400. Security and compliance engineering is 200 to 500. Core or legacy migration with a parity harness is 300 to 900, the widest range here for good reason.
  • An Oman digital lender wanting a full first release adds lending and customer channels to the control core: 1,500 to 2,800 more before QA, so 1,725 to 3,500 additional hours, or $103,500 to $245,000.
  • Identity verification, credit bureau, KYB data and processor fees are vendor pass-through costs. They are quoted on a separate line and never buried inside engineering hours.

Engagement

How we can work together

Four models for fintech and banking software development, each with the downside stated in the same breath. Those four are: Discovery and architecture sprint, Fixed scope phase one, Dedicated squad, monthly and Run and certification retainer. Pick by how settled the scope actually is, not by preference.

Discovery and architecture sprint

Upside

Two to four weeks at a fixed fee, producing the integration register, the exception catalogue, the target architecture and a costed phase one. The output is yours whether or not you build with us.

Downside

It produces a document rather than running software, and sometimes the honest conclusion is that you should buy rather than build.

Fixed scope phase one

Upside

Scope frozen at the end of discovery, with a fixed price and a fixed date, which is the model procurement and a board are most comfortable approving.

Downside

Change costs a change order, and regulators move things mid-build, so this model is least comfortable exactly where the rules are changing fastest.

Dedicated squad, monthly

Upside

A named team at a predictable monthly cost, absorbing scope change without renegotiation, which suits a roadmap that is still moving.

Downside

You carry the scope risk and must supply a decision-maker every week. The cost is predictable, the delivery date is not guaranteed.

Run and certification retainer

Upside

Ongoing operations, reconciliation break support, and cover for calendar-bound work such as SWIFT standards releases, network certification windows and assessment evidence.

Downside

A retainer is capacity rather than an incident response commitment, and embedded engineers cannot compensate for weak environments or missing test data.

Delivery

How we deliver fintech and banking software development

Five phases, each named by the artifact it produces. A generic waterfall diagram would tell you nothing. Those phases are: Integration register, Ledger and message contract, Penny test evidence pack, Parity report and Evidence pack and handover. Each is named by the artifact it hands you, so you can ask to see one.

  1. Phase 01

    Integration register

    Every system, its protocol, its authentication, its sandbox status, its cutoff and blackout windows, its certificate expiry dates, and the minor-unit table for every currency in scope. Signed by both sides before design starts.

  2. Phase 02

    Ledger and message contract

    Chart of accounts, posting rules, the payment state machine with terminal states, the idempotency policy, the ISO 20022 field map and the full exception catalogue. Delivered as a document plus machine-readable schemas, so tests assert against it rather than against someone's memory of a meeting.

  3. Phase 03

    Penny test evidence pack

    Real money moved on one live rail, with real credentials against real cutoffs, inside the first month of build where the partner allows it. The evidence is the message trace, the posting, the statement line and the matched reconciliation record.

  4. Phase 04

    Parity report

    Where a migration or replacement is in scope, run both systems in parallel, replay a month of history through a parity harness, and require balance-to-the-penny sign-off before cutover. There is no cutover without this report.

  5. Phase 05

    Evidence pack and handover

    Reconciliation runbook, break queue owners, access matrix, data flow diagrams, retention policy, log-scrub assertions in CI, disaster recovery test results, infrastructure definitions in Terraform and dashboards in Grafana. This is what your auditor, your regulator and your next engineer all read.

Non-functional

The technical buyer's checklist

Paste this into your RFP. These are the defaults we build to, and the last group is the one most vendors are vague about. Three groups cover: Ledger and correctness, Availability and timing, Authentication, transport and key handling, Audit, immutability and access control, Data protection and residency and Certifications, stated plainly.

Ledger and correctness

Append-only postings with derived balances. Effective dating and reversing entries. Integer minor units against a data-driven exponent table. Idempotency keys on every mutating call and explicit terminal states. Daily three-way reconciliation with an aged break queue and named owners.

Availability and timing

An authorisation-stream latency budget with a deterministic fallback rather than a timeout. 24/7 operation with no assumed batch window on rails such as Oman RTGS. Documented recovery point and recovery time objectives, with disaster recovery tested and the evidence retained.

Authentication, transport and key handling

mTLS with a certificate inventory and expiry alarms. OAuth2 client credentials with private_key_jwt. FAPI 1.0 Advanced including pushed authorisation requests where the regime requires it. Detached JWS request signing, X.509 signing for UPI, HMAC webhook signatures, and SFTP with PGP and IP allowlisting for file rails. Tokenise at the edge with network tokens through Visa VTS or Mastercard MDES, and run hardware security module key ceremonies on payShield 10K or Utimaco.

Audit, immutability and access control

Hash-chained audit logs. Write-once object storage using S3 Object Lock in compliance mode. Role-based access with maker-checker and dual control on every back-office money action. A disposition record that survives examination rather than one assembled afterwards.

Data protection and residency

Residency applied to backups, logs and observability, not only to the application tier. Six-hour breach reporting and 180-day in-country log retention for India. Consent captured with versioning, revocation and a consent audit ledger. No real personal data in any non-production environment.

Certifications, stated plainly

Buyers commonly require ISO/IEC 27001, SOC 2 Type II, a PCI DSS attestation of compliance as a service provider, ISO 22301, ISO 27701, and in region evidence of SAMA Cyber Security Framework and NCA ECC alignment. Zyneto holds none of them. We build to those controls and produce the evidence artifacts for your assessment, and your assessor certifies you rather than us. Ask any vendor who implies otherwise for the certificate number.

Frequently Asked Questions

Do you hold PCI DSS, SOC 2 or ISO 27001 certification?

No. We hold none of them, and you can verify that by asking us for an attestation of compliance or a report, which we do not have. We build to those controls, produce the evidence artifacts and support your assessment. Anyone in our position claiming otherwise should be asked for a certificate number.

Who owns the code, the data and the accounts?

You do, from the first commit rather than at handover. Code sits in your repository, infrastructure is defined as code in Terraform, and cloud, rail, screening and identity vendor accounts are created in your name. Two relationships stay directly yours because they cannot be ours: we are not a licensed financial institution, and we are not an accredited e-invoicing Service Provider in the UAE, Oman or Saudi Arabia. Replacing us should cost you a notice period, never a rebuild.

What does phase one cost, how many hours is that, and how long does it take?

A control core of onboarding, ledger, one rail, reconciliation and back office is 1,587 to 3,250 hours after the QA and certification uplift, which is $95,000 to $227,500 at a $60 to $70 blended rate, over 14 to 22 weeks. The two variables that move it most are the number of money rails, at 180 to 350 hours each plus that rail's certification calendar, and migration data quality, at 300 to 900 hours for a parity harness. The full arithmetic is in the cost section above.

What changed on 22 November 2025, and what does it mean if we still send MT?

SWIFT CBPR+ MT and MX coexistence ended, so MT 1xx, 2xx and 9xx no longer meet CBPR+. Translation exists as contingency, not as an architecture. The follow-on date is November 2026, when fully unstructured postal addresses are decommissioned and town name plus country code must sit in structured fields.

In the UAE, do we integrate every bank separately for open finance?

No. The CBUAE model is centralised, so all licensed financial institutions and third-party providers connect through Nebras Open Finance LLC. The governing rule is the Open Finance Regulation, Circular 7 of 2023, updated by Circular 3 of 2025 in force 10 July 2025, which also added service-initiation rights.

Our core is FLEXCUBE, iMAL or Finacle and it has no REST API. Can you still integrate?

Yes, and that is the normal case. FLEXCUBE exposes SOAP gateways over JMS and MDB plus a Java and EJB layer, Finacle uses Finacle Integrator, BaNCS is web services, and older estates use file drops over SFTP. The real design constraint is not the protocol, it is the end-of-day and beginning-of-day blackout window where the core rejects writes.

How do you handle Omani rial amounts?

As integer minor units against a data-driven ISO 4217 exponent table. OMR, KWD and BHD carry exponent 3, so one rial is 1,000 baisa. Any codebase that multiplies by 100 is already wrong for these currencies, and the failure is silent rather than loud, which is what makes it expensive.

Can our data leave Oman, Saudi Arabia or India?

Each answer is different. Oman's PDPL under Royal Decree 6/2022 became fully enforceable on 5 February 2026, with cross-border transfer controlled by MTCIT. Saudi Arabia has no adequacy list, so transfers out need SDAIA standard contractual clauses issued in September 2024 or approved binding rules. India's RBI April 2018 circular requires full end-to-end payment data in India, and where it is processed abroad it must be deleted overseas and repatriated within 24 hours or one business day, whichever is earlier.

Can we store card numbers for our Indian product?

No. Since 1 October 2022 no entity other than card issuers and networks may store card-on-file data, so you tokenise. Separately, PCI DSS v4.0.1 has required 6.4.3 script inventory and authorisation and 11.6.1 tamper detection on payment pages since 31 March 2025, which now catches merchants who previously self-assessed lightly.

Do we need a licence before we start building?

You need to know your licence category before you design. Oman's CBO framework for digital banks, Decision 25/2025 effective 1 June 2025, sets category 1 at OMR 30m and category 2 at OMR 10m paid-up capital, with different permitted activities behind each. Separately, regulator no-objection for cloud or outsourcing in Saudi Arabia and the UAE is measured in months, so it belongs on the plan before the first sprint.

Can you build Murabaha or Ijarah on our existing loan engine?

Not by configuration. Islamic products use profit rates rather than interest, early settlement runs through an ibra' rebate, accrual may follow the Hijri calendar, and the schedule needs Sharia board sign-off. Shipping product logic before that sign-off is how a schedule engine gets rewritten twice.

Have you migrated a core banking platform or delivered a live SWIFT integration?

No to both, and you should weigh that. We have built a multi-partner fintech platform, a financial reporting dashboard and an operations platform for a financial services company. What we are offering you to judge us on is the reasoning above on messages, the ledger and reconciliation. If your requirement is a vendor who has already migrated a FLEXCUBE estate, that is reasonable and we are not it.

What happens next

Four steps, and we will not send you a number before the third.

  1. A 30 minute scoping call

    Bring three things: your core system name, your rail list and your regulator. We will tell you on that call whether we are the right fit, including when the answer is no.

  2. A written question list

    Within two business days, along with the integration register template. Yours to keep, and yours to send to other vendors if you want a like-for-like comparison.

  3. A paid discovery sprint

    Two to four weeks at a fixed fee. Output is the signed integration register, the exception catalogue, the target architecture and a costed phase one with the arithmetic shown. You keep all of it even if you take the build elsewhere.

  4. Phase one, ending on a penny test

    Month one ends with real money moved on one live rail. Not a demo environment: real credentials, real cutoffs and a real reconciliation record.

Talk to an engineer, not a salesperson

Tell us what moves money today and where it stops reconciling, and we will tell you what is worth building and what you should buy.

  • No fixed quote before discovery
  • Reply within one business day
  • $40 to $100 per hour, by role

Our Success Stories

Real feedback from the people we've proudly partnered with.

Brooklyn Foster profile

Brooklyn Foster

Sales Director |Cintas

United States

GoodFirms
"

Zyneto Global Technologies provided excellent project management and technical expertise throughout the engagement. The team was responsive, collaborative, and adaptive, ensuring the project met our expectations and set a strong foundation for future growth.

"
Verified Review
Rating: 5 out of 5
Krystian Chlebek profile

Krystian Chlebek

Founder & CEO |Moneteo

TechBehemoths
"

We engaged Zyneto to design and develop a custom web platform for Moneteo, aimed at improving project management, data tracking, and collaboration across internal teams and external partners. Their work included full-stack web development, custom modules for workflow automation, API integration, and comprehensive testing.

"
Verified Review
Rating: 5 out of 5
Kevin Scott profile

Kevin Scott

CEO |E-Commerce Platform

Clutch
"

Overall, their responsiveness and timely deliveries contributed positively to the project's success. The client achieved better data management and quality. The service provider delivered the project on time and ensured prompt responsiveness throughout the engagement. Their innovative approach was outstanding.

"
Verified Review
Rating: 5 out of 5

Explore further

Go deeper

Build and integrate

Automate and analyse

Sectors we go this deep on

Related Insights

Engineering notes on payments, security and the back office work that sits behind a regulated build.

WhatsApp
Email
Book a Meeting