Services
Three capabilities, one discipline.
Everything below is built to the same test: if it stops, who notices; if it's wrong, who pays; if it's audited, what does the trail show.
01
Mission-critical architecture & delivery
A system is decided long before the first line of code. We write the decisions down — then we carry them to production.
- System architecture for critical operations. Multi-tier transactional platforms: application, compute, reporting and interface tiers, and the boundaries between them. Registry and control systems where the database is the source of truth for real-world obligations — money, capacity, entitlements.
- Born-digital processes, on cryptographic foundations. Not paper workflows projected onto screens: processes designed digital from the first step, where signature, authorization, transmission and archiving form one mathematically protected chain. Turnaround falls from days to seconds, every step leaves verifiable evidence, and the process's correctness can be demonstrated to outside parties — publicly, without disclosing the underlying data.
- Analytical accounting & general ledger design. User management, instrument, account, product, transaction — the object model of money. Booking templates, balance and inventory containers, loro/nostro logic, GL mapping. For banks, investment service providers, pension funds — and for markets that settle in megawatt-hours instead of forints.
- Specifications that survive contact with development. Business and functional specifications, logical system plans, use cases, interface contracts. Written to be built from, and argued about before the money is spent.
- Audit & due diligence. Operational and IT due diligence of existing systems and vendors — what is actually there, what it costs to keep, what it costs to leave.
- Calculation design. Annuity schedules with variable rates and terms, day-count and rounding regimes that survive reconciliation, allocation algorithms for quotation and settlement.
- Delivery discipline. Coding standards, code review, test coverage tied to the specification, release management. Agile where it helps, written down always.
Proof point
For a factoring operation we derived the agreement calculation from first principles — a recurrence over variable monthly rates and instalments that solves for any one unknown: instalment, rate, present value or term. The spreadsheet the business signed off is the same mathematics the engine runs.
02
Distributed algorithms & systems
Correctness at scale is a design property, not a load test result.
- High-throughput transaction processing. Six-sigma-operated platforms over terabyte-class databases; locking, journaling and idempotency treated as first-class features. The neo-core banking system we designed and built books 10–15,000 transactions per second per node and serves 100,000 client accounts per node — on 2 CPUs and 4 GB of RAM, not a cluster the size of a data centre.
- Two-phase commit without the central manager. Our own distributed transaction protocol needs no central transaction-manager server — which is precisely what makes linear scaling honest: add a node, get a node's worth of throughput, no coordinator to saturate.
- Distributed registries without a single point of truth-keeping. Architectures where institutions maintain their own cryptographically chained records, interlinked so the whole stays verifiable without any participant holding the full dataset. Includes our decentralized inventory management design — P&L computable without booking through client accounts.
- State machines for money. Offers, agreements, transfers, settlement runs — modeled as explicit state machines, designed for replay, reconciliation and audit.
- Message-driven pipelines. NATS, Kafka, RabbitMQ; ingestion-to-publication flows where the output is a market event — tender evaluation, optimization, transparency publishing.
- Algorithms for the hard 1%. Allocation and rounding schemes that stay consistent under concurrency; optimization models for capacity procurement — including objective functions too complex to invert, solved numerically; the edge cases everyone else postpones.
Proof point
The balancing-energy procurement system we designed for a national transmission system operator ingests daily tender bids, feeds an optimization engine, and publishes results to the European transparency platform — a pipeline where an implausible number is not a typo, it is an incident.
03
Applied cryptography
Fifteen years of cryptographic engineering — protocols we design, prove, publish and run in production. Not theoretical cryptography that lives in papers: constructions that clear audits, carry licences and settle payments. In the EU, perhaps one or two groups do this end to end. We are one of them.
Why purpose-built beats generic ZK
Generic zero-knowledge systems are a marvel — and usually the wrong tool. They bring trusted ceremonies, heavy proving times and a dependency you cannot swap. We design purpose-built protocols instead: proofs shaped to the exact business property that must be shown. The result is speed (sub-100 ms where generic circuits take seconds), no trusted setup to explain to an auditor, and interchangeable cryptographic primitives — when a curve or scheme ages, the construction survives. That is what turns cryptography from a cost line into a business advantage.
- Threshold cryptography. Distributed key generation and management where the complete private key never exists — anywhere, at any moment. Our published NPVDKGRS scheme (non-interactive, publicly verifiable DKG and resharing over BLS12-381) runs under a MiCA-licensed platform today, and has been reviewed by university cryptographers.
- Cryptographic authorization. Our own entitlement protocol built on NPVDKGRS: access rights as cryptographic facts, not database rows. Who may act, who did act, and when — provable; delegation without ever handing over a key; rights revocable instantly. Institutional threshold signatures where the decision is accountable but the individuals are not exposable to pressure.
- Threshold command & control. The two-person rule, generalized: any k-of-n approval scheme enforced by mathematics rather than procedure — a seal that never exists in one piece, usable in seconds, with no HSM and no trusted ceremony. Signing is single-message (non-interactive), so it works over slow, degraded or one-way links; signatures stay constant-size however many parties took part. When a keyholder changes — reassignment, loss, suspected compromise — shares are redistributed in fractions of a second while the organization's public seal stays unchanged.
- Provable process integrity. Sealed submissions that no operator can open early — provably; chained, tamper-evident procedural trails; compliance demonstrated to outside parties by zero-knowledge-style proofs, without surrendering the underlying data. Built for procurement, tendering, classified-context oversight and any procedure where "trust us" is no longer an acceptable answer.
- Post-quantum readiness. Quantum-safe algorithm work and PQC migration design against the EU's 2030 critical-infrastructure deadline: cryptographic inventories, hybrid transition schemes — and a lattice-based post-quantum variant of our own threshold scheme, designed and awaiting implementation.
- Digital cash, done properly. We authored the Pactena Protocol — private, offline-capable, instant payments where double-spending mathematically reveals the fraudster — and Qashmore, the payment solution built on it.
- Proof systems sized to the problem. Selective disclosure, commitments, accumulators, proof-of-reserves constructions — lightweight, purpose-built proofs where a full SNARK is more than the problem needs.
- Protocol review. Second opinions on cryptographic designs before they become commitments — key ceremonies, custody schemes, signing flows, recovery paths.
Proof point
Trustless but supervised: in our key-generation scheme, independent parties create and reshare a threshold key with every step publicly verifiable — and when a keyholder changes, the shares are redistributed in seconds, with no ceremony and no HSM. The property a regulator wants, delivered as mathematics rather than policy.
Where it runs
Financial core systems
Core banking, securities settlement, factoring, pension fund and fund accounting. Two decades of ledgers in production.
Energy & commodities
Registry, settlement and procurement systems for energy markets — proven on the power side (exchange clearing, TSO balancing tenders, European transparency publishing), built to carry gas, oil and other commodities under the same discipline.
Regulated digital assets
MiCA-licensed platform engineering, tokenization with real analytical accounting behind it, DORA-conscious operations.
Public sector & defence
Where process integrity is the mission. Born-digital administration instead of digitized paper; command and entitlement chains enforced by k-of-n mathematics; sealed procedures with tamper-evident trails; oversight satisfied by proofs, not by handing over the data. The building blocks above — threshold key management, cryptographic authorization, provable process integrity — carry directly; the same discipline that passed financial-supervisory scrutiny applies to procedures where the stakes are higher still. We speak this domain's language: sovereignty, no foreign black boxes, open and independently auditable algorithms.
How an engagement starts
- 01A conversation. You describe the system, we ask the uncomfortable questions early.
- 02A written scope. Short, priced, honest about unknowns.
- 03Work in the open. Specifications, decisions and progress visible to you throughout.