Payment Middleware for a Regional Fintech
The result, up front
Challenge
A fast-growing fintech needed a PCI-DSS aligned payment layer capable of handling high transaction volumes with low latency.
Solution
We built an event-driven microservices architecture on AWS with auto-scaling, Redis caching, and a fraud-detection rules engine.
Outcomes
- Authorization down from 4+ seconds to under one at peak
- PCI scope cut from the whole platform to one service
- Auto-scaling held through Ramadan campaign peaks
Where this project started
When this Gulf-based wallet company first called us in early 2024, their payment logic lived inside the same monolith as everything else. It had been fine at launch. Two years and a few hundred thousand users later, every promotion turned into an incident: authorization times crept past four seconds during Ramadan campaigns, and their PCI assessor had started asking uncomfortable questions about how much of the codebase sat inside cardholder-data scope.
Their CTO didn't want a rewrite. He wanted the payment path carved out into something isolated and auditable, without freezing feature work on the main app while it happened.
The work, including the part that went sideways
We started with a four-person team plus a part-time architect and gave ourselves a hard rule: the monolith keeps running untouched until the middleware proves itself on shadow traffic. For the first six weeks, every real transaction was mirrored into the new event-driven layer, which processed it and threw the result away. That gave us two weeks of production-shaped data to tune against before anything went live.
The launch itself had one genuinely bad weekend. Our fraud rules engine, tuned on that shadow traffic, turned out to be too aggressive with cross-border top-ups, a pattern the shadow window had barely captured. Roughly 3% of legitimate declines on Saturday were ours. We flipped the engine back to log-only mode within the hour, spent ten days retuning against the fuller dataset, and re-enabled it rule by rule instead of all at once.
By month four the middleware was authorizing in under a second at peak, and the client's PCI scope had shrunk from the whole platform to one well-guarded service. The monolith never noticed.
“The false-decline weekend is actually why we trust them. They spotted it in their own dashboards before our support queue did, owned it on the call, and had a rollback live before lunch.”
Facing something similar in fintech?