amBrain
FinTechSep 29, 202610 min read

A Fintech Founder Without a CTO: How to Choose the Firm That Designs, Builds and Hands Over Your Platform

Fintech FoundersWho Builds ItCode OwnershipTrading Platform Development
Error loading image

You have funding for a trading or brokerage platform and nobody on your side who can read code. Hire an advisor who answers to you, own the architecture on paper, let the licence shape the plan, and check that a firm has really shipped fintech systems before you sign.

If you have funding and a fintech product to build but no CTO, do not start by choosing a builder. First put one technical person on your side, even part-time. Then shortlist engineering companies. They build a system that becomes yours, while a platform vendor licenses you its product and a freelancer, however good, leaves the system depending on one person. Choose among them by what they can show running in production and by what their contract lets you keep.

This article does not rank firms: a ranking cannot know your licence or your launch date. It gives the checks in the order a founder needs them, and describes amBrain in one section near the end.

The short answer: before you choose a builder, get one technical advisor who answers only to you. Then pay for an architecture phase whose documents you own, settle the licence plan before the design is final, ask to see production systems and speak to the people who built them, and sign a contract that keeps the code and the accounts with your company and lets you leave.

I have funding but no CTO. What should I do first?

There are three ways to get technical judgement into the project. They differ mainly in who checks the builder's work.

  • Hire a full-time CTO first. It is the strongest position once the right person is found, but the build waits for the search, and a new CTO has no team to lead at first
  • Bring in a fractional CTO or an independent technical advisor: an experienced engineer who works for you part-time and is paid only by you. They read what builders propose, ask the follow-up questions and check each milestone for you
  • Let the builder lead the architecture. It is the fastest start, and the design is often sound because the firm has built similar systems. The catch is that the firm designing the system will be paid to build it, and nobody on your side can tell a necessary part from a convenient one

What protects you is the second and third options together: the builder drafts the architecture, and your advisor reviews it before you commit to the build. Pick an advisor who has worked on a trading or brokerage system, so they know what to ask about the order path and the records a regulator expects. They should have no referral fee or other deal with any firm on your shortlist.

What should the architecture phase give me before any code is written?

An architecture phase should end with documents, written so that your advisor can check them and you can follow them:

  • One page of scope: which product comes first (a terminal for your clients, the brokerage systems behind it, or an exchange), for which market and which first users
  • A drawing of the system and everything it connects to: brokers or exchanges, banks and payment providers, identity checks, market data vendors
  • The path of one order from the client's screen to the market and back, with the risk checks marked and what happens when a connection drops
  • What the system must record, for how long and for whom, taken from the rules of your licence
  • Where it will run: cloud or server accounts opened in your company's name
  • The third-party contracts your company must sign, and which of them the build waits for
  • The first release in writing, including what is deliberately left out
  • Open risks, and an estimate per milestone rather than one number for everything

Pay for this phase separately, and make the documents yours whether or not you continue with the same firm. A second firm can then quote against the same design, and your future CTO starts from a written record instead of somebody's memory. Some regulators ask for the same kind of material, as the next section shows.

Which licences and rules shape the build?

Settle the licence question before the design is final, with a regulatory lawyer involved. The licence decides what the system has to do and when you may switch it on, and no engineering firm can obtain it for you or make the regulator decide faster.

Regulators look at your systems as part of the application:

  • In the UK, the FCA asks applicants to “demonstrate that the technology or systems you'll be using are ready to carry out the applied-for regulated activities”. It also considers whether, “if we were to authorise you today”, you could carry out the activity you applied for
  • In the US, a broker-dealer registers with the SEC and becomes a member of a self-regulatory organisation such as FINRA before it starts doing business. FINRA's admission standards include communications and operational systems that “provide reasonably for business continuity”, and “a recordkeeping system that enables Applicant to comply with federal, state, and self-regulatory organization recordkeeping requirements”
  • In the EU, an application to become a crypto-asset service provider must contain “the technical documentation of the ICT systems and security arrangements, and a description thereof in non-technical language”. A firm that wants to run a crypto trading platform must also describe the platform's operating rules and its procedure and system for detecting market abuse

The regulator's clock is measured in months. The FCA's guidance for applicants, last updated in March 2026, says a complete application from a firm such as a broker is usually assessed within six months, and an incomplete one can take up to twelve. Under MiFID II, the EU law for investment firms, an applicant must be told within six months of submitting a complete application whether authorisation has been granted. Under MiCA, the EU's crypto-asset regulation, the authority checks completeness within 25 working days and decides within 40 working days of receiving a complete application, pausing for up to 20 working days while it waits for answers to its questions. FINRA's rules let an applicant escalate if no decision has come 180 days after filing, or by a later date agreed in writing.

The rules also decide what the system keeps. An EU investment firm must keep records of all its services, activities and transactions “sufficient to enable the competent authority to fulfil its supervisory tasks”, and keep recordings of calls and electronic communications about client orders for five years, or up to seven if the authority asks. Requirements like these shape how data is stored from the first design.

How do I check that a firm has really shipped fintech systems?

Real shipping means a system in production, with real clients' orders or money going through it, that you can see and whose builders you can question. The article on where to start lists the basic proofs: a named production system, a walk-through of it, an incident story, and the people who did the work. Without a CTO of your own, add checks that do not depend on reading code:

  • Check the client yourself. If a firm says it built a platform for a regulated client, public registers show whether that client is authorised: FINRA's BrokerCheck in the US, the FCA's Financial Services Register in the UK, ESMA's register of authorised crypto-asset service providers in the EU
  • Call a reference yourself, without the firm on the line, and ask what broke after go-live and how the firm handled it
  • Bring your advisor to the walk-through to ask the questions you cannot
  • If the firm says the engineers who built that system will work on yours, write their names into the contract

Be precise about which experience counts. A payments app and a trading platform are both called fintech, and they fail in different ways. For a trading or brokerage product, ask for systems where orders pass through the firm's code on their way to a market.

What should the contract say about code, accounts and handover?

Paying for code does not by itself make it yours. In the UK, the Intellectual Property Office's guidance says the first legal owner of the copyright in a commissioned work is whoever created it, “unless you otherwise agree it in writing”. In the US, a transfer of copyright is valid only in writing, signed by the owner of the rights or their authorised agent. The article on checking a dedicated team covers the ownership clause itself. For a fintech build, add these terms:

  • The code repository, cloud accounts, domains and app store accounts are opened by your company from the first day, and the firm gets access you can remove
  • Credentials for brokers, exchanges, banks and market data vendors are issued to your company, and those contracts are signed in its name. If the firm holds them, your trading depends on the firm staying
  • Anything the firm keeps, such as its own reusable libraries, is listed by name, with a licence that lets you keep using and changing it after you part ways
  • Handover has an acceptance test and a rehearsal before the last milestone; the article on hiring engineers or a partner lists what it should contain
  • Exit terms cover notice periods, the firm's help during a transition, and the return of your data in a usable format

If your company will be an EU investment firm, crypto-asset service provider or trading venue, it falls under the Digital Operational Resilience Act (DORA), which has applied since 17 January 2025. Article 30 of DORA sets minimum terms for contracts for technology services, which the regulation calls ICT services, among them the regions or countries where data is processed and stored, the return of your data if the provider becomes insolvent, stops operating or the contract ends, and termination rights with notice periods. Contracts for services that support critical or important functions also need exit strategies with a mandatory transition period. Ask your lawyer which parts of your agreement with the builder fall under it, especially support and hosting after launch.

How should the work be split into milestones and payments?

Split the build so that each payment buys something you can see working, checked by your advisor against criteria agreed before the work began. One shape for a trading or brokerage build:

  • The architecture documents, priced on their own and yours whether or not you continue
  • One order travelling from a test account through the risk checks to a broker's or exchange's test environment and back to the screen, running in your company's cloud account
  • The first market working end to end: accounts, balances, positions, the records your licence requires, and the connection tests that brokers and exchanges run on their own calendars
  • A launch to a small group of real clients, with monitoring on and someone on call
  • A handover rehearsal, in which your own engineer deploys a change and rolls it back while the builders watch

Line the milestones up with the licence application. The FCA, for one, wants the systems ready to carry out the regulated activity when you apply, so the build has to be well advanced by then.

Keep the right to stop after any milestone with everything built so far, including right after the architecture phase, before you have committed to the whole build.

What are the red flags when choosing a fintech development partner?

  • A fixed price and a launch date in the first reply, before anyone has asked which licence you are applying for or which brokers and exchanges you will connect to
  • A launch plan with no room for the regulator's decision or for your brokers' connection tests
  • A free architecture phase with no written right to the documents, which leaves you unable to take the design to another firm
  • Broker or exchange credentials, or the cloud account, held in the firm's name
  • “Our platform is compliant.” Software does not hold a licence; your company does. Ask which rules the design was checked against, and by whom
  • Resistance when you bring an independent advisor to review the design
  • Fintech examples that are all websites and dashboards, with no system that moves orders or money

Where does amBrain fit?

Of the kinds of firm described above, amBrain is an engineering company. amBrain has been building software since 2019.

Its trading services are listed as “Trading terminal development, order management systems, and FIX protocol exchange integration.” amBrain built the trading terminal for Spectre Trade. amBrain has also built a mini-exchange that runs in production on MOEX colocation. The mini-exchange's client is not named.

amBrain describes how it works with clients in one line: “Three formats: full delivery, a dedicated team, or engineers embedded in your team.” On ownership, its line is: “The client keeps full ownership of the product and the code, except our reusable components.” That exception is the kind of carve-out this article tells you to pin down, so ask amBrain for the list of those components by name before you sign. This article is not a case study, and its checks apply to amBrain as much as to any other firm.

If you are at the start, write one page before you contact anyone: the product you are building first, the licence you are applying for, your first market and users, and the date you need to be live. Send it to your advisor, then to two or three firms, amBrain or any other, and compare the questions that come back.

Have a design like this on the table?

Bring your current architecture and the failure mode that worries you, and we will go through it together in half an hour.