PROPELOO

CEX / CENTRALISED EXCHANGE DEVELOPMENT

Centralised Exchange Development — built for real trading volume.

PROPELOO engineers centralised cryptocurrency exchanges — from matching engine design and order book architecture through liquidity management, KYC/AML compliance, custodial wallet infrastructure and the security architecture that keeps user funds safe. A CEX is the most technically demanding product in crypto: it must be fast, secure, compliant and available 24/7 with no tolerance for downtime or fund loss.

A matching engine that cannot handle a flash crash will fail at exactly the moment your users need it most.

Centralised exchange development is one of the most technically demanding engineering challenges in finance. The matching engine must process thousands of orders per second with microsecond-level latency and zero tolerance for matching errors — a matching bug means incorrect trades that must be reversed. The custody system must keep user funds secure against both external attacks and insider threats. The KYC/AML system must satisfy regulators across multiple jurisdictions. The liquidity system must provide tight spreads from day one, before organic market makers arrive. Every one of these is a separate engineering domain, and all must work correctly simultaneously. PROPELOO has the experience to build all of them.

The CEX engineering stack.

A centralised exchange has six distinct engineering domains. All must be production-grade before the first user deposits funds.

System Layers

  • Matching Engine Layer: Order book management, price-time priority matching, order types, clearing
  • Account & Ledger Layer: User balances, double-entry ledger, transaction history, fee accounting
  • Custody Layer: Hot/cold wallet architecture, key management, deposit detection, withdrawal processing
  • Market Data Layer: Real-time order book feed, trade history, OHLCV, ticker, WebSocket push
  • Compliance Layer: KYC/AML, sanctions screening, Travel Rule, regulatory reporting

Core Technical Capabilities

  • Matching Engine

    High-performance order book matching engine — price-time priority for spot, funding rate mechanics for perpetuals. Order types: limit, market, stop-limit, iceberg, FOK, IOC. Written in Go or Rust for sub-millisecond matching latency.

  • Custodial Wallet Architecture

    Hot wallet (10-20% of funds, operational) + cold storage (80-90%, offline multi-sig). HD wallet derivation for deposit address generation, automated sweep from hot wallet to cold, multi-sig withdrawal approval (Fireblocks or custom MPC).

  • Trading Interface

    Professional trading UI with real-time order book depth chart, trade history, TradingView charting integration, order placement panel, position management and portfolio view. Web and mobile.

  • KYC/AML System

    Identity verification (Sumsub, Jumio, Onfido), tiered KYC (Tier 1: email only, Tier 2: ID document, Tier 3: enhanced due diligence), sanctions screening (Chainalysis, Elliptic), transaction monitoring and SAR filing.

  • Liquidity Management

    Market maker integration (White Label market making or self-operated), liquidity aggregation from upstream venues, spread management, circuit breakers on price dislocation.

  • Exchange API

    REST and WebSocket API for algorithmic traders — compatible with standard trading libraries (ccxt), rate limiting per API key, co-location support, FIX protocol for institutional clients.

How we think about CEX engineering.

A CEX is not a trading application. It is a financial institution that happens to use software. Every engineering decision must be made with the same discipline as a bank.

  • The matching engine is the product

    Everything else — the UI, the API, the mobile app — is a presentation layer on top of the matching engine. The matching engine must be correct first (no matching errors, no race conditions, correct P&L accounting), fast second (sub-millisecond latency at 50,000 orders/second), and available third (no downtime during market volatility). Build and validate the matching engine before any user interface.

    Axiom:

  • Cold storage is not optional

    90% of user funds in cold storage (offline multi-sig, geographically distributed) is the institutional standard. A hot wallet holding 100% of user funds has been the setup of every exchange that lost user funds to hacks. Cold storage with a rigorous sweep schedule, HSM-backed key management and multi-party withdrawal approval is the minimum security architecture.

    Axiom:

  • Compliance is a licensing prerequisite, not a feature

    Operating a centralised exchange without proper licensing (VASP registration, FINTRAC registration, FCA authorisation, MAS licensing) creates existential legal risk as enforcement increases globally. KYC/AML must be operational before the first user deposits funds, not added after growth. Travel Rule compliance (required in most G20 countries) requires an additional technical implementation layer.

    Axiom:

  • Liquidity on day one requires a plan

    An exchange with no liquidity has no traders. No traders means no liquidity. Breaking this circular dependency requires: initial market making (self-operated or contracted), initial trading pairs with the deepest external liquidity (BTC/USDT, ETH/USDT), and an aggressive trading incentive programme (fee rebates, trading competitions) to bootstrap organic volume.

    Axiom:

CEX architecture decisions.

  • Matching engine technology?

    Impact: Go for most new exchanges — excellent performance, simpler than C++, proven at exchange scale (Binance, Kraken use Go). Rust for teams that need maximum performance or want memory safety guarantees.

    • Go — high performance, good concurrency model, most common for modern exchanges
    • Rust — maximum performance, memory safety, growing adoption
    • Java/C++ (legacy) — proven at scale, higher engineering complexity
    • Third-party matching engine — fastest to market, licensing dependency
  • Database architecture?

    Impact: Redis for hot order book state (sub-millisecond reads), PostgreSQL for the settled ledger (ACID financial records). The matching engine holds canonical order book state in memory; PostgreSQL stores the immutable settled result.

    • PostgreSQL with sharding — ACID, good for financial ledger
    • MemSQL/SingleStore — in-memory performance, ACID, high cost
    • Redis + PostgreSQL — Redis for order book state, PostgreSQL for settlement
    • Custom in-memory engine — maximum performance, maximum engineering cost
  • Custody architecture?

    Impact: Fireblocks for most new exchanges — institutional-grade custody without building MPC infrastructure from scratch. Self-managed MPC for exchanges at scale where Fireblocks per-transaction fees become significant.

    • Self-managed MPC — distributed key, no single point of failure, complex
    • Fireblocks — institutional-grade, managed MPC, per-transaction cost
    • Ledger Enterprise (HSM) — hardware security, proven, expensive
    • Custom multi-sig — transparent, auditable, slower withdrawal process
  • Market types at launch?

    Impact: Spot-only at launch. Futures adds derivatives regulation complexity (different licensing in most jurisdictions). Add futures after spot is stable and you have demonstrated product-market fit.

    • Spot only — simplest, lowest regulatory complexity
    • Spot + futures — higher volume potential, derivatives regulation required
    • Spot + margin — leverage attracts traders, requires margin management
    • Full suite (spot + futures + options + margin) — maximum complexity, highest revenue potential
  • KYC tier structure?

    Impact: Tiered KYC (Tier 1: email for low limits, Tier 2: ID document for full limits, Tier 3: EDD for institutional) is the standard — balances user onboarding friction with compliance requirements.

    • No KYC (anonymous) — not compliant in any regulated jurisdiction
    • Tier 1 (email + phone) for low limits, full KYC for higher limits — industry standard
    • Full KYC required from day one — highest compliance, higher friction
    • IP-based geo-blocking with basic KYC — pragmatic start
  • Fee model?

    Impact: Maker/taker model with competitive fees (maker: -0.01% to 0.02%, taker: 0.04% to 0.10%) is the industry standard. Lower fees attract volume; higher fees increase revenue per trade. Calibrate to target market.

    • Maker/taker model — rebates for makers, fees for takers, industry standard
    • Flat fee per trade — simple, less efficient for market makers
    • Token-based discount (like BNB) — creates token utility, complex
    • Zero fee (spread-based) — no trading fees, make money on spread

What PROPELOO builds.

  • Spot Exchange

    Full spot trading exchange — matching engine, order book, custodial wallet, KYC/AML, trading UI, REST/WebSocket API and market maker integration.

  • Derivatives Exchange

    Perpetual futures exchange with funding rate mechanism, cross/isolated margin, liquidation engine, insurance fund and professional risk management.

  • Regional Crypto Exchange

    Exchange designed for specific market (India, Middle East, Africa) with local payment methods (UPI, bank transfer), local currency pairs and jurisdiction-specific KYC.

  • Institutional Exchange

    Institutional-grade exchange with FIX protocol, co-location, prime brokerage features, OTC desk integration and institutional KYB.

  • Exchange White Label

    White-label exchange platform — branded, configurable, deployed under your brand with your supported trading pairs and your compliance configuration.

  • Exchange Technology Upgrade

    Rebuild matching engine or custody system for existing exchange — higher performance, better security architecture, regulatory compliance upgrade.

The CEX engineering stack.

  • Matching Engine

    Stack: Go / Rust, Redis (order book state), Apache Kafka (event sourcing), LMAX Disruptor pattern

  • Ledger & Database

    Stack: PostgreSQL (financial ledger), TimescaleDB (market data), Redis (hot cache), Kafka (event log)

  • Custody

    Stack: Fireblocks, MPC key management, Hardware Security Module (HSM), Multi-sig cold storage

  • Frontend

    Stack: React / Next.js, TradingView Charting Library, WebSocket (market data), React Native (mobile)

  • Compliance

    Stack: Sumsub / Jumio (KYC), Chainalysis (AML), Elliptic (transaction monitoring), ComplyAdvantage (sanctions)

  • Infrastructure

    Stack: AWS / GCP (multi-region), Kubernetes, Terraform, Datadog, PagerDuty

Exchange security must protect user funds against all attack vectors.

  • Cold storage architecture

    80-90% of user funds in air-gapped cold storage with geographically distributed multi-sig keyholders. Only the online hot wallet holds operational funds. Automated sweep from hot to cold when hot wallet balance exceeds threshold.

  • Withdrawal security

    Multi-signature withdrawal approval for all amounts above threshold. Hardware wallet signing for large withdrawals. 24-hour delay on new withdrawal addresses. Email/2FA confirmation for withdrawal changes.

  • Matching engine integrity

    Immutable event log of all order events. Real-time reconciliation between matching engine state and ledger. Automated alerts on any balance discrepancy. Replay capability for recovery.

  • DDoS protection

    Exchange trading engines are prime DDoS targets. Multi-layer DDoS protection (Cloudflare + AWS Shield Advanced), rate limiting per IP and per API key, circuit breakers on suspicious order patterns.

  • API security

    API key scoping (read, trade, withdraw — separate permissions), IP whitelist per API key, HMAC signature on all authenticated requests, anomaly detection on API usage patterns.

  • Insider threat

    Maker-checker for all administrative operations, no single person can authorise both a withdrawal and the signing, audit logs for all admin actions, regular security audits of access control.

From concept to live exchange.

  1. 01. Architecture Design

    Matching engine design, custody architecture, compliance structure, market selection, liquidity strategy.

  2. 02. Core Matching Engine

    Order book, matching algorithm, order types, settlement, event log. Load tested before any UI work.

  3. 03. Custody & Wallet

    HD wallet generation, deposit detection, hot/cold architecture, withdrawal processing.

  4. 04. Compliance Setup

    KYC/AML integration, sanctions screening, Travel Rule implementation, regulatory reporting.

  5. 05. Trading Interface

    Professional trading UI, order placement, real-time order book, charting, portfolio dashboard.

  6. 06. API & Market Making

    REST/WebSocket API, FIX protocol (if institutional), market maker integration, liquidity bootstrap.

  7. 07. Security Audit & Launch

    Third-party security audit, penetration testing, KYC/AML compliance review, staged launch.

Exchange platforms we have shipped to production.

Three exchange builds handling real trading volume today.

  • Spot exchange with in-house matching engine processing 12,000 orders/second

    Challenge: Client needed a spot exchange handling 50+ trading pairs with sub-millisecond matching, a professional trading UI with depth charts and order history, and KYC/AML integration for regulatory compliance.

    Architecture: Go matching engine with in-memory order book, Redis pub/sub for real-time price feeds, Kafka for trade event streaming, PostgreSQL with time-series partitioning for order history. WebSocket connections for live order book updates.

    Outcome: Launched with 60 trading pairs, 12,000 orders/second peak throughput, <1ms median matching latency, 99.98% uptime in first year.

  • Perpetual futures exchange with funding rate engine and cross-margin risk

    Challenge: Trading firm needed a perpetual futures exchange with up to 100x leverage, cross-margin account mode, auto-deleveraging, and a funding rate engine keeping perpetual prices anchored to spot index.

    Architecture: Rust matching engine for microsecond latency, cross-margin risk engine calculating portfolio margin in real time, 8-hourly funding rate calculation from TWAP spread, auto-deleveraging queue for risk events, insurance fund accumulation.

    Outcome: $340M cumulative trading volume in first 6 months, ADL engine triggered zero involuntary liquidations, funding rate within 0.02% of benchmark.

  • OTC trading desk with RFQ system and settlement API for institutional clients

    Challenge: Crypto prime broker needed a white-glove OTC desk system: clients send RFQs, traders respond with firm quotes, trades settle directly to client custody wallets with full audit trail.

    Architecture: RFQ workflow engine with quote expiry and acceptance, bilateral credit line management per counterparty, settlement via Fireblocks transaction workflow, real-time P&L reporting for traders.

    Outcome: $80M monthly OTC volume, average quote response time 45 seconds, 100% settlement accuracy across 1,200+ trades.

Frequently Asked Questions

What licences are required to operate a crypto exchange?

Requirements vary by jurisdiction. Common licences: VASP (Virtual Asset Service Provider) registration under FATF guidelines — required in most countries. Specific jurisdictions: FinCEN MSB registration (US), FCA registration (UK), MAS licence (Singapore), VARA licence (Dubai), AISP/PISP under MiCA (EU). Most exchanges launch in a friendly jurisdiction (Dubai, Estonia, Seychelles) and expand licences as revenue justifies compliance cost.

How much does building a crypto exchange cost?

A full-featured spot exchange with matching engine, custodial wallet, KYC/AML, trading UI and API: 8–15 months of engineering time. At a team of 5–8 engineers: $500K–$1.5M in development cost. White-label platforms (AlphaPoint, Openware) are faster and cheaper but less customisable. Licensing and compliance costs are separate and vary significantly by jurisdiction.

What is the Travel Rule for crypto exchanges?

The Travel Rule (FATF Recommendation 16) requires VASPs to share originator and beneficiary information when processing transfers above a threshold ($1,000 in most jurisdictions). This means collecting and transmitting customer information with cryptocurrency transfers, and implementing a Travel Rule protocol (TRP, TRUST, Sygna, Notabene) for VASP-to-VASP transfers. Non-compliance is a regulatory violation. Required in most G20 countries as of 2024.

How long does it take to build a crypto exchange?

A white-label spot exchange can go live in 3–4 months. A fully custom spot exchange with a proprietary matching engine, custodial wallet infrastructure, KYC/AML integration and a professional trading UI typically takes 8–15 months. Perpetual futures or margin exchanges add 3–6 months for the risk engine, funding rate module and auto-deleveraging system. A discovery sprint (2–4 weeks) at the start gives you a reliable milestone plan before full development begins.

What is a matching engine and why does it matter?

The matching engine is the core of a centralised exchange — it receives buy and sell orders and executes trades when prices cross. Performance requirements are extreme: sub-millisecond matching latency, deterministic order priority (price-time), and the ability to handle 10,000–100,000 orders per second during peak volatility. We build matching engines in Go or Rust with in-memory order books and Redis pub/sub for real-time price feed distribution. A slow or buggy matching engine means slippage, user complaints and regulatory scrutiny.

What custody architecture is best for a crypto exchange?

A tiered custody architecture is the industry standard: a hot wallet (5–10% of funds) for instant withdrawal processing, a warm wallet (15–20%) for daily rebalancing, and a cold wallet (70–80%) in air-gapped HSMs or MPC custody for long-term storage. We integrate Fireblocks or Copper for institutional MPC custody, and implement withdrawal limits, multi-sig approval workflows, and anomaly detection. The 2022 FTX collapse and 2023 Binance issues made custody architecture a regulatory priority.

How do you handle KYC and AML for a crypto exchange?

We integrate tier-based KYC: Tier 1 (email + phone, low withdrawal limits), Tier 2 (government ID + liveness check, standard limits), Tier 3 (proof of address + source of funds, institutional limits). KYC providers we integrate: Sumsub, Jumio, Onfido, Veriff. AML screening covers transaction monitoring (Chainalysis, Elliptic), wallet risk scoring, and Suspicious Activity Report (SAR) filing workflows. Ongoing transaction monitoring flags unusual patterns — velocity, dark web wallet interaction, mixing.

What is the difference between spot, margin and futures on an exchange?

Spot trading: buy and sell actual crypto assets at current market price. Settlement is immediate — you own the asset. Margin trading: borrow funds to open positions larger than your balance (2x–10x leverage). You own the underlying asset but risk liquidation if the position moves against you. Futures/perpetuals: contracts that track an asset price without owning it. No expiry (perpetuals), settled in cash, leverage up to 100x on major platforms. Each market type requires different matching engine logic, risk management, and regulatory treatment.

How do you prevent wash trading and market manipulation on a CEX?

Wash trading detection: cross-referencing buy and sell orders from accounts with shared funding sources, IP addresses or device fingerprints. Spoofing detection: flagging large orders placed and cancelled within milliseconds at the same price levels. Our platform includes a surveillance module that generates alerts for compliance review. Market maker agreements include minimum spread and uptime requirements to prevent manipulative quoting. Regulatory requirements (MiCA, SEC rules) increasingly mandate surveillance systems for licensed exchanges.

Do you build white-label crypto exchange platforms?

Yes. We offer two models: a fully custom exchange built from scratch (best for teams with specific technical or regulatory requirements), and a white-label deployment using AlphaPoint, Openware or our own platform (faster time-to-market, lower upfront cost). White-label platforms trade customisation for speed — launch in 3–4 months vs 12–18 months. Both include KYC/AML integration, custodial wallet, admin dashboard and compliance reporting. We recommend white-label for market validation and custom builds for scale.