One product, one ledger, one account: spot trading, perpetual futures and margin, with the wallet layer, the identity checks, the growth modules, the back office and the mobile apps in the same system. It has its own KYC. It has its own custody. It needs nothing from anyone else to run, and if you would rather use Sumsub, Fireblocks or BitGo, you can plug them in instead. We have been building and operating crypto exchange infrastructure since 2017.
It is a complete digital-asset exchange that we wrote, delivered under your brand, and operated either by you or by us. Spot, perpetual futures and margin run on one matching engine, one ledger and one user account rather than three systems bolted together, alongside the wallet and custody layer, the identity verification module, the growth and marketing stack, the fee and limits engine, the administrative back office, the public API and native iOS and Android apps. You can run it inside your own data centre with your own keys, or we can run it in ours. It is not a demo that becomes a product later and it is not a set of open-source parts behind a new logo. It is the system you will be shown in a demo session, configured for your market.
What it is not, and we will say this on the first call rather than the last: it is not a licence, a banking relationship, a market maker's balance sheet, or a compliance function. Those remain yours, and any vendor who blurs that line is selling you a problem you will discover after signature.
Exchange operators and licence applicants replacing a platform they have outgrown, upgrading legacy systems, or expanding into additional markets. The deciding question is what survives a technical review.
Financial institutions planning to offer digital asset trading, wallet, and custody experiences under their own brand. On-premise delivery and the access model usually matter more here than the launch date.
Businesses offering branded digital asset services through sub-accounts, dedicated APIs, and institutional trading capabilities.
Teams launching a digital asset exchange without building matching engines, wallet infrastructure, market data systems, or a back-office control layer themselves — including commercial teams with no engineers, who buy Managed Exchange Operations rather than software.
Consumer platforms adding branded digital asset trading as a new revenue line through institutional APIs and sub-accounts, without building exchange infrastructure of their own.
If you are migrating users, balances and verification evidence off an existing exchange, that is the first thing Discovery looks at.
The demo you will be shown is the product you would be buying, not a sales environment — which also means it is a full exchange, and a full exchange is a confusing thing to walk through with no map.
So here is the map. Five places, chosen because they are where this platform separates from the rest of the category rather than where it looks nicest. Ask for all five in your session, in this order, and ask us to hand you the controls rather than drive.
Hedge mode holding a long and a short in the same contract; the funding rate and interval visible to the user; TP/SL triggered by last, mark or limit price; the estimated liquidation price moving as margin mode or leverage changes. It is the screen most demos in this market do not reach.
Sub-affiliates, commission and rebate rates across spot and futures, custom referral codes, referred-user activity and reward leaderboards. Ask every other vendor on your shortlist to show you their equivalent, and note how many have one bullet on a slide instead.
Open a task and look at what the condition is reading: live exchange data — spot and futures volume, trade count, deposits, net balance, verification level, account age, referrals, security state. This is the difference between a growth module and a coupon table.
Tiered levels, the document set, proof of address as a separate step, source of funds and source of income as different questions, the sanctions questionnaire, and the corporate path with its register of directors and ownership structure. This module is ours — it is the line most commonly rented in this industry.
Withdrawal address whitelist. Anti-phishing code. Two-factor authentication. API key management with IP restrictions. Your risk team will ask about these before it asks about anything else.
The most useful demo session is one where somebody tries to break the product. Bring what it does badly as well as what it does well, and we will answer with the engineer who wrote that part. Judge the software, not the copywriting.
Request a Platform DemoAsk any vendor in this category one question before you ask about features: which parts of this did you write, and which parts are somebody else's? The answer sets your unit economics for the life of the venue, and it is almost never on the website.
This platform has its own identity verification. Its own wallet and custody layer. Its own node access, through infrastructure we run ourselves. Its own matching engine, its own ledger, its own growth modules, its own back office, its own mobile apps.
No third-party product is required to operate it. That sentence is short and most of our category cannot write it.
Per-check identity billing, per-transaction custody fees, per-request node quotas and per-active-user marketing tools are all priced on the same axis: your growth. A venue that succeeds pays more, on a curve it does not control. And a supplier who carries none of your risk can change terms, deprecate an endpoint or exit your jurisdiction on their timetable. When those layers are ours, your cost is one commercial conversation rather than five.
Sumsub for identity verification. Fireblocks or BitGo for custody. Because our own modules are part of the product rather than an optional purchase, they stay present whether or not you switch them on — so you can start with a third party and move to the built-in layer later, or between providers, without replacing the platform. The migration work is real and we will scope it honestly.
We do not run the public blockchains, provide your banking rails or card acquirer, own the app stores, or hold your licence. If you choose a third-party identity or custody provider, that dependency is real and it is yours — we map it during Discovery rather than after signature. The layer below the software is also ours: our own data-centre cage space in Zurich, Frankfurt and Istanbul.
Spot and futures trading, proprietary matching engines, aggregated liquidity, real-time market data, wallet integration, and account security — the capabilities running underneath every order on MCEX.
Support different order types, position modes, margin configurations, leverage tiers, and risk controls across a unified digital asset platform.
Spot orders match on price-time priority; the futures engine manages positions, margin, PnL, funding, risk tiers, and liquidations.
Aggregate order books from centralised and decentralised venues into one deeper, higher-volume book, with configurable book-building and automated hedging behind it.
Deliver real-time price, order book, trade, balance, order, and position updates with WebSocket sequence-number recovery.
Multi-asset wallet infrastructure works natively with spot and futures accounts — deposits, withdrawals, transfers, and balances in one place.
Two-factor authentication, passkeys, device management, session monitoring, and withdrawal address whitelists keep accounts and assets secure.
From order matching to institutional APIs — the operational depth behind the trading experience.
A central limit order book model using price-time priority.
Built to manage leveraged trading operations and position risk.
Between spot and futures: real assets, borrowed size, settled on the same ledger.
MCQuote fills and hedges the book from day one — market depth from centralised and decentralised venues, aggregated into one deeper, higher-volume book.
Live prices, order books, trades, and statistics streamed to every user.
Balances, deposits, withdrawals and transfers, on MCTX — node operation and one API across the chains we run.
Extend the trading experience with additional financial products.
Extensive API access for algorithmic traders, brokers, and institutional clients.
A matching engine does not grow an exchange. It is table stakes, it has been table stakes for years, and no customer has ever chosen a venue because of it. What grows an exchange is acquisition and retention: who brings users in, what makes them place a first trade, and what brings them back in a week when the market is quiet.
Almost every platform in this category stops at the order book. The affiliate programme, the referral mechanics, the campaigns, the tasks, the rewards — the machinery a growth team actually operates — are left as your problem. Build it yourself, and discover that it is a year of engineering, because payout rules have to be exactly right or your finance team is reconciling by hand every month. Or bolt on a general-purpose marketing tool that cannot see a maker fill, a futures closed position, a KYC level or a wallet balance, and so cannot enforce the conditions that matter.
Growth is a module here, and it reads the same data as the exchange, because it is part of the exchange.
A full affiliate programme covering both spot and futures, not a single referral link.
The retail counterpart to the affiliate programme.
A campaign is a set of conditions and a reward. Conditions can be combined, and they read live exchange data:
Rewards can be paid as cash, as a coupon or as commission, in steps, with a claim action the user takes. If your supervisor's view is that an incentive may not be offered in a particular jurisdiction, the campaign engine is where that rule is enforced — before the reward is granted rather than clawed back afterwards.
The same condition engine, presented as a progression rather than a promotion.
Coupons carry a claimable value. Commission coupons apply against trading fees, which is the incentive that costs a venue the least and moves behaviour the most. Bonuses and rewards can be granted directly by an operator, or issued automatically as the outcome of a campaign or task — and airdrop tools distribute assets to a defined population under the same recorded, rule-driven machinery.
Every issuance is recorded against the user and the rule that produced it, so a promotion has an auditable trail from budget to payout — which is the question your finance function will ask in month two and your auditor in year one.
A dedicated invite-a-friend flow with shareable links and QR codes, built for mobile, and connected to the same referral rewards and leaderboards rather than sitting in its own silo.
Copy trading lets customers follow experienced traders and mirror their positions, which keeps the users who would otherwise trade nowhere at all trading on your book. It is wired into the same machinery as everything else in this section. Campaign and task conditions can read copy-trading state, from enabling it to follower counts and copy-trade volume, so it can be incentivised, measured and audited like any other behaviour on the venue.
Affiliate, referral, campaign, task, coupon, bonus and reward modules are add-ons that switch on and off. Launch with referrals only, add campaigns when you have someone to run them, turn tasks off in a market where they are not appropriate. The economics — rates, tiers, budgets, conditions, eligibility — are settings in the back office, not a change request in our backlog.
Because it is the part of this product that a serious operator cannot buy elsewhere at any sensible price, and because it is where your venue's profit and loss is actually decided. The order book is a commodity. The reason a user came, and the reason they came back, is not.
Identity verification is the layer most commonly rented, and the one where renting costs the most as you grow, because it is priced per check on a population that has to be re-verified. It is built into this product. It is also replaceable, on purpose.
Identity document front and back, selfie and optional proof video, proof of address as a separate module, source of income and source of funds held as different questions, supplementary documents, and a sanctions questionnaire — combined into levels that gate limits, features and campaign eligibility.
Certificate of incorporation, memorandum and articles, register of directors and of members with recency requirements, ownership structure with ultimate beneficial owners above your threshold, authorised traders and signatories with a letter of authorisation, registered versus operating address, and nature of business from a structured list.
Prefer Sumsub, or another provider you already have a contract with? Integrate it. The case queue, the review workflow, the tiering and the audit record stay where they are, so changing provider changes your supplier — not your control environment, and not your evidence for an audit.
Every EU and Swiss venue has this on its technical evaluation. The control points the rule needs are all in one system: the originator record in our own verification module, the withdrawal path with its KYT threshold, address book and whitelist rules, on-chain and off-chain transfers distinguished in the ledger, and every administrative action attributable and exportable. In every version of the rule the obligation belongs to the licensed operator, and a vendor who tells you their product makes you compliant with it is describing something that cannot exist.
We are not going to print a travel-rule messaging implementation on a web page as a shipped feature. The protocol layer is a design conversation we work through with you during Discovery and write down before a contract — either engineered into the withdrawal path as work we do, or connected to the travel-rule provider your supervisor and counterparties already expect.
The platform is built to meet FINMA and MiCA requirements, and is designed so that a licensed operator can satisfy its FINMA and MiCA obligations. We are deliberate about that wording: a software vendor cannot hold supervisory compliance — the licence, the permissions and the obligations are yours, and any vendor who says otherwise is being loose with language.
What we can do is build the platform so that nothing in it stands between you and your obligations: transaction controls where a supervisor expects them, exportable evidence, duties separable between operations, finance, compliance and engineering, and your data where you say it sits. We do not give legal advice, and we neither sell nor arrange licences.
Most exchange losses are not matching-engine failures. They are account takeovers, phished withdrawals and API keys left unrestricted. The controls that prevent them are unglamorous and they are all here.
Email, SMS, authenticator app and passkeys, with the option to require more than one method before an account is considered protected. Sensitive changes carry a cooling-off period during which withdrawals are held.
A code the user sets that appears in every official email from your venue, so a customer can tell your message from a convincing forgery — the single cheapest control against the attack that actually drains retail accounts. QR login authenticates the web session from the mobile app, with no password typed on a machine the user does not control.
Keys are labelled, listed and revocable, with granular, separately switchable permissions: read, spot and margin trading, futures, margin loan and repayment, transfers, withdrawals. IP access restrictions can be required, a symbol whitelist limits which markets a key may act in, keys cannot be created before identity verification is complete, and secrets are shown once.
Their own balances, orders, API keys and passwords, transferable to and from the main account, freezable individually — freezing cancels open orders and deletes that sub-account's keys — with consolidated balances at the parent.
A list of logged-in devices with location, the ability to sign one out, and an account activity log of logins and sensitive actions with IP address, source and outcome.
With the preconditions a regulated operator needs: no open orders, no open positions, no outstanding borrowings, no pending withdrawals, and retention of verification records where law requires it. A public API and documentation give your institutional customers and your own tooling a supported path in.
The trading screen is where an operator's attention goes and where a customer spends a fraction of their time. The rest of the surface is what turns a visitor into an account.
A markets overview with favourites, hot coins, new listings, top gainers, losers and volume, and per-asset pages with live price summaries, market statistics and direct actions to trade, deposit or withdraw. Apply for listing gives projects a front door and gives your listings team a queue instead of an inbox.
Staking products in flexible and locked forms, selectable periods and durations, published APR tiers, subscription and redemption history, and savings products alongside. Automatic Earn accrues on an hourly or daily basis, and products support partial and early redemption with automated maturity payouts. Products, tiers, periods and caps are configured by you.
Automated grid strategies inside the platform, so the customers who want a rules-based approach do not leave for a third-party bot — and so the volume stays on your book.
A peer-to-peer market with advertisers and merchants, configurable payment methods, and the order and dispute flow around them. For venues in markets where banking rails are difficult, P2P is not a nice-to-have; it is the deposit channel.
Fiat deposit and withdrawal by bank transfer, with limits set per verification level, and a buy-crypto path presented to users who will never open an order book. Convert gives retail a quote-and-accept path between assets, and block trade handles size that should not walk the book.
Announcements and news, a help centre, and an academy for the educational content that carries a surprising share of organic search traffic. Multi-language support with bulk import and export of translations, light and dark theming with separate configurations for web and mobile, versioned terms, policies and agreements, and a centralised media and document library — so your marketing and legal teams change content without a release.
Native mobile applications for both platforms, covering registration and verification, deposits and withdrawals, spot and futures trading, asset transfer, custom trading layouts and the security features above. Distribution through the app stores or through your own channels.
Vendors demonstrate the trading screen. Your staff will spend their careers in the back office, so it is worth asking to see it.
The user submits an order through the web platform, mobile application, or institutional API.
The system validates identity, permissions and API security requirements.
Balance availability, trading permissions, order limits, leverage rules, and other business conditions are verified.
The order is processed by the spot matching engine or futures trading engine.
The result is applied to the order book and user balances, then delivered through active WebSocket connections.
We host and run the platform in our own cage space in Zurich, Frankfurt or Istanbul, with geographic redundancy and disaster recovery designed in. The same platform, without buying hardware or building a data-centre operation to look after it.
Your system is deployed within a week.
The platform deployed into a public-cloud tenancy — yours or one we stand up for you. Deployment time depends on the choices you make: the cloud provider, the regions, the network design and what your compliance function requires of the environment.
The platform on a private cloud — including the managed private clouds we build and operate ourselves. Deployment time depends on the choices you make.
The platform runs in your data centre or your own tenancy. You hold the keys, the data and operational control, and there is no call-home dependency on us to keep trading. Fully customisable — behaviour, not only branding. This is where regulated institutions and banks usually land, and it is the model that makes the dependency argument above real rather than rhetorical. Deployment time depends on the choices you make.
Run an exchange without hiring a technical team.
We take deployments, upgrades, monitoring, node operation, wallet operations, capacity planning, security patching and incident response. You take listings, pricing, marketing, compliance decisions and your customers.
This is a real commercial position, not a hosting upsell. It lets a firm launch with a commercial team and no engineers, at a moment when senior exchange engineers are both expensive and slow to hire. It is also worth saying out loud in your own market: your customers care that competent people are on call, not that those people sit on your payroll. Firms use this line in their own marketing, and they are right to.
In our infrastructure services — private cloud, GPU platforms, DevOps — our team does not need to see application data and does not: the boundary is the platform, not the records running on it. Managed Exchange Operations is a different service and cannot honestly be described the same way. Operating a live exchange means named engineers of ours hold administrative access to systems that carry your customers' personal data, their balances and their transactions. Any supplier who offers to run your exchange and also tells you they never touch your data is being inaccurate about one of those two statements, and it is worth working out which.
On platform-as-a-service, your system is deployed within a week. On public cloud, private cloud and on-premise, deployment time depends on the choices you make — the environment, the network design, the custody structure and what your compliance function requires of them.
Now the honest part, because you will hear a shorter answer elsewhere. The software is rarely the long pole. Banking relationships, licensing, identity-provider onboarding, listing decisions, treasury policy and your own go-to-market usually take longer than the platform does. Any vendor who quotes you a launch date before seeing your regulatory position is guessing. We map the critical path with you during Discovery, mark which parts we control and which we do not, and put it in writing before a contract rather than after one.
Every vendor in this category publishes throughput and latency figures. None of them publish the hardware, the book depth, the instrument mix, the order profile or the measurement method behind those figures, which makes them impossible to compare and impossible to verify. Reading one tells you nothing about how the system will behave on your workload. It tells you only what conditions the vendor chose.
So before you commit, we run a live load test and stress test of the platform with you. Proof of Performance is a scheduled, structured session:
Instruments and markets, order profile and cancel rate, book depth, user concurrency, deposit and withdrawal load, funding settlement, and the failure conditions you want to see.
Defined hardware, a real build of the platform, with the configuration written down. Not a simulation and not a slide.
Including what happens when we deliberately break something — a node, a venue connection, a database primary, a data centre. Including a liquidation cascade if that is what keeps your risk officer awake.
The measurements and the configuration that produced them, so you can put them next to anything else you are evaluating and compare like with like.
You see how the real system behaves under real load, instead of reading a number in a brochure. If the results are not what you hoped, you will have found that out before signing rather than after launching.
Request a Proof of Performance sessionThe core team has worked together since the 1990s — more than thirty years in computing, programming, networking and large-scale systems. It has been building and operating crypto exchange infrastructure since 2017. It is a senior team by design. Other companies consult us on problems that require deep engineering.
The people who wrote the matching engine, the wallet layer and the node infrastructure are the people who will be on your calls. There is no delivery organisation between you and the engineers, and no offshore layer that has to escalate your incident to someone who has seen the code.
Nothing to sign and nothing to fill in beyond this: the engineers who wrote the platform take a technical conversation before there is a contract.
You will learn more from one hour inside the product than from any deck. Ask for a demo session, use the platform as an end user and as an operator, and bring us the questions it raises — the awkward ones especially. Then let us run a Proof of Performance session against a scenario you define, on defined hardware, before you commit to anything.
If you are earlier than that, still building the business case, choosing between deployment models or waiting on a licence, tell us where you are and we will give you a straight answer about whether we are the right supplier. Sometimes the answer is no, and it is cheaper for both of us to establish that now.
Or email us directly at [email protected] · Minimal Code Systems on LinkedIn · More about how we work
Alongside this product: MCQuote, which fills and hedges the book · MCTX, node operation and one API across the chains we run.
Part of Blockchain & FinTech.