JA_Available
// CASE STUDY · 2026

Croe

Escrow for social commerce on Mobile Money. Croe holds a buyer's MoMo payment until delivery is confirmed, then pays the vendor automatically.

Role
Founding engineer — backend, mobile & admin
Timeline
Jul — Sep 2026
Stack
React Native · Express 5 · PostgreSQL 16 · Redis
Links
Private repo · walkthrough on request
Reviewer console · buyer appFinTech · 2026
// Sandbox · pre-launch
admin.croe · disputes
Export
CroeEscrowsDisputesReconciliationKYCLedger
DisputesAI verdicts need ≥ 0.90 confidence
ESCROWAMOUNTTRIAGE · FINDINGSTATUS
tx_01J9Q4GHS 1,200Refund buyer · confidence 0.94Tier 3 · LLM reviewAuto-resolved
tx_01J9P1GHS 450Sybil velocity trapTier 2 · SQL heuristicsFlagged
tx_01J9M8GHS 800Recycled image matchTier 1 · evidence hashFlagged
tx_01J9K2GHS 320Confidence 0.71 — below gateTier 3 · LLM reviewHuman review
Daily reconciliation: custody = sub-ledger = partnerchecksum OK
01

The problem

Social commerce in Ghana runs on trust that doesn't exist. A buyer on Instagram is asked to send Mobile Money to a stranger; the vendor is asked to ship to someone who may never pay. Vendors lose an estimated 20–30% of qualified orders to that standoff, and buyers who pay first have no recourse when it goes wrong.

Both positions are completely rational, and the sale dies between them.

— From the Croe one-pager

Results

As of the 26 Sep 2026 production-readiness audit
515Automated tests passing across backend, mobile and admin
14States in the escrow machine, every transition on the ledger
3Tiers of dispute triage: evidence hashing, SQL heuristics, LLM review
02

The build

An Express 5 API on PostgreSQL 16 and Redis, a React Native (Expo) app for buyers and vendors, and a Next.js admin for reviewers. Every money movement goes through one state machine and lands in an append-only ledger; payment webhooks are verified, de-duplicated and replay-protected before they can move state.

HTTPSHMAC + replay guardledger entriesSETNXevidenceMOBILE APPReact Native · ExpoMOMO WEBHOOKSPaystack · HubtelESCROW APIExpress 5 · 14-state machineLEDGERPostgreSQL 16 · append-onlyREDIS 7.2idempotency · rate limitsDISPUTE AIself-hosted LLM · ≥0.9 gate
// Decision 01

Money is NUMERIC(15,2), never a float

Amounts travel as decimal strings, are stored as NUMERIC(15,2) and fees are computed in minor units. There is no floating-point arithmetic on the money path, so 2.5% of GHS 1,200.00 is always exactly GHS 30.00.

// Decision 02

The ledger can only grow

UPDATE and DELETE are revoked on the ledger at the database level, not just in application code. Corrections are new entries, so every balance can be rebuilt from history and reconciled daily against custody and partner statements.

// Decision 03

Custody sits behind an interface

Holding third-party funds is regulated in Ghana. A CustodyProvider abstraction separates the product from who holds the money: aggregator sandbox today, a licensed partner bank's trust account later — a configuration switch, not a rewrite.

03

What I'd do differently

Escrow is a regulated activity, not a feature — licensing and custody shaped the architecture as much as the code did. Even with that designed in, the September production-readiness audit found gaps to close before real money moves; they're now tracked as launch gates.

The state machine and the append-only ledger. They made the hardest tests — concurrent webhook races, decimal precision, daily reconciliation — straightforward to write.

// NEXT PROJECTAutoFlowAutomation · AI · Next.js 15 · tRPC · Inngest · Prisma