Small Change
Fintech identity and product, end to end
A fintech that wanted to look as trustworthy as it is. We built the identity and the product surface it lives on — one voice, top to bottom.
- Year2026
- Runs onWeb
- DisciplineWebsites & Web Apps

A sample brief, a real product. We wrote this brief ourselves to show how we work; the client and their story are illustrative. The product is not: it was designed and engineered here, and you can use it below. We publish results only for work a client has let us verify, so this page shows none.
The brief
Small Change had the licence and the ambition but a look that undersold both. We built a complete identity — type, colour, voice — and the marketing product it needed to launch on.
The problem
Money is trust. The brand had to feel established on day one without pretending to a history it did not have — confident, not costume.
- An identity that reads as safe and modern
- A system that scales from favicon to billboard
- A site that converts without shouting
- Motion that feels engineered, not animated
The approach
Identity and interface were designed by the same people, in the same weeks, so nothing was lost in a handoff.
- A tight type and colour system, documented
- A component library shared by brand and web
- Copy and motion drafted together
- A build fast enough to feel premium
What shipped
- Balance derived from postings, never stored
- Idempotent send: spam the button, it moves once
- Card controls and freeze
- Budgets, scheduled payments and insights
- CSV statement
- Accounts and pots
- Physical and virtual cards with limits
- Payees, investments and SIPs
- Support tickets and disputes
Under the surface
How it is built
A NestJS core models ledgers double-entry style on PostgreSQL; Plaid links accounts, Stripe Issuing powers the card, and every money movement is an idempotent, audited command behind a Next.js front end.
- Double-entry ledger — balances derived, never stored
- Idempotency keys on all mutation endpoints
- Plaid + Stripe webhooks verified and replay-protected
- Terraform-managed AWS with least-privilege IAM
Considered and turned down
Firebase would have shipped faster; a relational ledger and typed migrations mattered more for money.
Stack
The mechanism, working
The part of Small Change that was hardest to get right, as a small model you can operate.
Double-entry ledger
Balances are derived from postings, never stored. Money can’t be created or lost, only moved.
Idempotent money movement
Every mutation carries a key. Retry the same request a hundred times, the transfer happens once.
