Cloud-native banking infrastructure

Quiet infrastructure
for moving money.

Swepay builds identity, certificates, and authentication infrastructure for fintechs entering the Brazilian market — FAPI-ready, LGPD-compliant, ICP-Brasil aware.

ComplianceFAPI 1.0 AdvancedTrustICP-Brasil awarePrivacyLGPD by defaultFootprintsa-east-1 native
01 — Essence

A short way to pay.

Swepay sells the unglamorous parts of finance — identity, certificates, authentication. The brand reflects that: precise, restrained, dependable. We borrow our discipline from Scandinavian engineering, our clarity from developer tooling, and our temperament from infrastructure that just works.

Promise

Quiet by design.

Your customers' brands are loud. Ours is the steady hum behind them. We earn trust by disappearing into the work.

Audience

Builders of money.

CTOs, security leads, and platform engineers at fintechs and banks. People who choose tools by reading the docs first.

Posture

Brazil-native by design.

We treat Bacen, ICP-Brasil and LGPD as first-class concerns, not afterthoughts. The compliance perimeter is the product.

02 — Brazilian market

Brazil is hard.
That's the point.

Brazil's financial stack has a regulatory perimeter that doesn't exist anywhere else. Foreign fintechs typically lose 12–18 months learning it the hard way. Swepay sells those months back to you, as infrastructure.

What we handle

The plumbing between you and the regulator.

From sovereign certificate trust chains to FAPI-grade authorization flows and consent ledgers, we operate the layer that sits between your product and Brazil's financial regulators. You ship features. We carry the audit trail.

Built in sa-east-1 with multi-region failover. Designed for institutions that can't afford a Sunday outage.

Regulatory perimeter

ICP-BrasilSovereign PKI · A1/A3 client certsSolved
FAPI 1.0 Adv.PAR · JARM · mTLS · DPoP · PKCESolved
Open FinanceBacen directory · consent · DCRSolved
Res. BCB 4.893Cybersecurity policy · audit logSolved
Circ. 3.978AML / CFT signal hooksSolved
LGPDLawful basis · retention · DSRSolved
03 — Products

Three products.
One trust fabric.

Buy them together and they share the same identities, certificates, and audit trail. Buy them separately and each one drops cleanly into an existing stack.

swepay · native guard

Native Guard

A FAPI-aligned OIDC / OAuth 2.1 authorization server. Managed alternative to self-hosted Keycloak with the regulatory perimeter built in. Multi-tenant, multi-realm, native AOT runtime.

  • PAR · JARM · mTLS · DPoP · PKCE
  • Private Key JWT client auth
  • PS256 / ES256 signing · JWKS rotation
  • Dynamic Client Registration (DCR)
  • Bot defense via Turnstile per realm
swepay · ca manager

CA Manager

API-first private CA for issuing, revoking and bundling mTLS client certificates. CRL and OCSP endpoints out of the box. Built for Open Finance Brasil and bilateral banking integrations.

  • REST API · per-tenant key isolation
  • CRL distribution · OCSP responder
  • PKCS#12 / PEM bundles · presigned URLs
  • Profile-based issuance (BCB, Bacen, internal)
  • Audit trail signed end-to-end
swepay · passkey

Passkey

FIDO2 / WebAuthn passwordless authentication. Plugs into Native Guard, or stands alone behind any existing IdP. Phishing-resistant by construction. Friendly to your end users, hostile to attackers.

  • WebAuthn level 3 attestation
  • Cross-device passkey sync
  • Platform & roaming authenticators
  • Step-up auth for high-value flows
  • Standalone JS SDK · no IdP lock-in
04 — Specs

Numbers that matter to engineers.

We optimise for cold start, p99 latency, and audit completeness. The boring numbers. The ones that show up at 3am when your incident channel lights up.

<50ms

Cold start

.NET 10 Native AOT, single-binary lambdas. No JIT warm-up tax.

99.95%

SLA target

Multi-AZ in sa-east-1 with cross-region failover for critical paths.

7y

Audit retention

Tamper-evident logs aligned to Bacen / Open Finance retention rules.

100%

Tenant isolation

Cryptographic key separation per tenant. No shared blast radius.

05 — For technical decision-makers

Built for the people
who pick the tools.

Swepay is sold to engineering and security leadership. Not because finance teams aren't smart — but because what we sell is, fundamentally, an architectural decision.

CTO · VP Engineering

Buy back the next 12 months.

Stop staffing a 4-person team to build an OAuth server you don't want. We've done it; it's aligned with FAPI 1.0 Advanced; it runs.

Head of Security · CISO

Defensible audit trail.

Cryptographically signed logs, sender-constrained tokens, mTLS by default. Designed to support a Bacen audit.

Security Architect

Standards, not surprises.

FAPI 1.0 Advanced, RFC 9449, RFC 9126, RFC 8705. We follow the spec; we don't invent dialects.

Head of Compliance

LGPD-aware on day one.

Lawful-basis tagging per data class, consent ledger, retention schedule, DSR endpoints. Privacy as a contract.

06 — Contact

Talk to engineering, not to a sales funnel.

Bring a real problem and we'll bring a real architect. We respond from a working address, not a CRM. Expect a reply within one business day.