GAMB TECH Start a project

Financial software engineering since 2004

We engineer the software behind regulated financial products.

Gamb Tech is a software engineering company for the financial industry. We design and build the systems that banks, payment institutions and regulated fintechs rely on — from architecture and core integrations to secure, audit-ready delivery. We write software; licensing and operations stay with you.

Contract development · Team extension · Long-term engineering partnership

architecture · live view 3 services · 1 ledger
CLIENT App / API API LAYER Ingest · validate · dispatch transform · orchestrate · audit Service A processed · 210 ms Service B integrated · in sync Service C reconciled · ledgered
processed integrated reconciled illustration, not production data
PCI DSS 4.0 3-D Secure 2.x / SCA ISO 20022 Network tokenisation Ledger & reconciliation Event sourcing API integration Regulatory reporting GDPR / DSGVO ISO 8583 Secure SDLC EU hosting

What we build

Financial software, written to your name.

Every engagement ends with a system your team can own: your repositories, your infrastructure accounts, your documentation. We bring the domain knowledge — payments, banking, compliance — that usually takes years to accumulate in-house.

Payments

Payment systems

Gateways, acquiring and issuing integrations, APIs and orchestration — built to standard and documented for your certification.

  • REST / S2S
  • webhooks
  • tokenisation
  • ISO 8583
Banking

Core banking & ledger

Accounts, balances, booking logic, double-entry ledgers and the reconciliation that keeps them provably correct.

  • ledger
  • reconciliation
  • settlement
  • event sourcing
Compliance

Regulatory & reporting

Compliance tooling, regulatory reporting, audit trails and the evidence your auditors and supervisors ask for.

  • audit trail
  • reporting
  • data residency
  • retention
Integration

API platforms & integration

System-to-system integration, message standards and middleware that connect legacy cores to modern services.

  • ISO 20022
  • SWIFT
  • middleware
  • idempotent APIs
Data

Data & reconciliation

Settlement files, matching engines, financial data pipelines and the month-end reporting finance actually needs.

  • matching
  • pipelines
  • finance reporting
Platform

Cloud & platform engineering

Kubernetes, infrastructure-as-code, EU-only deployments and a secure SDLC that stands up to review.

  • Kubernetes
  • Terraform
  • EU hosting
  • secure SDLC
20+years in financial systems
50+integrations delivered
EUbased senior team
Auditready by default

Figures describe delivered work across two decades. Reference details available under NDA.

Compliance & security

Built for audit, not just for launch.

In financial software, an audit finding costs more than a missed sprint. We build with the certification path in mind from the first commit, and we have sat in the rooms where these programmes are reviewed.

  • PCI DSS 4.0

    Scope design, segmentation, secure SDLC evidence, key management and change control. We prepare the artefacts your QSA asks for and reduce scope with proxy and tokenisation patterns instead of paperwork.

  • 3-D Secure, SCA & strong authentication

    Strong customer authentication done properly: data quality in the authentication request, exemption and delegation strategies where they apply, and honest measurement of the trade-off against fraud.

  • Standards & message formats

    ISO 20022, ISO 8583 and SWIFT message handling, stored-credential consent, mandate handling and the audit trail that proves each of them — the details that make or break a review.

  • Data protection and data residency

    GDPR-aware architecture: lawful basis per processing purpose, sub-processor documentation, EU hosting where required, retention and deletion that are implemented rather than promised.

How we work

Five stages, in this order, for a reason.

Certification and sign-off cannot be moved to the end of a regulated software project. They sit between build and launch, so we plan for them from the start.

STAGE 1

Discovery

Systems, data, integrations and the regulatory context you already operate in. Two weeks, fixed price, written outcome.

STAGE 2

Architecture

Domain model, PCI scope, failure modes, data residency and a build plan you can hold us to.

STAGE 3

Build

Two-week increments, trunk-based, tested against sandboxes from day one. Demo every sprint.

STAGE 4

Certify

Certification support, security testing, penetration-test fixes, compliance evidence, runbooks and load tests.

STAGE 5

Handover

Documented handover, training and a support window — and, if you prefer, we can run the system for you under a support agreement.

Three ways to work with us.

Mode

Build for you

You define the outcome, we deliver the system: full ownership of design, implementation and certification, handed over with documentation and training.

Best for
New platforms and rewrites
Commercials
Fixed-scope phases or time and materials
Mode

Extend your team

Senior engineers inside your process, your repositories and your stand-ups — adding domain knowledge without adding a management layer.

Best for
In-house teams under load
Commercials
Monthly per engineer, minimum three months
Mode

Engineering partnership

Long-term ownership of a codebase we built or inherited: changes, upgrades, security patching and technical reviews under a support agreement — and we can operate it for you if you don't want to run it in-house.

Best for
Systems that need to keep evolving
Commercials
Retainer per service tier

Engineering

Boring technology, deliberately chosen.

Financial systems are judged on correctness under load and on how quickly someone can debug them at 3 a.m. We pick tools that reward that, and we write the tests and runbooks to match.

Services

  • Java / Kotlin
  • Go
  • TypeScript / Node
  • Python
  • PHP (legacy care)

Data

  • PostgreSQL
  • Redis
  • Kafka
  • ClickHouse
  • Event sourcing

Platform

  • Kubernetes
  • Terraform
  • AWS · GCP · bare metal
  • EU-only deployments
  • Blue/green releases

Assurance

  • Contract testing
  • Load & chaos testing
  • OpenTelemetry
  • SAST / DAST in CI
  • Runbooks & game days

Company

Two decades of financial engineering, one small senior team.

Gamb Tech was founded by engineers who have built banking back ends, payment systems and integration layers since the early 2000s — through the arrival of 3-D Secure, PSD2, ISO 20022 and open banking. We stay small on purpose: the people who scope your project are the people who write the code.

Who you work with

Senior engineers only

No junior bench, no account managers between you and the people building the system. The engineer in the scoping call stays on the project.

Where we work

EU team, EU hosting

Development and operations sit inside the EU, which keeps data residency simple. CET working hours with deliberate overlap into US mornings.

How we contract

Small first step

NDA, then a fixed-price discovery before anyone commits to a build. If the assessment says the project should not happen, we say so.

Questions

Answered before you ask.

Are you a payment institution or a licensed provider?

No. Gamb Tech is a software engineering company. Licensing, acquiring relationships, settlement and the movement of funds stay with you or your regulated partners. We build the technology around that and document it so your regulator and auditors can follow it.

Can you take over a system someone else built?

Yes, and it is a large part of what we do. We start with a two-week assessment: code, data model, PCI scope, dependencies and operational risk, followed by a stabilisation plan that separates what must be fixed now from what can wait.

How quickly can we be in production?

A first integration typically reaches production in eight to twelve weeks. The variable is rarely the code — it is certification slots, third-party documentation and testing, all of which we schedule in stage 2.

How do you work with our compliance and audit teams?

Directly. We produce the evidence, documentation and audit trails your compliance function, auditors and supervisors ask for, and we sit in the reviews to walk them through the technical detail. The certification path is planned from the first commit, not bolted on at the end.

How do you keep our PCI scope small?

By keeping card data out of your infrastructure: hosted fields or a PCI-certified proxy for capture, tokens everywhere downstream, network tokens where the scheme supports them, and strict segmentation for anything that must remain in scope.

What happens after launch?

Either your team takes over with a documented handover and a support window from us, or we continue as your engineering partner for changes, upgrades and technical reviews under a support agreement. Both are priced before the build starts.

Contact

Tell us what you are trying to ship.

Send a short description of the system, the volumes and the deadline. You will get a reply from an engineer, not a sales team, usually within one working day.

No newsletter, no CRM sequence. We reply once and follow your lead.