Financial Services · 2024

Modernizing a National Securities Exchange Platform

Platform modernization and expansion for a regulated, multi-asset exchange handling equities, bonds, and tokenized securities.

Quick answer

What did Seypro build for MERJ Exchange? Five connected public, investor, issuer, and administrative platform surfaces. Live at merj.exchange (opens in new tab). Stack: React, Next.js, TypeScript, Node.js, PostgreSQL, Redis. Part of our Fintech & Regulated Systems and Cloud & Infrastructure practice.

MERJ Exchange — built by Seypro
In production · MERJ Exchange
18+
Months of continuous development
5
Interconnected platforms shipped
Weekly
Incremental production delivery cadence
Named
Regulated client and public platform

The brief.

MERJ needed to modernize its exchange infrastructure — a platform where real money moves, regulators watch, and downtime is not an option. The existing systems were aging, fragmented, and difficult to maintain. The brief: rebuild the public-facing platform and internal tooling to match the operational rigor of a licensed national securities exchange, while supporting a new asset class — tokenized securities — that most exchanges haven't touched.

How we built it.

Seypro worked with the MERJ team to modernize and expand the platform incrementally. The engagement emphasized traceable changes, regression testing, security review, and frequent production releases within a regulated operating environment.

Scope of work

The engagement covered five connected platform surfaces: the public markets interface, investor portal, issuer dashboard, administrative back-office, and supporting security controls.
  • Public exchange platform — real-time market data, listed securities, corporate actions, announcements, and regulatory filings
  • Investor portal — account management, portfolio tracking, order history, KYC document submission, and dividend reporting
  • Issuer dashboard — listing applications, disclosure management, corporate action scheduling, and compliance document uploads
  • Administrative back-office — user management, trade supervision, reporting tools, and audit trail interfaces
  • API layer — RESTful and WebSocket APIs for market data, order routing, and third-party integrations

Security as a foundation

An exchange is a target. Every component was built with defense in depth: encrypted data at rest and in transit, role-based access control with granular permissions, session management with anomaly detection, rate limiting on every public endpoint, and input validation that assumes hostile intent. We ran penetration tests before every major release and maintained a rolling vulnerability assessment program.
  • TLS 1.3 everywhere, AES-256 at rest, key rotation on schedule
  • Role-based access control with per-resource permission matrices
  • Comprehensive audit logging — every state change, every access, every admin action
  • Automated penetration testing integrated into CI/CD pipeline
  • DDoS mitigation at the edge with Cloudflare and AWS Shield
  • KYC/AML compliance workflows with document verification and risk scoring

Tokenized securities

MERJ is one of the first regulated exchanges in the world to list tokenized securities. We built the infrastructure to handle digital assets within the same regulatory framework as traditional equities — not as a separate "crypto" silo, but as a native asset class with full clearing, settlement, and custody integration. This required careful coordination with MERJ's compliance team and the Seychelles Financial Services Authority.

Performance under pressure

Market opens don't wait. We optimized for sub-second page loads on the public platform, real-time data delivery via WebSockets with graceful degradation, and database queries that hold up during peak trading hours. The infrastructure is auto-scaling on AWS with multi-AZ redundancy — the exchange doesn't go down because a server does.

The engagement connected investor-facing experiences, issuer workflows, administration, market data, and compliance tooling within one evolving platform architecture.

Stack

ReactNext.jsTypeScriptNode.jsPostgreSQLRedisAWSDockerCloudflare

Building something this serious?

This is the work we do. Tell us what you need.