OkeiloCrowdfundingPlatform
Devehope designed and implemented a crowdfunding and investment platform operating under a Czech National Bank licence. Alongside the product, we acted as CTO as a Service — responsible for architecture, infrastructure and the technical implementation of DORA.

Technology
Identity,moneyandcomplianceinoneplatform
An investment platform cannot treat identity, money, contracts and compliance as separate features. Before an investor participates, the system has to know who they are, whether they meet the required conditions, which terms apply and whether the documents have been accepted.
Once money starts moving, bank transactions have to stay consistent with the platform’s own record of payments, investments and balances. Okeilo also needed an internal operating system for evaluating projects, controlling funding and repayments, and keeping an auditable history.
- 1
Investor experience
Onboarding, projects, wallet, investing and portfolio.
- 2
Operations
Project approval, KYC, payments, documents and reporting.
- 3
Core platform
Identity, permissions, investment engine, transactions and audit.
- 4
Infrastructure and integrations
BankID, Raiffeisen, Cloudflare R2, PostgreSQL and monitoring.
One domain model across the investor product and the operating system behind it.
Regulatoryrulesasexecutablesoftware
Regulatory requirements were implemented directly into application state and business logic, rather than left as manual checklists. The onboarding and investment journey combines identity, banking, questionnaires and eligibility before an investment can proceed.
The platform also reacts to identity-data changes reported through BankID and can require renewed verification before further investment activity.
- Identity verification through BankID or a manual path
- Bank account and phone verification
- Investor questionnaire and loss-capacity assessment
- 2FA for sensitive actions
- Eligibility checks before an investment can proceed
Compliance conditions are executable rules enforced by the platform.
Afinancialengineconnectedtorealbanking
The architecture separates an expected payment from the bank transaction that eventually fulfils it. Payments carry their own type, direction, due date, investment relationship and expected banking details. Transactions are imported separately through the Raiffeisen API and reconciled against them.
Matching can use the variable symbol, destination account, counterparty account and counterparty identity. Strong matches can be processed automatically. Ambiguous cases stay available for manual review. The same layer supports wallets, funding, repayment schedules, withdrawals, refunds and export of outgoing payments.
- 01
Bank transaction
- 02
Variable symbol, account and counterparty
- 03
Match confidence
- 04
Automatic reconciliation or manual review
- 05
Payment completed
- 06
Wallet, investment and financial state updated
Reconciliation keeps the internal ledger aligned with the bank.
Contractsgenerated,signedandstoredasoneworkflow
Investment documents are generated from structured templates filled with data from users, projects, investment plans and transactions, then rendered to PDF inside the operational workflow. Signing sensitive documents is protected with 2FA and tied to the verified identity.
Public project media and private documents use different Cloudflare R2 areas. Private files are exposed only through temporary authorized URLs, and especially sensitive identity documents receive an extra encryption layer before storage.
Investment terms → contract generation → review → 2FA signature → final document → protected storage
Thefullprojectlifecycle,notonlytheinvestorinterface
A project moves through controlled stages: initial review, indicative approval, due diligence, investment committee evaluation, documentation, funding, active repayment and completion. Internal roles, versioned reports and committee decisions model the work of bringing an opportunity to market.
Administrators manage KYC, investments, bank transactions, payment schedules and documents from the same system. Payload CMS handles editorial content, while regulated business data stays in the core application model.
- Investor platform
- Project-owner workspace
- Partner portal
- Internal operations system
- Public website and CMS

Engagementbuiltintothefinancialmodel
The loyalty layer makes long-term investing more engaging without turning the product into superficial gamification. Tier benefits can change the conditions of an investment, and referral commission conditions are locked when a relationship is created, then feed into the payment schedule and wallet.
That required loyalty to behave like a financial subsystem, not a decorative frontend feature.
- XP earned through investment activity
- Tiers with fee benefits and earlier project access
- Achievements and badges based on investor behaviour
- Personal investment goals and partner offers
- A referral network with XP and financial commissions

Productionoperationsforaregulatedenvironment
Responsibility continued past application development. The platform uses separated development, beta, build and production environments. Applications run in Docker with rolling releases. Network access is restricted through firewall rules and SSH keys, and databases communicate on an internal container network.
Prometheus, Loki, Grafana and Grafana Alloy collect server metrics, container telemetry and application logs. Audit logs separately record important changes to users, projects, investments, payments and documents.
Devehope also led the technical implementation of DORA requirements: ICT risk controls, access management, monitoring, operational resilience, infrastructure documentation and management of technology dependencies.
Wheretheworksat
The hardest decisions sat between finance, regulation, user experience, operations and software architecture.
Technical direction
Product and system design, technology choices and development leadership as CTO as a Service.
Financial systems engineering
Wallets, expected payments, bank import and reconciliation, repayments and outgoing payment export.
Rules in the domain model
Onboarding, eligibility, 2FA and identity changes enforced by the platform before money can move.
Infrastructure and DORA
Environments, observability, audit history and the technical delivery of operational-resilience requirements.
Oneenvironmentfortheproductandthebusinessbehindit
Okeilo connects the investor-facing product with the operational infrastructure required to run an investment platform. Onboarding, project evaluation, investments, banking, contracts and investor engagement share one domain model and administration layer.
For Devehope, it is the kind of project where architecture, FinTech engineering, regulated workflows, security and long-term technical ownership come together.
Selectedprojects
From regulated FinTech and RegTech platforms to AI systems, marketplaces, and large e-commerce ecosystems.









