Compliance software
We built Arx Compliance alongside its founders, from the first prototype to an enterprise platform certified to ISO 27001 and running inside banks and public agencies, in seven months.
- Client
- Arx Compliance AS
- Duration
- 7 months
- Result
- ISO 27001:2022 certified
Services
Domains
Tooling
- Next.js
- TypeScript
- Rust
- Azure
- BankID/SSO
- BRREG
Result
- ( r1 ) Seven months from prototype to an enterprise-ready product, certified to ISO 27001:2022.
- ( r2 ) The first pilot customer signed while the MVP was still in users' hands.
- ( r3 ) In production with SpareBank 1, Odin Forvaltning, Arctic Asset Management, and Statens vegvesen.
- ( r4 ) We helped Arx hire a CTO and build an in-house engineering team, then handed the platform over for them to run themselves.
Arx Compliance came to us with a clear target: the paper-heavy, stagnant world of compliance reporting. Their founders wanted one platform where regulated businesses could report and follow up on employees' investments and outside activities across every instrument, in one place, instead of the fragmented spreadsheets and legacy tools the industry still runs on.
Reporting an employee's private trades, board seats, and outside interests usually means stitching together spreadsheets, emails, and half a dozen systems that were never built to talk to each other. Arx wanted to replace that with a single source of truth, one that could still meet the security and scale a large enterprise demands.
The founders were not looking for a vendor to hand a spec to. They wanted a technical partner who builds companies from idea to product, and who could help them hire a CTO and stand up an in-house engineering team so Arx could carry the platform forward on its own.
From a prototype in front of real users to an enterprise platform in seven months. Next.js and TypeScript across the stack, one dedicated search service in Rust, and infrastructure that keeps regulated data inside Norway.
We started with a prototype so the founders could gather real feedback and sharpen the direction, shipped an MVP that covered the core reporting and follow-up, then scaled to a small team to build out the enterprise platform. It runs on Next.js and TypeScript on the front end, fast and responsive. Users report and follow up on compliance data across different financial instruments in one place, and the platform holds it together as the rules change.
The platform is TypeScript from front to back, with one deliberate exception. Compliance means checking people and holdings against large, global sets of company and securities data, so we built that search as a separate service in Rust, running apart from the core application where it can be tuned for raw performance. It aggregates and searches large volumes of data quickly, without slowing the rest of the platform down.
Regulated customers care as much about where their data lives as what the product does. We deployed on Azure with infrastructure built to scale, and kept all sensitive data stored exclusively in Norway to meet local rules. Access runs through BankID and single sign-on, and the platform is certified to ISO 27001:2022.


