BRUNA

Forex and fintech software

Cyprus hosts one of the largest concentrations of regulated brokers in Europe. We build the systems that sit behind the trading platform: onboarding, back-office, reconciliation and the reporting a CySEC-regulated firm has to produce on demand.

Cyprus is one of Europe's densest clusters of regulated investment firms, most of them concentrated in Limassol. The trading platform is rarely the problem. The problem is everything around it: onboarding that stalls, spreadsheets holding reconciliation together, and reporting that takes three people a week to assemble.

What we build for brokers and fintech firms

The trading platform stays. We build the systems that feed it and the systems that answer for it.

  • Client onboarding portals — application, document upload, identity and sanctions screening, appropriateness assessment, and a reviewer queue with a full audit trail.
  • Back-office and CRM — account lifecycle, deposits and withdrawals, IB and partner structures, internal permissions that match who is actually allowed to see what.
  • Reporting pipelines — pulling data out of the trading platform, the payment providers and the ledger into one place, on a schedule, with the numbers reproducible after the fact.
  • Reconciliation — matching platform records against PSP settlements and bank statements, and surfacing the breaks instead of burying them in a spreadsheet.
  • Payment integrations — card acquirers, bank transfers and alternative methods, with routing and failure handling that does not lose a deposit silently.

Why regulated firms need custom software

Off-the-shelf broker back-office products exist, and for some firms they are the right answer. They stop being the right answer at the point where your obligations, your partner structure or your product mix stop matching the vendor's assumptions.

The usual trigger is reporting. A regulated firm has to produce specific numbers, on a specific basis, and defend how they were calculated. When the data lives in four systems that do not agree, the reconciliation happens manually every period, and the manual step is where both the cost and the risk sit.

Working within a regulated environment

We build to the requirements your compliance function defines. That is a deliberate boundary: your compliance officer, legal counsel or regulatory consultant interprets CySEC and MiFID II obligations, and we implement systems that satisfy their interpretation and produce the evidence they need.

In practice that shapes the engineering:

  • Audit trails are not optional. Every state change that touches a client account is recorded with actor, timestamp and prior value.
  • Data handling is scoped from day one. Client data is personal data under GDPR, and access controls, retention and deletion get designed in rather than retrofitted.
  • Reports must be reproducible. A figure produced last quarter has to be reproducible from stored data this quarter, which rules out pipelines that overwrite their own inputs.
  • Deployment is boring on purpose. Staged environments, reviewed changes and rollback paths, because an outage in a client-facing financial system is not a normal outage.

How an engagement runs

We start with a scoping phase: sitting with the people who currently do the work manually, mapping where data actually lives, and identifying which systems must be integrated rather than replaced. That produces a fixed scope and a fixed price range before any development starts.

Delivery is staged. The part of the system that removes the most manual work goes live first, rather than everything arriving at the end. You get working software early and can change direction while changing direction is still cheap.

At handover you get the source code, the infrastructure configuration and the documentation. We are available for ongoing maintenance and further development, but you are not dependent on us to keep the system running.

Talk to us

If you are running a regulated firm in Cyprus and the reporting cycle is eating your team, tell us what the process looks like today. We will tell you honestly whether it is a software problem, a process problem, or something an existing product already solves.

Common questions

Do you build software for CySEC-regulated firms?

Yes. Most of our fintech work sits behind a regulated entity: client onboarding, back-office, reconciliation and reporting. We build to the requirements your compliance team specifies. We are a software company, not a regulatory consultancy, so we implement against their interpretation rather than issue our own.

Can you integrate with MT4, MT5 or our existing trading platform?

Yes. The trading platform is usually the one system nobody wants rebuilt, so we integrate rather than replace. Typical work is pulling trade and account data into a back-office or reporting system through the platform manager API or a supported bridge.

Can you connect our onboarding flow to KYC and AML providers?

Yes. Identity verification, document checks, sanctions and PEP screening are almost always third-party services with an API. We build the onboarding flow and the audit trail around them, so a reviewer can reconstruct why an account was approved or rejected.

Who owns the source code?

You do. We hand over the full repository, infrastructure configuration and documentation at the end of every project. For a regulated firm this matters more than usual, since an auditor may ask how a reported number is produced.

Tell us what is not working

Describe the process that eats your team's week. We will tell you honestly whether it is a software problem.

Start a conversation

Last updated: