Practice 01 · Payments

    Money movement that doesn’t break at 2 AM.

    PIX, cards, settlement and anti-fraud — built on patterns from systems processing R$1B+ monthly at 99.99% availability.

    Proof
    R$1B+
    monthly volume processed
    99.99%
    availability
    < 80ms
    p99 authorization
    The brief

    Payments are a ledger problem disguised as an API.

    Most payment incidents aren’t outages — they’re silent drift between what your API said and what the bank actually did. We design payment systems where the ledger is the source of truth and every external call is reconciled against it.

    From PIX rails to card acquirers to settlement and chargebacks, we build the infrastructure that lets product teams ship checkout features without worrying whether tomorrow’s reconciliation will balance.

    What you walk away with

    Deliverables and the operating posture they buy you.

    Tangible deliverables
    • Production-ready payments service with idempotent API
    • Money-state machine and ledger schema (PostgreSQL)
    • PIX, card and settlement integrations
    • Reconciliation jobs with discrepancy alerting
    • Anti-fraud rules engine and audit trail
    • On-call runbooks and incident playbooks
    What changes in operations
    0

    double-charges on retry — idempotency keys at every boundary

    T+1

    settlement closes balanced, automatically

    < 5 min

    MTTR for stuck transactions via ledger-only recovery

    100%

    auditability — every state transition is queryable

    Capabilities

    What we build into the stack.

    Click any capability to see how we approach it.

    How we approach it

    PIX integration

    Real-time PIX with webhook reconciliation, dynamic QR codes, refunds and devolução handling.

    • Direct integration with PSP or via BCB-licensed acquirer
    • Idempotent webhook receivers with replay protection
    • Dynamic QR with TTL, status polling and merchant callback
    • Refund + devolução flows with audit-grade traceability
    How we approach it

    Card processing

    Acquirer-agnostic card flow with tokenization, 3DS, recurring billing and chargeback hooks.

    • Tokenization with PCI scope confined to vault
    • 3DS2 step-up triggered by risk score
    • Recurring billing with retry ladders and dunning
    • Chargeback dispute pipeline wired to settlement
    How we approach it

    Settlement & reconciliation

    Daily settlement closures with three-way reconciliation: ledger, processor and bank statement.

    • Three-way reconciliation: internal ledger vs. processor vs. bank file
    • Auto-resolution of known mismatch patterns, queue for human review
    • Settlement preview dashboards for finance teams
    • Closing reports formatted for audit and tax
    How we approach it

    Anti-fraud layer

    Rules + score-based fraud screening with velocity checks, device signals and external API hooks.

    • Configurable rules engine with shadow-mode for new rules
    • Velocity, device fingerprint and behavioural signals
    • External score providers wired through a single risk facade
    • Case-management UI for analyst review
    Workflow

    From volume audit to phased production rollout.

    Each engagement follows the same five-stage cadence — adapted to your stack, but never to your detriment.

    1. Week 1 · Discovery

      Volume audit & failure-mode mapping

      We profile current transaction volume, P99 latency, retry rates and existing incident history — then map the failure modes we’ll design against.

      DeliverableVolume report + risk register
    2. Week 2–4 · Architecture

      Idempotency contract & money-state model

      We codify the transaction state machine, idempotency keys at every boundary and reconciliation invariants — so a retried PIX never debits twice and a stuck settlement is recoverable from the ledger alone.

      DeliverableRFC + state diagram + reconciliation runbook
    3. Week 4–8 · Integration

      Provider integration & sandbox certification

      PIX, card acquirer and settlement integrations wired with idempotent receivers, replayable webhooks and end-to-end sandbox certification before any production traffic.

      DeliverableIntegrated providers + certified sandbox suite
    4. Week 6–10 · Reconciliation

      Ledger reconciliation & finance handoff

      Three-way reconciliation jobs, daily closing reports and finance-team dashboards. Discrepancies trigger alerts before they reach the books.

      DeliverableRecon jobs + finance dashboards
    5. Week 10–12 · Launch

      Phased production rollout

      Canary rollout with kill switches, on-call rotation onboarding, runbook drills and SLO sign-off. We don’t leave until your team owns the pager.

      DeliverableProduction launch + signed-off SLOs
    Architecture

    How a payment flows through the stack.

    Every external call is mirrored in the ledger before acknowledgment — so reconciliation always has somewhere to start.

    INBOUNDAPI requestGATEValidation + idempotencySOURCE OF TRUTHMoney ledgerState machine + write-ahead logPostgreSQL · Append-onlyPROVIDERSPIX · Acquirers · PSPCALLBACKWebhook + replay safeCLOSE THE LOOPThree-way reconLedger · Processor · BankDaily · Alerted

    Inbound request → validation → state transition → provider call → webhook receipt → ledger write → reconciliation.

    Technology

    Tools we reach for first.

    Defaults — not dogma. We pick what survives your next year of volume.

    Core runtimes
    • Node.js / TypeScript
    • Go
    • Java
    Data
    • PostgreSQL
    • Redis
    • Materialize
    Messaging
    • RabbitMQ
    • Kafka
    • AWS SQS
    Payment rails
    • PIX (BCB / PSP)
    • Stripe
    • Adyen
    • Cielo · Rede · Stone
    Observability
    • OpenTelemetry
    • Prometheus
    • Grafana
    • Sentry
    How we engage

    Three shapes, one commitment to ownership.

    Pick the engagement that fits your team — every shape ends with your team holding the pager.

    Engagement model

    Fixed-scope build · Rescue sprint · Retainer

    A scoped payments build, a sprint to unblock a stalled integration, or a monthly retainer for new rails and maintenance — delivered as an external team.

    Typical timeline

    8–12 weeks to first cut

    From kickoff to a production-ready payments flow handling real money in canary.

    Ownership

    100% yours, always

    Ledger, source, intellectual property and runbooks transfer to you. No lock-in, and no bodies to manage.

    FAQ

    Questions we hear before the kickoff.

    If yours isn’t here, ask us directly.

    Start a payments build

    Ready to build payments that don’t wake you up?

    Tell us the volume, the rails and the SLO. We’ll come back with a shape and a timeline.