In active development · Founding Members open

Cross-border payments, built ledger-first.

XFluxPay is payments infrastructure built on a double-entry ledger, where a balance is a provable position and every movement leaves a record that reconciles. We are building the financial core first, and we are looking for Founding Members to shape it while the foundational decisions are still being made.

Free to join. A welcome email, then updates when there is something substantive to share.

  • Ledger-first. Balances derived from journal entries, not stored counters.
  • Passkey-first. Biometrics stay on your device; the server verifies proofs.
  • Built to be audited. Append-only records, replayable decisions.

Our mission

Mission

Make money explainable

Every payment should be able to say where it is, what it cost and why — at any moment in its life.

Method

Foundations before features

The ledger, identity and settlement core comes first, because correctness there is what everything above it inherits.

Horizon

A global payment ecosystem

Architecture designed from day one for millions of users, many currencies and cross-border scale.

The problem

Sending money across a border still works like posting a letter and hoping.

The interfaces have improved enormously. The systems underneath still struggle to answer basic questions about their own state — and that is where the real cost sits.

01

The price arrives after the decision

The rate on screen and the amount that lands are different numbers, separated by a spread and fees disclosed in stages. Globally, sending remittances costs an average of 6.36% of the amount sent, against an international target of 3%.

Source: World Bank Remittance Prices Worldwide, Q3 2025. Target from UN Sustainable Development Goal 10.c.

02

Arrival is a range, not an answer

"Two to five business days" absorbs cut-off times, correspondent hops and weekends that never reach the person waiting. A window that wide is a system describing its own uncertainty.

03

In-flight money is hard to locate

When a payment stalls, support often sees the same single-word status the customer does. The money sits between two institutions whose records were never designed to reconcile against each other.

These are not design problems wearing an engineering costume. They are accounting problems wearing a design costume.

Why we started with the ledger

Our vision

Money that can account for itself.

This is the payments experience we are building toward. Each point below is a design goal that the architecture is being shaped to support.

  1. The price is known before you commit

    An executable quote carrying the exact amount, rate, fee and expiry — so what you agree to is what happens.

  2. Arrival as a commitment

    Where a corridor can commit to a time, it commits. Where it can speak only in probabilities, it says so precisely.

  3. Every state visible and explainable

    Pending, reserved, settled, reversed, refunded, disputed — each one a real state with a real record behind it.

  4. Identity that travels with you

    A new phone should carry your history forward. Recovery is designed as part of the security model, not appended to a support queue.

  5. Resilience when connectivity is imperfect

    Payments in the real world happen on patchy networks. We are designing for that case deliberately, with limits stated plainly.

Our values

Four commitments we build against.

Written down early, and deliberately specific enough to be measured against. These shape every technical decision we make.

Value one

Correctness before surface

Accounting, identity and settlement foundations come first. They are the layers everything above them inherits, and the layers that reward being got right the first time.

Value two

Honest state, always

A payment reports exactly what is known about it. Where an outcome is still resolving, the system says so precisely rather than guessing on the customer's behalf.

Value three

The server decides; the device proves

Authority over balances, limits and permissions stays server-side. The device holds keys and produces cryptographic proofs, which is what keeps decisions verifiable.

Value four

We show our work

Architectural decisions are documented with the reasoning behind them, including the ones we revised. Founding Members see that record as it is written.

Engineering highlights

What "built properly" means in practice.

Specifics rather than adjectives. Each of these is a decision already made and documented in the platform's foundations.

Balances are derived

A balance is a projection of double-entry journal entries rather than a stored counter. There is no single number for two processes to race over, and the figure shown always agrees with the history behind it.

Integer money, everywhere

Amounts are integer minor units paired with an ISO currency code, keeping monetary paths free of floating point. Zero-decimal and three-decimal currencies are modelled at their real precision.

Rounding you can audit

A single rounding authority using banker's rounding, applied at named boundaries. Every conversion retains the exact product, the rounding difference and the effective rate, so each fraction of a unit is accounted for.

Passkeys at the centre

Your fingerprint or face unlocks a key held on your device. The server verifies a cryptographic signature and never receives a biometric — the proof travels, the biometric does not.

Trust derived from evidence

Identity, device, authentication and session context are modelled as independent signals derived from stored evidence, so authorization reflects what has actually been demonstrated.

Records that hold their shape

Audit records and authorization decisions are append-only, enforced at the database level. Each decision stores the policy version that produced it, so it can be replayed exactly years later.

Recovery as a first-class design

Account recovery is architected as its own security domain with layered paths, so the strength of the evidence presented determines the capability restored.

Assistance with clear boundaries

Intelligence in the product explains, categorises and surfaces insight. Authorising value movement always rests with you, backed by the ordinary financial controls.

Our journey

Where this started.

XFluxPay began with a question that turned out to be harder than it looked: why can a payment app show you a beautiful balance and still not tell you where your money is?

The answer is architectural. When a friendly interface sits on top of a stored balance and a third-party status field, the product can only ever be as truthful as the agreement between those two things. Improving the interface does not improve the answer.

So we started at the other end. Before writing a transfer screen, we built a currency and money model with exact integer precision. Before building accounts, we designed how trust would be derived from evidence. Before enabling a single movement of value, we specified the double-entry ledger those movements would be recorded in, and the recovery paths that protect the people who own them.

That order is slower to demonstrate and considerably more durable. It is also why our architectural decisions exist as written records with their reasoning attached — a habit we intend to keep as the team grows.

We are early, focused, and building in the open with the people who join us now. Founding Members see that work as it happens.

What's next

The sequence we're building in.

Ordered by dependency rather than by date, because each phase makes the next one safe to build. Founding Members receive progress updates as each milestone lands.

  1. In progress

    Phase one — the financial core

    Chart of accounts and double-entry ledger. Identity, devices, passkeys and sessions. Capability-based authorization with versioned policy. A recipient directory designed for privacy. Reconciliation with a defined review path.

    The foundation everything above it inherits.

  2. Next

    Phase two — first money movement

    A sandbox that exercises failure deliberately — timeouts, duplicate delivery, partial settlement, reversal — followed by transfers between XFluxPay accounts with a full lifecycle and durable retry path. Founding Members are invited here first.

    A payment system is defined by how it behaves under stress.

  3. Planned

    Phase three — cross-border and currency exchange

    Expiring executable quotes, a review step showing the complete instruction, settlement through licensed financial institutions, and reconciliation against what actually settled. Corridors are announced as each one is ready.

    A rate you cannot execute at is not a price.

  4. Exploring

    Phase four — the frontier

    Payments that tolerate imperfect connectivity within stated limits. Assistive intelligence that explains rather than decides. Interfaces for businesses and developers. Active research directions on our long-term horizon.

    Where the platform goes once the core carries weight.

Founding Members · Open now

Come in before the foundations set.

The ledger schema, the authorization model and the recovery design are being decided right now. Founding Members are the people who get to shape them while shaping them is still inexpensive.

This is a working community rather than a mailing list. We are looking for a small number of people who care how a payment system is built — and then actually listening to them.

Claim your founding seat

  • Free to join, with no obligation
  • A welcome email, then substantive updates only
  • One click to leave, and we remove your record
  • Your address stays with us and is never sold

Influence while it counts

Roadmap input before decisions calcify — and we tell you when your argument changed something.

First through the door

Founding Members enter the sandbox first, then the first live cohort, ahead of general access.

The engineering view

Progress updates written for people who want the reasoning, not just the changelog.

Permanent standing

Founding status recorded on your account, and it does not expire as we grow.

Questions

Frequently asked questions

What is XFluxPay building?

Cross-border payments infrastructure built on a double-entry ledger. The goal is a platform where every balance is a provable position, every movement reconciles, and every payment can explain its own state.

We are building the financial core first — the ledger, identity, authorization and settlement foundations — because that is the layer everything else inherits its correctness from.

Is XFluxPay a bank?

XFluxPay is a technology company building payments infrastructure. As we bring money movement online, it will operate through licensed financial institutions and payment partners, and we will name them as each is in place.

How does XFluxPay earn trust?

By being specific. We publish the architectural decisions behind the platform along with the reasoning, including where we revised our thinking. Founding Members receive that record as it is written.

Trust in payments is earned over time through a track record. Our approach is to make that record legible from the beginning rather than to assert it.

What happens after I join?

You receive a welcome email confirming your place. After that you hear from us when there is something substantive: an engineering update, a milestone, or your sandbox invitation when phase two opens.

Founding Members are invited to the sandbox ahead of general access, and to the first live cohort after that.

Does joining cost anything or commit me to anything?

No and no. Founding membership is free and carries no obligation. It is a place in an early testing community and a direct line to the people building the platform, and it confers no equity, security, token or financial entitlement. The Terms of Service set that out in full.

What do you do with my email address?

We use it to contact you about XFluxPay, and for nothing else. It is never sold, rented or shared for advertising. Every message carries one-click unsubscribe, and unsubscribing removes your record. Full detail is in the Privacy Policy.

Which currencies does the platform handle?

Our currency model covers seventeen currencies at their correct minor-unit precision, including those with no decimal places and those with three. Handling that precision correctly at the foundation is what makes accurate conversion and settlement possible above it.

Corridor availability is announced as each one comes online.

How is my data handled?

Traffic is encrypted in transit. Secrets, tokens and account identifiers are kept out of logs by design. Audit records are append-only at the database level. Authentication is built around device-held keys rather than shared secrets, so what crosses the network is a cryptographic proof rather than a credential.

Do you use AI, and can it move money?

We use machine intelligence to explain, categorise and surface insight. Authorising value movement always rests with you, supported by the ordinary financial controls, and that boundary is enforced in the architecture itself.

Are you hiring, raising, or open to partnerships?

We are always glad to talk to people who find this approach interesting — investors, prospective partners and engineers alike. Write to hello@xfluxpay.com and tell us which one you are.

About

About XFluxPay

XFluxPay is an independent engineering effort building cross-border payments infrastructure the way infrastructure should be built: financial correctness first, product surface second.

Our work starts at the layer most people never see. A double-entry ledger where balances are derived from journal entries. Money represented as integers with explicit currency precision. Identity where trust is assembled from evidence. Recovery designed as a security domain in its own right. Audit records that hold their shape. None of it appears in a screenshot, and all of it determines whether the screenshot can be believed.

We are early and deliberately focused. We document our architectural decisions with the reasoning attached, because a payments platform should be legible to the people who depend on it.

If that is the kind of infrastructure you want to exist, claim a founding seat and help us build it.

Contact

Talk to us

A real person reads every message. We aim to reply within a few working days.

General & partnerships

Questions, ideas, investment, press, or anything not covered above.

hello@xfluxpay.com

Security disclosure

Responsible disclosure is welcome. Report privately and allow reasonable time for a fix before publishing; we will not pursue legal action against good-faith research.

security@xfluxpay.com

Privacy requests

Access, correction or deletion of the data we hold about you.

privacy@xfluxpay.com