Client
B21 Invest
Mission

Make crypto investing as simple as buying coffee.

Pre-Engagement Stack

Angular web app, Node.js monolith, MongoDB Atlas

B21 Invest

B21 Invest
Case Study

Executive Summary

B21 Invest set out to democratise crypto wealth management for mainstream investors who find exchanges complex and self-custody scary. Their initial web MVP validated demand but lacked mobile reach, iron-clad compliance, and automated portfolio management. To close a pending VC round and win a strategic banking partnership, B21 Invest needed a bank-grade, mobile-first platform-complete with on-ramp/off-ramp, KYC/AML, and real-time portfolio rebalancing—live in less than six months.

Steady Rabbit deployed a Micro-GCC Core-Flex squad that, in eleven sprints, delivered:

  • Native-like iOS & Android apps (React Native, 93 % code reuse) with instant on-ramp via UPI, ACH, and SEPA
  • Self-custody + institutional-grade custody hybrid (Fireblocks) achieving 99.97 % platform uptime
  • Automated portfolio rebalancer that cut user trade fees 28 % and lifted Net Asset Growth 16 %
  • PCI DSS SAQ-A and EU 5AMLD compliance, clearing due diligence for a Tier-1 banking partner
  • $15 M Assets Under Management in the first 120 days post-launch
  • 40 % lower cloud OpEx than the previous architecture via spot instances & serverless order routers

Not a single sprint milestone slipped—giving investors the confidence to close a $9 M Series A at a premium valuation.

Client Profile & Business Context

  • Client
    B21 Invest

    FinTech start-up headquartered in Gibraltar

  • Founded

    2019

  • Mission

    Make crypto investing as simple as buying coffee.

  • Pre-Engagement Stack

    Angular web app, Node.js monolith, MongoDB Atlas

  • Regions Targeted

    EU, India, SEA, and US (via MSB partner)

B21 Invest’s MVP allowed credit-card buys of Bitcoin and Ethereum, but lacked multi-asset baskets, auto-rebalancing, stable on-ramps in India/EU, and mobile apps—critical for emerging markets. New regulatory guidance (EU 5AMLD, India VDA rules) raised the bar. The founders promised investors a production-grade, compliant mobile platform by Q3 to unlock Series A and a co-branding deal with a mid-tier bank.

Problem Statement / Key Challenges

Mobile Gap

Challenge

No native apps, web UX clunky on low-end devices

Impact if Unsolved

TAM plateaued; user growth stuck at 18 K

Regulatory Compliance

Challenge

Must meet 5AMLD, PCI SAQ-A, FATF Travel Rule

Impact if Unsolved

Without licences, fiat on-ramp partners would walk away

Custody & Security

Challenge

Hot-wallet architecture vulnerable; no MPC or HSM custody

Impact if Unsolved

High asset-loss risk, no institutional trust

Scalability

Challenge

Node monolith capped at 200 TPS; flash crashes freeze UI

Impact if Unsolved

Peaks during bull runs could cripple reputation

Time-to-Market

Challenge

22 weeks to meet investor & bank deadlines

Impact if Unsolved

Delay would drop valuation and kill partnership

Our Approach

Micro-GCC Squad Structure

Layer
Roles
Prime Objectives
Core (6)
Squad Lead/PM, 2 React-Native engineers, Go micro-services dev, DevOps/SRE, QA Automation
Deliver mobile apps, micro-services, and CI/CD
Flex (3)
Cloud-Security Architect (PCI), Blockchain Engineer (Fireblocks, EVM), Payments SME (UPI/SEPA)
High-risk spikes: custody, fiat rails, compliance
Buffer (1)
Shadow Full-Stack dev
Absorb PTO/attrition without cost to B21

Shift-Left Governance & SteadCAST

  • 7 Plan-Left gates per Jira story—Persona, Acceptance, Risk, Arch sketch, Estimate, Capacity, Test note.
  • SteadCAST dashboards track velocity, capacity drift, Risk-High WIP.
  • 30-minute weekly steering with founders + legal/compliance leads; zero surprises.

Discovery Sprint 0 (Weeks 1–2)

  • Design Thinking Workshops – User journeys for first buy, KYC, portfolio view.
  • Architecture Blueprint – Event-driven Go micro-services, Fireblocks custody, serverless order router (AWS Lambda).
  • Regulatory Gap Analysis – Map PCI SAQ-A scope, 5AMLD KYC/KYT flows, Travel Rule API.

Velocity forecast 108 SP per sprint; go-live timeline confirmed for Week 22.

Solution Delivered

Cloud-Native Micro-Services

  • Go + gRPC services for wallet, order-router, portfolio, notifications.
  • Kafka event backbone; Aurora Postgres for ACID wallet DB.
  • Lambda order-router autoscales 0 → 100 TPS under load; average cold-start 210 ms.

Hybrid Custody Model

  • Fireblocks MPC custody for > $1 k equivalent; self-custody HD wallets for micro-balances.
  • AWS KMS HSM plus CloudHSM for key fragments; SOC 2 evidence logged.

Mobile & Web Front-Ends

  • React-Native apps (iOS/Android) share 93 % code.
  • Offline mode caches portfolio snapshots; low-bandwidth optimisation (< 300 KB first install).
  • Next.js PWA for marketing & desktop traders; SEO + server-side render.

Fiat On-Ramp & KYC/AML

  • Razorpay UPI, Plaid ACH, SEPA rails integrated via Payments Flex SME.
  • SumSub KYC SDK + FATF Travel Rule API; TPS 30 → 120 with adaptive throttling.
  • Automated SAR (suspicious activity report) generator.

Portfolio Rebalancer & Analytics

  • CRON Lambda computes risk-weighted indexes, triggers market orders via Binance & Coinbase Pro APIs.
  • Trade fee savings 28 % vs. manual rebalance; user NAG ↑16 %.

Compliance & Observability

  • PCI tokenisation means app qualifies for SAQ-A only; no card data on servers.
  • OpenTelemetry feeds Grafana dashboards; p95 API lat ≤ 450 ms.
  • Automated evidence bucket stores Sonar/Snyk/Trivy, CloudTrail logs—cut audit prep 100+ hrs.

Execution Journey

Sprint
Focus & Milestones
KPI Shift
Predictability
Sprints 0
Workshops, arch diagram, AML mapping
Baseline p95 Lat 900 ms
100 % gate pass
Sprints 1
Wallet DB, Fireblocks POC, React-Native shell
Custody latency 900 ms → 420 ms
Risk-High WIP 15 %
Sprints 2
Kafka events, order router v0, UPI sandbox
TPS 200 → 450
Buffer unused
Sprints 3
KYC SDK, Travel Rule API, iOS build
KYC pass rate 71 % → 88 %
PCI Flex 16 h
Sprints 4
Portfolio screen, PWA SSR, Sonar gate
Bug density –48 %
No schedule slip
Sprints 5
SEPA ACH rails, MPC rollout
Uptime rolling 7-day 99.97 %
Hot-fix fries 0
Sprints 6
Rebalancer, push notifications
Net Asset Growth +9 %
Flex Blockchain 24 h
Sprints 7
Load test (5×), blue-green drills
p95 Lat 900 ms → 450 ms
Risk WIP < 10 %
Sprints 8
PCI SAQ-A audit, Play/App Store beta
Audit findings critical 0
--
Sprints 9
Marketing PWA, referral engine
Activation 27 % → 44 %
Budget +5 %
Sprints 10
Production launch, bank partner demo
AUM $0 → $10 M
Delivered on day-21
Sprints 11
Hardening, Series A data-room support
AUM $10 M → $15 M
All sprints green

Buffer dev replaced a React-Native engineer (COVID) in sprint 5—velocity dip 0 SP thanks to shadow tickets.

Business Outcomes & Impact

Assets Under Management: $0 → $15 M in first 120 days

Uptime 99.97 % across first 90 days (target 99.9 %)

Trade fee savings 28 % via automated rebalancer; Net Asset Growth +16 %

User activation 27 % → 44 % (+17 pp) post mobile launch

KYC pass rate 88 %, onboarding within 4 min avg

Operating Cost –40 % vs. previous stack via spot & serverless

PCI SAQ-A & 5AMLD compliance cleared bank DD in first try

Closed $9 M Series A; bank partner signed co-branding MoU

Predictability premium (~8 % uplift) paid back in ≤ 30 days by avoiding a two-sprint delay valued at ≈ $1.2 M lost AUM.

Why Steady Rabbit?

Core-Flex Micro-GCC

Inserted blockchain & payments SMEs within 48 h; Buffer bench eliminated risk.

SteadCAST Predictability

Real-time capacity and risk ensured 98 % sprint compliance.

Shift-Left Governance

Plan-Left gates reduced re-work 41 % while adding < 2 h per sprint.

Reg-Tech Expertise

PCI DSS, 5AMLD, Travel Rule baked into DevSecOps; auditors impressed.

Outcome-Linked Engagement

KPIs (uptime, AUM, activation) tied to squad incentives; no vanity metrics.

Transparent Partnership

Weekly demos, Slack war-room, shared burn charts—zero surprises, ever.

Client Testimonial

Steady Rabbit

CEO & Co-Founder

B21 Invest

Steady Rabbit delivered a bank-grade crypto platform in record time. Their Core-Flex model meant we always had the right expert on tap, and we never missed a milestone. Investors and banking partners were blown away.