04 — Your licence, their product
The platform layer that lets a licensed institution safely expose accounts, payments and cards to third-party programmes.
BaaS turns a bank into a platform, and platforms fail differently to banks. The risk is no longer a single balance sheet — it is dozens of programmes with different risk appetites operating under one licence, each capable of generating an obligation the bank must answer for.
The platform we build assumes that. Programme isolation, per-programme limits, real-time exposure monitoring and a kill switch that works are not features added at scale; they are the architecture. Onboarding a programme should be a configuration, and offboarding one should not require an engineer.
Common questions
What is the difference between BaaS and embedded finance?
BaaS is the supply side: a licensed institution exposing regulated capability through APIs. Embedded finance is the demand side: a non-financial product consuming that capability so its users never leave. The same infrastructure serves both, but the risk sits with the licence holder in either case.
Who is responsible for compliance in a BaaS arrangement?
The licence holder, always. A programme partner can operate controls day to day, but the regulator holds the institution accountable for customer due diligence, monitoring and reporting. Platforms that assume otherwise are the ones that end up in enforcement actions.
How do you prevent one programme from harming the others?
Isolation at the ledger, limits enforced in the transaction path rather than in reporting, real-time exposure monitoring per programme, and an offboarding procedure that has been rehearsed. If disabling a programme requires a code change, it will not happen fast enough.
Next capability
Embedded finance
Bring us the hard part.
Forty-five minutes with the people who would actually run the build.