We Engineer Critical Infrastructure
RegTech · FinTech · B2B SaaS
We architect high-security transactional systems, AI-powered compliance engines, and proprietary B2B infrastructure for enterprises that cannot afford failure.
Every Build Ships with AkidOTP
We don't just build apps — we provide the plumbing.
AkidOTP is our proprietary Reverse-Auth Infrastructure. Every Xontric project includes WhatsApp & Telegram-based verification as a native component — eliminating SMS costs and greatly reducing fraud risk.
Explore AkidOTP →What We Engineer
Three domains of specialization. One standard of excellence.
RegTech & Compliance Engineering
We build AI-powered compliance engines that bridge machine intelligence with regulatory standards. Our proprietary validation filters eliminate AI hallucinations before they reach compliance-critical outputs.
- Document Intelligence
- Multi-Model Vision Pipelines
- Regulatory Validation Filters
- Audit Trail Architecture
- Computer Vision
- LLM Integration
- BS 7671 / ISO Standards
- Custom Validation Logic
FinTech & Transactional Infrastructure
We engineer high-security transactional cores with atomic data integrity. Real-time bidding, wallet operations, and biometric authentication for environments where every transaction must be auditable and reversible.
- Atomic Wallet Operations
- Real-Time Bidding Engines
- Biometric Auth (WebAuthn/FIDO2)
- Server-Side Locking & Race Protection
- PostgreSQL RPC
- Socket.io
- WebAuthn
- Row-Level Security
B2B SaaS & API Infrastructure
We build proprietary platforms that replace expensive third-party dependencies. Self-serve API portals, usage-based billing, multi-channel authentication — infrastructure that our clients' clients consume.
- Self-Serve API Portals
- Usage-Based Billing
- Multi-Channel Auth (WhatsApp/Telegram)
- Developer Documentation Engines
- REST API Design
- Webhook Architecture
- Payment Gateway Integration
- API Key Management
The Xontric Process
Five stages from concept to production. Nothing ships without approval at every gate.
We audit your existing infrastructure, interview stakeholders, and map your technical requirements against regulatory and security constraints.
- Technical Audit
- Stakeholder Interviews
- Threat Modeling
- Requirements Architecture
We design the system blueprint — database schemas, API contracts, security layers, and deployment topology. Nothing is built until the architecture is approved.
- System Design
- Database Schema
- API Contracts
- Security Architecture
We build in 2-week sprints with continuous integration. Every component is tested in isolation before integration. You receive weekly progress reports.
- Sprint Development
- CI/CD Pipeline
- Component Testing
- Weekly Reporting
Penetration testing, load testing, accessibility audit, and cross-browser/cross-device validation. We break it before your users do.
- Penetration Testing
- Load Testing
- Accessibility Audit
- Cross-Platform Validation
Zero-downtime deployment with rollback capability. Post-launch monitoring, incident response, and continuous optimization. We don’t disappear after launch.
- Zero-Downtime Deploy
- Monitoring & Alerting
- Incident Response
- Performance Optimization
We don’t just build and leave. Every Xontric system is monitored, maintained, and actively managed — with optional long-term support — so it keeps performing long after launch.
Platforms We’ve Built
A selection of platforms we designed and built — each carries our mark and links back to us. They represent a sample of our work, not our full portfolio.
The AI compliance engine for UK electrical, gas, plumbing, fire-safety and surveying engineers. Phone-camera AI vision extracts every circuit and data plate, cross-references BS 7671:2018+A4:2026, GSIUR 1998, BS 5839 and WRAS, and renders QR-verified PDF certificates in seconds. Hallucinations filtered before output. Built, maintained, and actively managed by Xontric Systems.
Libya’s first registered e-auction platform — an Arabic-first PWA combining time-bound auctions with a Buy Now marketplace. Atomic escrow wallet operations via PostgreSQL RPC, anti-snipe real-time bidding over Socket.io, and WebAuthn biometric login. Built, maintained, and actively managed by Xontric Systems.
Our proprietary reverse-auth platform — verify users via WhatsApp, Telegram, email or SMS instead of costly SMS OTP. Up to 90% cheaper than traditional SMS with strong phishing-resistance. Self-serve API keys, real-time webhooks, and a subscribe-and-use payment gateway accepting cards (Visa), bank transfer, and crypto (Bitcoin, USDT, ADA). Built, maintained, and actively managed by Xontric Systems.
An Arabic-first, end-to-end encrypted messaging platform — free voice and video calls, file and media sharing, all working today. Installable from any browser, no app store required. WebRTC calls, ECDH P-256 + AES-256-GCM encryption, and real-time delivery over Cloudflare Durable Objects. More features in active development. Built, maintained, and actively managed by Xontric Systems.
These 4 projects are a public selection of our work. Xontric Systems maintains a private repository of NDA-protected architecture for enterprise, governmental, and private banking clients.
Jawaab
Messaging built to serve the Arab world first — write in your own language and everyone understands you, with free calls, video, and file sharing
WebRTC calls that work on any phone, no app store.
Send photos, videos, voice notes, and PDFs.
ECDH P-256 + AES-256-GCM; the server never sees plaintext.
Type in your own language, and the other person will understand you.
Frequently Asked Questions
How is Xontric Systems different from a typical software agency?
We don't compete with web agencies — we compete with in-house engineering teams, and we win on architecture, speed, and cost. A typical agency assembles websites and apps from templates and hands them off. We engineer custom infrastructure: high-security transactional systems, AI-powered compliance engines, and proprietary platforms built to specification for organizations where failure is not an option. Every system we build is designed, owned, and maintained as serious infrastructure — not a deliverable we walk away from.
Do you only work with large enterprises?
No. We work with organizations of any size that need to build serious, secure platforms — from funded startups that need a technical partner rather than a contractor, to enterprises and institutions replacing in-house engineering. The deciding factor is not company size; it is whether the project is real infrastructure that has to work reliably. The same architectural rigor applies to a startup's first platform and an institution's compliance system alike.
Why build custom infrastructure instead of using third-party services?
Most platforms rent their critical functions — verification, authentication, payments, notifications — from outside providers, paying a recurring fee that grows with every user and inheriting risks they don't control: outages, sudden price changes, API deprecations, and lock-in that makes leaving costly later. We build these components natively into the platform we deliver, so they become part of your own system — a one-time build cost instead of a charge on every transaction, with no outside party in your critical path. As you scale, ownership wins on economics: a rented dependency costs more the more you grow, while infrastructure you own approaches zero marginal cost. For regulated systems it is also a security position — no third party touching sensitive data. AkidOTP is the working proof: it replaces a universal rented dependency, SMS verification, with infrastructure we built, cutting verification cost by up to 90%.
What is reverse authentication?
Reverse authentication flips the direction of identity verification. In the traditional model, a service generates a one-time code and sends it to the user — almost always over SMS — and the user copies it back into a login screen. Reverse authentication does the opposite: instead of receiving a code on a page, the user verifies from an app already on their own phone — WhatsApp or Telegram — by sending a pre-filled message that proves they control that account. Nothing is typed into a form that an attacker could imitate.
That direction change is what makes it phishing-resistant. The classic phishing attack works by tricking a user into entering a code on a fake page that mirrors the real one; reverse authentication removes the page from the equation entirely. The verification happens inside the user’s own trusted messaging app, so there is no code prompt to clone, intercept, or relay to a counterfeit site — the credential never leaves the device it was meant for. SMS stays available as an optional fallback for users with no messaging app installed, but it is the last resort rather than the default, which also removes the per-message SMS fees that drive verification costs — the source of the up-to-90% saving.
AkidOTP is our own working implementation of reverse authentication, and the proof that it is production infrastructure rather than theory. It runs live at akidotp.com and is built into every platform we ship — including the login of this site — so the first time you create an account with Xontric, you are using the mechanism firsthand.
How do you prevent AI "hallucinations" in a compliance system?
A general-purpose AI model can produce confident but incorrect output — a "hallucination" — which is unacceptable when the result drives a legal or safety decision. We do not rely on the model's judgment alone. The AI handles extraction (reading documents, identifying data), but its output passes through a deterministic validation layer that checks every value against the actual regulatory standard before anything reaches the user. The AI extracts; our logic validates; errors are caught at validation, not after they have reached a compliance-critical output. TradeDocs Pro is the live example: phone-camera AI vision extracts electrical data, then a proprietary filter cross-references it against the governing regulatory standards before a certificate is issued.
What does "atomic" mean in transaction processing?
"Atomic" means a transaction either completes fully or not at all — there is no half-finished state. In a financial system this is essential: if money moves between wallets, both sides must succeed together or the entire operation is rolled back as if it never happened. Without it, a crash or a race between two simultaneous operations can leave money debited but not credited, or a single balance spent twice. We enforce this at the database level — PostgreSQL RPC functions with server-side locking — so concurrent bids or payments cannot corrupt a balance. Mazadi Libya runs on exactly this: atomic escrow-wallet operations and race-protected real-time bidding that stay consistent even under simultaneous load.
How do you secure the platforms you build?
Security is built into the architecture, not added afterward. Depending on the system, that includes biometric authentication (WebAuthn / FIDO2), end-to-end encryption, database-level access controls and row-level security, server-side locking to prevent race conditions, and verification of identity at the messaging-app level. Every build also goes through penetration testing, load testing, and cross-device validation before launch — we test the system to its limits before your users do. For organizations handling sensitive or regulated data, security posture is treated as a core requirement, not a feature.
What is your development process?
We follow a five-stage process, and nothing ships without your approval at each stage. Discovery maps your requirements against regulatory and security constraints. Architecture defines the system blueprint — database schemas, API contracts, security layers — and no code is written until the architecture is approved. Engineering builds in two-week sprints with continuous integration and weekly progress reports. Testing covers penetration, load, accessibility, and cross-device validation. Deployment is zero-downtime with rollback capability, followed by ongoing monitoring and support. You see verifiable progress at every gate, not a single delivery at the end.
How do you structure development contracts, and what guarantees delivery?
We operate exclusively on a fixed-price, milestone-based delivery model. We do not bill by the hour or charge for open-ended effort — we charge for functioning infrastructure. To eliminate financial risk for our B2B and enterprise clients, we utilize an independent, third-party escrow protocol for all project capital. Before a development sprint begins, the architectural specifications are locked and the funds for that specific milestone are secured in escrow. Capital is only released to us upon the successful delivery, review, and approval of production-ready code against predefined acceptance criteria. This milestone-driven structure ties your budget directly to verifiable technical progress, guaranteeing that your capital is fully protected until the system performs exactly as designed.
Can you integrate with our existing systems?
Yes. We build with standard, well-documented interfaces — REST APIs, webhook architecture, and self-serve API access — so our platforms connect to the tools and systems you already run. Whether the work is a new platform that has to talk to your existing stack, or infrastructure that other systems plug into, integration is part of the architecture from the design stage — not an afterthought.
Do you maintain the platform after launch?
Yes. We do not build and leave. Every system we deliver is monitored, maintained, and actively managed, with optional long-term support — including post-launch monitoring, incident response, and continuous optimization — so it keeps performing long after launch. The platforms in our portfolio are not handed-off projects; they are systems we continue to run.
Is my project kept confidential?
Yes. The projects shown publicly are a selection we’re authorized to share; the majority of our work stays private under NDA. We maintain a confidential repository of architecture for enterprise, government, and private-banking clients, and your project is held to the same standard — nothing disclosed or shown without your authorization. Confidentiality is the default, not an upgrade.
Do you build for clients internationally, and in Arabic?
We work with clients across regions and build natively in Arabic, English, and Polish. Where it matters, our platforms are designed Arabic-first — Mazadi Libya is a fully Arabic-first financial platform, and Jawaab is an Arabic-first encrypted messaging platform — built to serve users and businesses across the Arab world and beyond. As a multilingual development firm we deliver multilingual software, and engagements are run remotely end-to-end, so location is not a constraint.