Partner-held ledgers
End-customer balances live in each fintech's system. The bank receives a file or an API summary.
Banks & BaaS
Sponsor banks and BaaS platforms carry the obligations of many fintech programs at once. Orangepill gives each program isolated financial state and governed execution, while the bank keeps oversight across all of them. It runs alongside your core and your rails; it is not a bank and does not replace one.
The problem
Each new fintech partner brings its own ledger, its own payout patterns and its own idea of what a balance means. The bank remains accountable for the funds underneath. Without a shared model, oversight becomes a recurring exercise of collecting reports from partners and comparing them with bank statements.
Typical architecture today
End-customer balances live in each fintech's system. The bank receives a file or an API summary.
Funds for many end customers sit in shared accounts, and attribution depends on the partner's records being right.
Limits and program rules are checked in reviews and reports, not at the moment money moves.
Where it breaks
Orangepill model
Isolate each program. Govern every movement. Keep the evidence.
Each program and its end customers have their own ledger state and settlement boundaries inside one runtime.
Program policy is applied before execution, and program ledgers are verified against bank settlement afterwards.
The bank sees each program's obligations derived from ledger events, not from the partner's summary.
Orangepill is software infrastructure. It is not a bank, payment service provider, or regulated payment rail. Accounts, licences and settlement remain with the bank and its rails. The runtime governs the financial state and the execution that sit on top of them.
Example workflow
A request that fails policy never reaches the rail. A request that reaches the rail and returns an unclear outcome becomes a Resolve case scoped to that program, not a bank-wide investigation.
Capabilities used
Separate ledger state per program and per end customer, so one partner’s balances are never derived from another’s entries.
Explore Wallet & Ledger →Partner-initiated payouts and transfers run as governed lifecycles, with program policy checked before value moves.
Explore Execution →Structured evidence of how each program-level outcome was produced, ready for oversight and audit questions.
Explore Proof of Record →Governs breaks between program ledgers and bank settlement, with authority staying with the bank.
Explore Resolve →Outcome
Pick a program and its payout path. We will show how its state could be isolated, governed and verified against your settlement accounts.