React Native app enabling instant cross-border transfers with biometric auth, real-time FX rates, and compliance checks across 12 currencies.
A FinTech startup needed a consumer-facing cross-border payment app that could clear regulatory requirements in Japan, UK, and Singapore simultaneously. Existing solutions were too slow, too expensive, or couldn't handle multi-currency wallets with real-time FX.
React Native codebase with iOS/Android parity. Plaid for bank account linking, a custom FX rate aggregator polling 4 providers, and a compliance engine that runs KYC/AML checks synchronously before any transfer initiates. All PII encrypted at rest with AES-256.
Shipped to App Store and Play Store in 18 weeks. 4.8-star average rating from 2,000+ early users. Sub-2-second transfer confirmation. Zero compliance incidents in the first 6 months of operation.
SYSTEM ARCHITECTURE
Zero-trust financial transaction architecture featuring biometric client signing, pre-flight AML/KYC guardrails, dynamic FX multi-quote aggregation, and append-only cryptographic ledger.
Prohibited all SQL UPDATE commands on account balances. Every financial operation is represented by balanced credit and debit ledger entries, ensuring total regulatory compliance.
Eliminated foreign exchange rate slippage risk during volatile market swings by caching locked institutional quotes in Redis with strict atomic TTL timeouts.
TECHNICAL DEPTH
Biometric auth (Face ID / Fingerprint) as the primary auth factor with PIN fallback. JWT refresh tokens stored in iOS Keychain / Android Keystore — never in AsyncStorage. Certificate pinning prevents MITM attacks on the API layer.
Custom rate aggregator polls 4 FX providers every 30 seconds, applies a spread, and locks the rate for 90 seconds during checkout. Redis stores the locked rate with TTL. Expired rates reject the transaction — no rate mismatch risk.
KYC via Jumio SDK integrated into onboarding. AML screening runs on every transfer via Sardine API. Flagged transactions enter a manual review queue with 24-hour SLA. Full audit trail stored in append-only PostgreSQL tables.