[FinTech · Investment platform]

OkeiloCrowdfundingPlatform

Devehope designed and implemented a crowdfunding and investment platform operating under a Czech National Bank licence. Alongside the product, we acted as CTO as a Service — responsible for architecture, infrastructure and the technical implementation of DORA.

Okeilo
FinTech
Okeilo crowdfunding platform on desktop and mobile

Technology

Next.js
React
Node.js
PostgreSQL
Prisma
Payload CMS
BankID
Raiffeisen API
Docker
Cloudflare
The challenge

Identity,moneyandcomplianceinoneplatform

An investment platform cannot treat identity, money, contracts and compliance as separate features. Before an investor participates, the system has to know who they are, whether they meet the required conditions, which terms apply and whether the documents have been accepted.

Once money starts moving, bank transactions have to stay consistent with the platform’s own record of payments, investments and balances. Okeilo also needed an internal operating system for evaluating projects, controlling funding and repayments, and keeping an auditable history.

  1. 1

    Investor experience

    Onboarding, projects, wallet, investing and portfolio.

  2. 2

    Operations

    Project approval, KYC, payments, documents and reporting.

  3. 3

    Core platform

    Identity, permissions, investment engine, transactions and audit.

  4. 4

    Infrastructure and integrations

    BankID, Raiffeisen, Cloudflare R2, PostgreSQL and monitoring.

One domain model across the investor product and the operating system behind it.

Compliance

Regulatoryrulesasexecutablesoftware

Regulatory requirements were implemented directly into application state and business logic, rather than left as manual checklists. The onboarding and investment journey combines identity, banking, questionnaires and eligibility before an investment can proceed.

The platform also reacts to identity-data changes reported through BankID and can require renewed verification before further investment activity.

  • Identity verification through BankID or a manual path
  • Bank account and phone verification
  • Investor questionnaire and loss-capacity assessment
  • 2FA for sensitive actions
  • Eligibility checks before an investment can proceed

Compliance conditions are executable rules enforced by the platform.

Financial systems

Afinancialengineconnectedtorealbanking

The architecture separates an expected payment from the bank transaction that eventually fulfils it. Payments carry their own type, direction, due date, investment relationship and expected banking details. Transactions are imported separately through the Raiffeisen API and reconciled against them.

Matching can use the variable symbol, destination account, counterparty account and counterparty identity. Strong matches can be processed automatically. Ambiguous cases stay available for manual review. The same layer supports wallets, funding, repayment schedules, withdrawals, refunds and export of outgoing payments.

  1. 01

    Bank transaction

  2. 02

    Variable symbol, account and counterparty

  3. 03

    Match confidence

  4. 04

    Automatic reconciliation or manual review

  5. 05

    Payment completed

  6. 06

    Wallet, investment and financial state updated

Reconciliation keeps the internal ledger aligned with the bank.

Documents

Contractsgenerated,signedandstoredasoneworkflow

Investment documents are generated from structured templates filled with data from users, projects, investment plans and transactions, then rendered to PDF inside the operational workflow. Signing sensitive documents is protected with 2FA and tied to the verified identity.

Public project media and private documents use different Cloudflare R2 areas. Private files are exposed only through temporary authorized URLs, and especially sensitive identity documents receive an extra encryption layer before storage.

Investment terms → contract generation → review → 2FA signature → final document → protected storage

Operations

Thefullprojectlifecycle,notonlytheinvestorinterface

A project moves through controlled stages: initial review, indicative approval, due diligence, investment committee evaluation, documentation, funding, active repayment and completion. Internal roles, versioned reports and committee decisions model the work of bringing an opportunity to market.

Administrators manage KYC, investments, bank transactions, payment schedules and documents from the same system. Payload CMS handles editorial content, while regulated business data stays in the core application model.

  • Investor platform
  • Project-owner workspace
  • Partner portal
  • Internal operations system
  • Public website and CMS
Okeilo investment opportunities on desktop and mobile
Loyalty

Engagementbuiltintothefinancialmodel

The loyalty layer makes long-term investing more engaging without turning the product into superficial gamification. Tier benefits can change the conditions of an investment, and referral commission conditions are locked when a relationship is created, then feed into the payment schedule and wallet.

That required loyalty to behave like a financial subsystem, not a decorative frontend feature.

  • XP earned through investment activity
  • Tiers with fee benefits and earlier project access
  • Achievements and badges based on investor behaviour
  • Personal investment goals and partner offers
  • A referral network with XP and financial commissions
Okeilo investor dashboard with portfolio and cashflow
Infrastructure

Productionoperationsforaregulatedenvironment

Responsibility continued past application development. The platform uses separated development, beta, build and production environments. Applications run in Docker with rolling releases. Network access is restricted through firewall rules and SSH keys, and databases communicate on an internal container network.

Prometheus, Loki, Grafana and Grafana Alloy collect server metrics, container telemetry and application logs. Audit logs separately record important changes to users, projects, investments, payments and documents.

Devehope also led the technical implementation of DORA requirements: ICT risk controls, access management, monitoring, operational resilience, infrastructure documentation and management of technology dependencies.

Wheretheworksat

The hardest decisions sat between finance, regulation, user experience, operations and software architecture.

Architecture

Technical direction

Product and system design, technology choices and development leadership as CTO as a Service.

FinTech

Financial systems engineering

Wallets, expected payments, bank import and reconciliation, repayments and outgoing payment export.

Compliance

Rules in the domain model

Onboarding, eligibility, 2FA and identity changes enforced by the platform before money can move.

Ownership

Infrastructure and DORA

Environments, observability, audit history and the technical delivery of operational-resilience requirements.

The result

Oneenvironmentfortheproductandthebusinessbehindit

Okeilo connects the investor-facing product with the operational infrastructure required to run an investment platform. Onboarding, project evaluation, investments, banking, contracts and investor engagement share one domain model and administration layer.

For Devehope, it is the kind of project where architecture, FinTech engineering, regulated workflows, security and long-term technical ownership come together.

Selectedprojects

From regulated FinTech and RegTech platforms to AI systems, marketplaces, and large e-commerce ecosystems.

Let’sdiscusswhatcomesnext

Whether you already have a clear plan or are still shaping the idea, we can help you clarify scope, priorities, and the most effective path forward.
Devehope Technologies s.r.o. Nové Sady 988/22 29000 Brno, Czech Republic
Reg. No.:19549997
Data Box:m99wavh
Loading verification...