Since 2015
11 years
Operating in fintech delivery
Founded 2015 on payments and card infrastructure; digital-asset delivery from 2018 onward.
EU-based crypto & fintech engineering
TrustChange builds and scales exchange, custody and payment infrastructure for crypto startups, licensed VASPs, PSPs, EMIs and neobanks — with MiCA, PSD2 and AML controls engineered in from the first sprint.
Engagement models: dedicated teams · staff augmentation · fixed-scope build · CTO advisory
Exchange & matching engines
Order books, risk, settlement
MPC wallets & custody
Key management, signing policy
On/off-ramps & PSP rails
SEPA, card and stablecoin flows
Our custody stack passed internal review and failed the auditor's. TrustChange rebuilt key management on MPC, produced the operational-control evidence the auditor actually asked for, and stayed in the remediation calls with us until it closed. We kept our licensing timeline — and never had to hire a blockchain engineer to do it.
Who owns delivery
TrustChange is a partner-led firm. The architecture behind your matching engine, custody stack or licensing file is designed and signed off by a founder — never handed down to a rotating bench.
Co-founder · Chief Technology Officer
Designs the systems that are not allowed to lose money: order-book state machines, MPC key ceremonies, and the reconciliation path underneath them.
Co-founder · Managing Partner
Runs delivery for EMI, PSP and neobank platforms — scope, team composition, and the release discipline an auditor expects to find already in place.
Co-founder · Head of Compliance Engineering
Turns the licensing file into shipped code — the controls, evidence trails and reporting a supervisor actually opens.
Delivery model
One founder stays accountable for the whole engagement — from the discovery workshop to the audit that follows go-live.
Practice areas
Exchange cores, custody, payment rails and compliance — engineered by one EU group against the same architecture, security and evidence standard, whether you need the whole product built or two senior people inside a team you already have.
How to read a row
01 Exchange core
Order books that stay correct under load. Ingress, risk and matching run as separate deterministic services, so a trading day can be replayed from the event log and reconciled against the ledger fill by fill.
Engagement Fixed-scope build Dedicated team
02 Custody
Hot, warm and cold tiers with key material handled the way an auditor expects to find it: threshold signing for operating balances, air-gapped multi-sig for reserves, and a written ceremony behind every key that exists.
Engagement Dedicated team CTO advisory
Automated signing for withdrawals inside the daily envelope.
Threshold shares split across operators and an HSM, no full key ever assembled.
Air-gapped, quorum-approved, moved only under a recorded ceremony.
03 Payment rails
One merchant-facing API in front of many providers. Routing, retries and failover are policy you can change, not a release you have to ship — and every leg lands in a ledger that balances fiat against on-chain settlement.
Engagement Staff augmentation Fixed-scope build
04 Control plane
Regulatory obligations built as product surfaces instead of spreadsheets. Screening, Travel Rule messaging and monitoring sit inside the transaction path, and every decision leaves an artefact a supervisor can follow.
Engagement Discovery & PoC CTO advisory
Written against MiCA AMLR PSD2 FATF Travel Rule
Every practice ships the same evidence pack — architecture decision records, threat model, test evidence and audit trail — so a supervisor's question is answered from the repository rather than from memory.
Buyer due diligence
Ownership, compliance drift, accountability, and what happens after go-live. Those four are where engineering partnerships fail — so they are answered here the way our contracts read, not the way a pitch deck reads.
You do, from the first commit. Every engagement is bespoke: repositories, infrastructure-as-code, threat models and architecture decision records sit under your organisation and your cloud accounts while the work is happening — not once a final invoice clears.
TrustChange does not resell a white-label exchange core, does not license a shared matching engine back to the client, and holds no escrow clause that turns leaving into a negotiation. Offboarding is a handover: credentials, runbooks, and a walkthrough with the engineers who wrote the system.
Regulatory drift is planned for, not billed as a surprise change request. Obligations are baselined during discovery — licence path, Travel Rule thresholds, safeguarding and reporting duties — then re-checked at every phase gate, so a revised technical standard normally lands as a scoped adjustment inside the roadmap you already approved.
When a change genuinely moves the build envelope, the impact arrives in writing before a branch is opened: what shifts, what it costs, and what the alternative is when the launch date is fixed.
One contract, one team, one escalation path. Each engagement runs with a named delivery lead and solution architect plus a fixed core of senior engineers and QA working your backlog on a shared sprint cadence. Nothing is re-bid per ticket, and nobody rotates off without a documented handover — the people on the kickoff call are the people who ship.
Capacity flexes at phase boundaries, up or down, when the roadmap needs it. Accountability does not move with it.
Severity tiers and response windows are agreed in writing before launch, and the operational surface is handed over documented rather than described. Beyond incident response and a written post-mortem, support covers the maintenance a regulated digital-asset product genuinely needs:
Most engagements start exactly there. Discovery reads what already exists — services, data model, custody design, provider integrations — and the output is a plan for your system, not a rewrite pitched as a rescue.
From there engineers either embed in your sprint cadence, review standards and definition of done, or take a fixed-scope module — a settlement engine, an MPC signing flow, an on/off-ramp integration — and deliver it against interfaces your team owns.
A technical call first, then a paid discovery of two to four weeks. It ends in artefacts you keep whether or not the build goes ahead: a reference architecture, a threat model, a compliance obligation map for your licence path, and a delivery plan with fixed phase gates and a cost envelope.
Build starts only once that plan is signed. Stopping after discovery is deliberately easy — an engineering partner that needs a long contract to prove its worth is the wrong partner for infrastructure this sensitive.
Discovery call 45 minutes
One call with our solution architects, and you leave with a scoped technical assessment: the target architecture, the compliance surface it has to satisfy, and a delivery sequence you can put in front of your board.
Inside the assessment
Prefer to write first? [email protected]