Centralized Exchange Development Company
We build centralized exchanges that hold real order flow. 120+ exchange platforms delivered across 20+ regions, with the matching engine, custody, ledger and compliance layers engineered as one system rather than assembled around a rented script.
Spot, margin and derivatives. Institutional custody or self-custody. Liquidity connected before launch day, not after it.
What Centralized Exchange Development Actually Involves
Centralized exchange development is the process of building a custodial trading platform where the operator holds user assets, maintains the order book, matches trades internally and settles them on its own ledger before touching a blockchain. Unlike a DEX, trades do not execute on-chain. The chain is used for deposits and withdrawals only, which is why a CEX can offer sub-second execution and why the operator carries custody, compliance and solvency obligations that a DEX operator does not.
A production exchange is seven systems that have to agree with each other at all times.
Matching engine and order book
Accepts, validates, sequences and matches orders under price-time priority.
Ledger
Tracks total, available and locked balances per user per asset with double-entry integrity.
Wallet and custody layer
Generates deposit addresses, monitors confirmations, signs and broadcasts withdrawals.
Liquidity layer
Supplies depth on both sides of the book through aggregation or market makers.
Fiat rails
Moves value between bank and exchange in both directions.
Compliance layer
KYC tiering, sanctions screening, transaction monitoring and Travel Rule.
Admin and risk console
Operator control over users, limits, fees, listings, treasury and incident response.
Most vendors sell the first system and the trading interface. The remaining six are where exchanges succeed or fail.
Inside a Centralized Exchange: From Order Placement to Settlement
A single limit order passes through six stages between the user pressing submit and the trade appearing in their history. Total round trip on a well-built engine is single-digit milliseconds, and almost none of it is spent on matching.
Intake and authentication
Order arrives at the API gateway. Session token validated, API key permissions checked, rate limit applied per key and per IP.
Pre-trade validation
Symbol enabled. Price and quantity conform to tick size and lot size. Order type permitted, notional within limits.
Risk check and balance lock
Ledger queried for available balance, not total. The required amount moves from available to locked before the order reaches the book. Locking after matching is a race condition.
Matching
Order enters the book and matches under price-time priority. Single-threaded per market so sequencing is deterministic and replayable.
Settlement
Ledger updated atomically for both sides. Balances adjust, locks release, maker and taker fees deducted by tier. All or nothing.
Market data and custody
Book deltas and trade prints publish to subscribers, sequence-numbered. Chain interaction happens only on deposit detection and withdrawal broadcast.
Matching Engine
- Price priority first
- Then time priority
- Single-threaded per market
- Deterministic and replayable
Have an architecture already drafted?
Bring it to a scoping call and we will review the matching, ledger and custody design against what we run in production.
Exchanges We Have Built
Three platforms from our exchange portfolio, each with a published case study.
Zircap · Centralized exchange with native token
A controlled exchange on Ethereum with its own utility token, MultiSig wallet security and matching web and mobile clients. Order execution measured at 50ms.
ESX Exchange · Exchange with integrated custody and staking
An exchange and wallet in one product, built with a six-tier staking mechanism, three layers of wallet security and multi-chain asset support.
Trustlink · Decentralized exchange on Ethereum
A non-custodial trading venue supporting 150+ trading pairs with no intermediary in the settlement path, plus built-in verification and community chat.
Centralized Exchange Development Services
Seven engagement models. Most clients start with one and add others after launch.
Custom CEX Development
Full build from architecture to production. Matching engine, ledger, custody integration, compliance stack and admin console specified against your markets and jurisdictions. You own the codebase. For operators needing derivatives or unusual market structure.
White-Label CEX Deployment
Our exchange platform configured to your brand, markets, fee structure and compliance profile. Faster to market and lower upfront cost, with a defined customisation boundary agreed before work starts. For a first exchange where speed matters more than differentiation.
Exchange Modernisation and Migration
Moving an operating exchange off aging infrastructure without losing balances, order history or users. Ledger reconciliation, wallet migration under dual control, and a cutover plan with rollback. For operators on a script that cannot scale.
Security Audit and Penetration Testing
Independent review of an exchange you already run or are about to launch. Application, infrastructure, wallet handling and withdrawal path. Delivered as a findings report with severity ratings. For pre-launch, pre-licence or post-incident review.
Liquidity and Market Maker Integration
Connecting your order book to external depth so it is not empty on day one. Aggregator integration, market maker onboarding, and spread and depth monitoring after launch. For every new exchange, without exception.
Compliance Implementation
KYC provider integration with tiered verification, sanctions and PEP screening, transaction monitoring, Travel Rule handling and jurisdiction-specific rule configuration. For regulated markets and licence applications.
Managed Operations and SRE
Ongoing responsibility for uptime, monitoring, incident response, node infrastructure, patching and release management after launch. For teams without an in-house infrastructure function.
Trading Modules and Order Types
What you turn on determines what you have to build underneath it. Modules are grouped by the infrastructure they require.
Core Trading
Matching engine, order book, ledger, market data
Conditional order store, trigger monitoring
Quote engine, spread config, inventory
Leverage & Derivatives
Collateral accounting, borrow book, liquidation, insurance fund
Portfolio risk, unified collateral, tiered maintenance margin
Funding rate, mark and index price, ADL, insurance fund
Expiry and settlement, Greeks and margin models, exercise
Alternative Venues
RFQ workflow, quote management, off-book settlement, higher KYC
Escrow, dispute resolution, reputation, payment proof
Signal distribution, proportional replication, performance accounting
Yield & Distribution
Reward accrual, lock periods, validator integration, yield accounting
Subscription and allocation, vesting, KYC gating per sale
Margin and derivatives are not features you add to a spot exchange. They require a liquidation engine, an insurance fund and a risk model that has to be designed before the ledger is finalised. Retrofitting them costs more than including them in the original architecture.
Wallet Architecture, Custody and Treasury
Custody is the largest architectural decision an exchange operator makes. It determines your insurance position, your licensing options, your operating cost and how fast you can go live.
The Three-Tier Wallet Split
Automated signing, online. Meets routine withdrawal demand without human approval.
Multi-party approval, semi-online. Replenishes hot wallets, handles large withdrawals.
Offline, geographically separated, multi-signature. Long-term reserve, never automated.
Self-Custody or Qualified Custodian
Self-custody
HSM, MPC or multi-signature held in-house. Full control over any asset and lower long-term cost, but the custody obligation and security engineering sit with you.
Qualified custodian
Institutional custody integrated through a documented API. Insured storage and a shorter path to launch, at the cost of ongoing fees and a constrained asset list.
Multi-signature
M-of-N approval on-chain. Well understood, transparent, chain-dependent.
MPC
Key material never exists whole. Signing is distributed and chain-agnostic.
HSM
Keys generated and used inside tamper-resistant hardware, never exported.
Solving the Liquidity Cold Start
A new exchange opens with an empty order book. The first user sees no depth, cannot trade at a sensible price and does not return. This is the most common reason a technically sound exchange fails, and it has to be solved before launch rather than after.
ORDER BOOK
Liquidity aggregation
Order book mirrored from external venues so your users trade against existing depth. Fastest to deploy.
Market maker agreement
A professional firm quotes both sides to committed spread and depth targets. Real depth on your own book.
Order book sharing
Your book combined with a partner exchange on the same infrastructure, on a revenue share.
Internal market making
Your own quoting strategy against your own inventory. Full control, full exposure.
We connect and monitor spread, depth and slippage before go-live so the book is populated on day one. Blockchain App Factory maintains working relationships with Binance, BitMart and XT, which is also relevant when the same operators later pursue token listings.
Fiat On-Ramp, Off-Ramp and Payment Rails
Fiat access decides whether your exchange serves people who already hold crypto or people who do not. The second group is considerably larger and considerably harder to onboard.
Third-party on-ramp
Card, bank transfer and local methods through an embedded widget. Provider carries KYC and chargeback risk. Highest fee, fast to integrate.
Direct bank integration
Lowest per-transaction cost, full control of the flow, settlement in your own accounts. Lowest cost, hardest to obtain.
Local method aggregation
Coverage of the rails people in your target market actually use, which is rarely card. Per-market effort, reconciliation load.
Stablecoin as fiat proxy
Avoids bank rails entirely for deposits. Does not solve onboarding for users without crypto. Varies by jurisdiction.
- ● Deposit reference matching, so an inbound transfer is attributed correctly
- ● Settlement timing and float management, since fiat settles slower than crypto
- ● Chargeback and reversal handling after the user has already traded
- ● Daily payment reconciliation against the exchange ledger
- ● Per-jurisdiction limits and reporting
The item most often missed: chargeback exposure. A card deposit can be reversed weeks after the user has withdrawn the crypto. Mitigations include withdrawal holds on card-funded balances, tiered limits by KYC level, and restricting card deposits to non-withdrawable trading balance until a hold period expires.
KYC, AML, KYT and Travel Rule Compliance
Compliance for an exchange is an engineering problem before it is a legal one. The obligations translate directly into gating logic, screening calls, monitoring rules and reporting jobs that have to exist in the codebase.
Tiered KYC and Feature Gating
Email and phone, verified
Account creation, deposits in some jurisdictions, no trading
Government ID, liveness check, address
Trading, withdrawals up to a daily limit
Proof of address, source of funds
Raised limits, fiat rails, margin access
Entity documents, UBO identification, director verification
Institutional limits, API trading, OTC desk
Feature gating enforced server-side at the account level, never in the client. Verified identity fields treated as immutable once approved, with any change requiring re-verification.
The Compliance Modules
Identity verification
Document authenticity, liveness, data extraction.
Sanctions and PEP screening
OFAC and other sanctions lists, politically exposed persons, adverse media.
Transaction monitoring (KYT)
Risk-scores blockchain addresses and flows, flags exposure to mixers, sanctioned addresses and darknet sources.
Behavioural AML
Detects structuring, rapid in-out movement, unusual counterparty patterns.
Travel Rule
Transmits originator and beneficiary data alongside qualifying transfers between institutions.
Case management
Alert queue, investigator workflow, decision audit trail, regulatory reporting.
Jurisdictional requirements differ significantly. Licensing regimes, permitted activities and capital requirements should be resolved with local counsel before architecture is finalised, because they determine custody model, asset list and whether margin can be offered at all. We build to the requirements your counsel defines rather than advising on the law itself.
Security Architecture and Pre-Launch Testing
An exchange is a permanent, well-funded target from the day it holds its first deposit. Controls are grouped by layer, and each one exists to close a specific attack path.
2FA on login, withdrawal and security changes · TOTP preferred over SMS · Anti-phishing code in outbound email · Device and session registry with remote revoke · Withdrawal whitelisting with cooling period · Account lockdown on password or 2FA change · Credential stuffing detection · Bot protection at signup and login
Input validation and parameterised queries · CSRF and SSRF protection · Rate limiting per key, IP and endpoint · Secrets in a managed vault · Signed API requests with timestamp and nonce · Strict transport security · Secure cookie flags · Full TLS
No private key on an internet-facing host · Dual control on withdrawals above threshold · Policy engine by asset, destination and velocity · Cold storage geographically separated · Multi-signature and MPC · Proof of reserves reconciliation
DDoS mitigation at edge · Trading API and public site on separate paths · Web application firewall · Network segmentation isolating the signing environment · High availability across zones · Tested disaster recovery with defined RPO
Least privilege access · No standing production database access for engineers · Immutable audit logging shipped off-host in real time · Approval workflows on privileged actions · Incident response runbook with named commander
Our Three-Stage Pre-Launch Process
Cyber security check
Comprehensive review of SSL configuration, cookie security, MFA implementation, anti-phishing measures, device management, strict transport security, SPF records, AML controls and WAF rules.
Penetration test
Extensive testing to identify security vulnerabilities, with findings resolved before the technical infrastructure is finalised.
Bug bounty
Structured testing against the full beta build to surface issues that internal review missed and that real users would otherwise find first.
Admin Console, Risk Engine and Back-Office Operations
Most vendors sell the trader interface. The operator spends far more hours in the admin console, and the quality of that console determines whether the exchange can be run by a team rather than by whoever has database access.
- Search and account lookup
- KYC review queue
- Tier assignment
- Limit override
- Freeze and unfreeze
- Session revoke
- Market enable and disable
- Tick and lot size
- Min and max notional
- Halt and resume
- Cancel-all
- Maker and taker schedules
- VIP tiers by volume
- Referral and affiliate rates
- Promotional overrides
- Listing workflow
- Technical review gate
- Contract verification
- Deposit test
- Staged enablement
- Hot, warm and cold visibility
- Sweep and refill triggers
- Withdrawal approval queue
- Trading volume
- Revenue by stream
- Balance reconciliation
- Compliance reports
- Exportable for audit
APIs, Market Data and Integrations
Institutional flow arrives through the API, not the web interface. API quality determines whether market makers, algorithmic desks and aggregators can connect to your exchange at all.
| Interface | Typical consumer | What it carries |
|---|---|---|
| REST API | Retail integrations, portfolio tools, back-office | Account state, order placement and cancellation, historical trades, deposit and withdrawal operations |
| WebSocket public | Aggregators, charting, data vendors | Order book snapshot and deltas, trade prints, ticker and candle streams, all sequence-numbered |
| WebSocket private | Active traders, market makers | Order status, fills, balance updates, position and margin events |
| FIX | Institutional desks, professional market makers | Order entry and market data over the protocol trading firms already run |
| Webhooks | Operator systems | Deposit confirmed, withdrawal completed, KYC status changed |
Standards that decide whether professionals use it
Platform integrations
TradingView charting with your order book as the data source. Blockchain node infrastructure per chain supported. Custody provider APIs. KYC and KYT provider APIs. Fiat on-ramp SDK. Notification delivery across email, SMS and push. Analytics and BI pipeline.
How We Deliver: Phases and Deliverables
Each phase produces artefacts you keep, whether or not you continue to the next one.
Discovery and architecture
Market and jurisdiction definition, asset and pair list, module scope, custody model decision, throughput and latency targets, threat model.
- ●System architecture diagram
- ●Technology stack decision record
- ●Custody model recommendation
- ●Threat model
- ●Scope and estimate
UX and interface design
Trading interface, onboarding and KYC flow, wallet and transaction screens, admin console, mobile layouts.
- ●Wireframes
- ●High-fidelity designs
- ●Interactive prototype
- ●Design system and components
Core development
Matching engine, ledger, order management, risk checks, user and account services, admin console.
- ●Working exchange core in staging
- ●API specification
- ●Database schema and migrations
Integrations
Custody, liquidity, KYC and KYT, fiat rails, blockchain nodes, notifications, analytics.
- ●Integrated staging environment
- ●Integration runbooks
- ●Sandbox credentials for your team
Security testing and QA
Functional and regression testing, load testing to the agreed throughput target, cyber security check, penetration test, bug bounty on beta.
- ●Test reports
- ●Load test results against target TPS
- ●Penetration test findings and remediation
- ●Bug bounty summary
Deployment
Production infrastructure, monitoring and alerting, disaster recovery, key ceremony where self-custody applies, staged go-live.
- ●Production environment
- ●Monitoring dashboards
- ●Incident runbook
- ●DR plan with tested restore
- ●Operator training
Post-launch support
Defect resolution, performance tuning, module additions, infrastructure operations under an agreed service level.
- ●Support agreement with response targets
- ●Release schedule
- ●Quarterly architecture review
Start at Phase 01
A scoping call produces the architecture sketch and estimate, whether or not you proceed.
Book a scoping callCentralized Exchange Development Packages
Three configurations covering most exchange launches. Scope determines price, so each tier describes what is included rather than what it costs.
Basic
Spot exchange, single market, fastest route to a live book
- ✓ Spot trading
- ✓ Market and limit orders
- ✓ Standard TPS matching engine
- ✓ Level 1 KYC
- ✓ Hot wallet
- ✓ Basic referral system
- ✓ SSL and 2FA
- ✓ Cloud infrastructure
- ✗ Stop-limit and OCO
- ✗ Margin and futures
- ✗ Mobile app
- ✗ Staking and earn
Medium
Spot plus leverage and mobile, for operators building a real product surface
- ✓ Everything in Basic
- ✓ Stop-limit and OCO orders
- ✓ Isolated margin trading
- ✓ Basic futures trading
- ✓ Enhanced TPS matching engine
- ✓ Mobile app
- ✓ Tiered KYC
- ✓ Hot and cold auto-split wallets
- ✓ Advanced tier referral system
- ✓ Basic earn module
- ✓ Multi-sig and risk monitor
- ✓ Cloud scalable infrastructure
Premium
Derivatives, custody-grade wallets and DR, for institutional scale
- ✓ Everything in Medium
- ✓ Cross and isolated margin
- ✓ Perpetual futures and options
- ✓ 100,000+ TPS matching engine
- ✓ Advanced mobile app
- ✓ Advanced AML and geo-blocking
- ✓ Custody grade wallets with HSM
- ✓ Affiliate and IB module
- ✓ Flexible, fixed and insurance fund staking
- ✓ AI fraud detection and audit support
- ✓ Hybrid cloud with DR setup
Full Package Comparison
| Capability | Basic | Medium | Premium |
|---|---|---|---|
| Spot trading | Included | Included | Included |
| Market and limit orders | Included | Included | Included |
| Stop-limit and OCO orders | Not included | Included | Included |
| Margin trading | Not included | Isolated | Cross and isolated |
| Futures trading | Not included | Basic futures | Perpetual and options |
| Matching engine capacity | Standard TPS | Enhanced TPS | 100,000+ TPS |
| Mobile app | Not included | Included | Advanced |
| KYC levels | Level 1 | Tiered KYC | Advanced AML and geo-blocking |
| Wallet system | Hot wallet | Hot and cold auto-split | Custody grade with HSM |
| Referral system | Basic | Advanced tiers | Affiliate and IB module |
| Staking and earn module | Not included | Basic earn | Flexible, fixed and insurance fund |
| Security | SSL and 2FA | Multi-sig and risk monitor | AI fraud detection and audit support |
| Infrastructure | Cloud | Cloud scalable | Hybrid cloud with DR setup |
| Request a quote | Request a quote | Request a quote |
Packages describe scope, not a fixed price. Final cost depends on trading modules, custody model, compliance jurisdictions, liquidity arrangement and throughput target.
Revenue Models for Exchange Operators
Nine monetization mechanisms available to centralized exchange operators. Configurable in the admin console.
Taker fee
Percentage of trade value. Primary revenue for most exchanges.
Maker fee or rebate
Percentage, sometimes negative. Often set to zero or negative to attract liquidity.
Withdrawal fee
Flat per asset. Should cover network cost with a margin, not act as a profit centre.
Listing fee
Per token. Requires a credible listing review process to be defensible.
Margin interest
Rate on borrowed funds. Scales with margin adoption.
Liquidation fee
Percentage of liquidated position, partly directed to the insurance fund.
Staking margin
Share of staking rewards. Requires validator or partner relationships.
Launchpad fee
Percentage of raise, or token allocation. Dependent on project pipeline.
API and data tiers
Subscription. Institutional users pay for higher limits and lower latency.
Technology Stack
The stack below reflects what we build exchanges with. It is deliberately shorter than an exhaustive list, because an exchange team that claims fourteen backend languages does not have an opinion.
Core engine
Services and frontend
Mobile
Data and messaging
Chains
Infrastructure
Why Exchange Operators Choose Blockchain App Factory
Exchanges in production, not prototypes
Exchange platforms delivered across 20+ regions. Zircap, ESX and Trustlink are published with case studies and a named client on video.
Engineering held in-house
Blockchain and fintech engineers on staff. The team that scopes your matching engine is the team that builds it.
Certified against real standards
ISO/IEC 27001 and SOC 2 Type II. For a platform holding customer assets, independent certification of how we handle your architecture and data is a filter worth applying to every vendor on your shortlist.
Security tested before launch
Cyber security check, penetration test and bug bounty on the beta build. Findings resolved before infrastructure is finalised, not after users arrive.
Exchange relationships that matter later
Working relationships with Binance, BitMart and XT, relevant when your own token or listed assets need distribution.
From build to launch
Exchange engineering, token development, security audit and go-to-market under one roof, so the technical claims in your marketing are checked by the people who wrote the code.
Launch Readiness Checklist
Everything that should be true before an exchange opens to the public.
- ● Matching engine load tested to target TPS
- ● Ledger reconciliation balancing against chain state
- ● Failover and disaster recovery restore tested
- ● Monitoring and alerting live with on-call rota
- ● Penetration test completed, critical findings closed
- ● Key ceremony completed, cold storage separated
- ● Withdrawal whitelisting and dual control enabled
- ● Incident response runbook with a named commander
- ● Tiered KYC live with server-side gating
- ● Sanctions screening and transaction monitoring active
- ● Travel Rule and geo-restriction configured
- ● Terms and risk disclosures reviewed by counsel
- ● Depth present on every listed pair at launch
- ● Market maker agreements signed and quoting
- ● Spread and slippage tested at realistic sizes
- ● On-ramp and off-ramp tested end to end
- ● Chargeback handling and withdrawal holds configured
- ● Daily reconciliation against the ledger
- ● Admin roles configured, no shared accounts
- ● Support team trained with documented escalation
- ● Fee schedule and treasury policies live
- ● Status page and communication plan ready


