Koodooka

Agentic AI-native by design. Banking-grade by discipline

Three pillars hold up Koodooka — NEXUS, 57 Rust microservices, and a five-agent core. We wrote the parts that did not exist and refused to ship the parts that were not safe enough

Architecture · live
healthy
Surfaces
Mobile
Web
Admin
B2B
NEXUS · gateway
one instance · four surfaces · agent-native
57 Rust microservices
Ledger
Payments
KYC
KYB
Cards
OB
Sessions
Notifications
+49 more
NEXUS

The next-gen gateway

One instance, four surfaces, traffic-lane prioritisation, per-lane auth, WASM plugin extension, agent-native.

57 Rust services

Predictable performance

Memory-safe, low-latency, no GC pauses, no JVM warm-up. Built for the SLAs that regulated workloads demand.

Five-agent core

Federated intelligence

Compliance, Operations, Customer, Product and Risk agents — federated over NEXUS through MCP.

Pillar one · NEXUS

The gateway we wrote because nothing existed

No vendor chassis. No monolithic core. One next-gen gateway in front of every service — with traffic-lane prioritisation, per-lane authentication, plugin extensibility and native agent support

  • 01
    One instance, four surfaces
    Mobile, web, admin and B2B traffic — single gateway, no fan-out.
  • 02
    Traffic-lane prioritisation
    Branch staff routed ahead of consumer traffic. Predictable under load.
  • 03
    Any OIDC provider, per lane
    Firebase, Entra and mTLS+HMAC running in production today. Plug in your own.
  • 04
    Native + WASM plugins
    Extend without forking the core. Sandboxed, hot-loadable, language-agnostic.
  • 05
    Agent-native by design
    Consolidates upstream MCPs — agents discover and execute across the platform.
Pillar two · the core

57 Rust services. Predictable by construction

We chose Rust deliberately. Memory safety the compiler enforces, latency the SRE team can trust, and a service-per-concern shape that does not collapse into a monolith on a bad Friday

Memory-safe, by the compiler

Whole categories of CVEs simply do not compile. The trade we made for predictable production behaviour.

Low, predictable latency

No GC pauses. No JVM warm-up. P99 is what you tested in staging — not a surprise at month-end peak.

Service per concern

Ledger, payments, KYC, KYB, cards, OB, notifications, sessions — each isolated, each independently deployable.

Built for SRE

Structured tracing, metrics and audit logs from day one. Operations teams get the signal they need to run a bank.

Pillar three · the agents

Five agents. One federated mind

Each agent owns a domain, plans across it, and federates with the others through NEXUS via MCP. Compliance is not a queue. Operations is not a ticket pile. It is a state, observed and acted on

  1. 01
    Compliance

    KYC, KYB, transaction monitoring, sanctions and SAR drafting — as a persistent, observable state, not a queue.

  2. 02
    Operations

    Ticketing, dispute handling, branch back-office. Routes work, drafts replies, escalates when judgement is needed.

  3. 03
    Customer

    Member-facing intelligence inside Moni and partner apps. Context-aware, never prescriptive.

  4. 04
    Product

    Pricing, eligibility, journey orchestration and partner-channel matching — measurable, explainable.

  5. 05
    Risk

    Real-time fraud, AML, credit and operational-risk signals — fed back into NEXUS lane decisions.

Rails we speak natively

Where banking actually moves

Direct integrations with the rails the UK financial system runs on

Faster Payments

Single Immediate Payments and standing orders, in & out, with reconciliation

BACS

Direct Debits, BACS Credits, AUDDIS, ARUDD and AWACS handling

CHAPS

Same-day high-value settlement integration

Pay.UK / NPA

Future-proofed against the New Payments Architecture

Open Banking

PISP and AISP — pay-by-bank, account aggregation, SCA flows

Card schemes

Issuer-processor integration, BIN sponsorship paths, 3DS, tokenisation

Posture

Security and compliance, treated like code

  • FCA-aligned controls

    Operational resilience, conduct and consumer-duty controls embedded in workflows

  • Security by design

    Defence-in-depth across services, secrets and data — controls modelled on industry frameworks

  • Audit trails

    Tamper-evident logs across NEXUS, services and agents — minute-level retrieval

  • Strong Customer Authentication

    PSD2 SCA across web, mobile and PISP flows — exemption logic where allowed

Koodooka

Talk to us

For architects, CTOs and engineering leaders evaluating the platform. Deep-dive sessions, reference architecture, and access to the people who built it

hello@koodooka.com · London