queue|onehello@queueone.io

A regulated fintech

As CTO and part owner

Getting regulator-ready reporting out of a white-labeled system I did not control, for a cash-to-crypto network that was live and taking real money.

  • FINTRAC reporting
  • KYC and identity verification
  • Third-party financial APIs
  • Non-custodial fund movement

Context

I was CTO and part owner. The company is not named here — the transferable substance is the regulated-integration work rather than the sector. It ran a live network of cash-to-crypto ATMs, with real customers and real regulatory obligations, and separately built an in-house SaaS product for automated recurring investment.

The problem

The ATM network ran on a white-labeled vendor platform. That is the ordinary condition of most integration work and the least discussed: the system of record belongs to someone else, it exposes what it chooses to expose, and you are nonetheless the one accountable to the regulator for reporting that it was never designed to produce.

Compliance is also not a feature you add afterwards. FINTRAC obligations and identity verification constrain the product design, and retrofitting them into a platform that already moves money is the expensive version of the problem.

What I built

FINTRAC reporting on top of a vendor platform
Scripts extracting and shaping the data the regulator required out of a white-labeled system that offered no such export — the recurring shape of integration work, where correctness is judged by someone outside the building.
KYC in the onboarding path
Identity verification integrated as part of onboarding rather than bolted on beside it, in both the ATM network and the SaaS product.
Non-custodial fund movement
Moving funds from customer chequing accounts through third-party APIs without the platform ever holding the asset — money crossing a boundary between systems that do not trust each other, which is the integration problem in its least forgiving form.

Outcome

The ATM network operated as a live regulated business and its reporting obligations were met. The in-house SaaS product shipped but never found traction — worth stating plainly, because the engineering was sound and the market answer was still no. The durable value was the pattern: when the system of record is someone else's, correctness becomes an extraction and reconciliation problem.

Sound like something you have?

Start a conversationhello@queueone.io

More work

  • KeystoneOS

    Idempotent webhook ingestion keyed on provider event IDs, anonymous-to-identified event backfill, CREA RESO OData sync, and pgvector semantic search over listings.

  • A major Canadian airline

    Booking, seat maps, flight search and automated baggage handling, integrated against airline reservation systems under a contractual throughput SLA.

  • Surefire Fundraising

    A Laravel platform handling catalog, checkout and transactional email for an Edmonton client whose business was built on top of it.

All work