About Bitrelic
Bitrelic is the company that builds TruvaLI. Compliance officers who have carried personal responsibility in supervisory audits work in the same team as the architects who build high-volume real-time infrastructure. Our own internal controls are certified: seven ISO certificates and a SOC 2 Type II independent attestation report.
Our own controls first
A company that sells compliance software is first judged on whether it can evidence its own controls. Customers do not want to be told how data is protected, what happens during an outage and how an incident is handled: they want the certificate that goes into a vendor assessment file.
We hold seven ISO certificates and one independent attestation report. None of them is a one-off assessment: each covers a live management system that can be handed to an auditor and is kept alive through regular surveillance audits.
ISO/IEC 27001, information security management
The management system that protects information assets end to end: risk assessment, access management, supplier control, incident response, the link to business continuity, and internal audit. It is the first certificate a vendor handling compliance data is asked for, and we would rather the conversation started there.
SOC 2 Type II, independent attestation
The report that evidences security, availability and confidentiality controls operating over an audit period rather than on a single day. It is the control report global banks and financial institutions ask their vendors for.
Six more management systems
Alongside those we hold six further certificates covering business continuity, IT service management, quality, anti-bribery, customer satisfaction and occupational health and safety. All of them are listed at the bottom of this page; scope, validity and the SOC 2 report itself are shared on request, so your information security and procurement teams can use them directly in a vendor assessment.
Both sides of the table
Financial-crime software takes two separate kinds of expertise. One is knowing what the regulation actually asks for; the other is building a system that processes millions of transactions a day without delay. The two rarely sit in the same team, and the result is either a compliant product that is slow, or a fast one that cannot be defended in an audit.
Bitrelic came out of exactly that gap. The founding team pairs senior compliance officers who have carried responsibility in MASAK and central bank audits with architects who build high-volume real-time infrastructure. The compliance side usually runs the product demonstrations too.
Where the infrastructure was proven
TruvaLI's decision engine was hardened where real-time decisions are mandatory, downtime is not tolerated and every step has to remain auditable after the fact.
We worked as the end-to-end infrastructure provider to the officially licensed dealer of Spor Toto Teşkilat Başkanlığı, the Turkish state sports betting organisation. We also provided the infrastructure for a digital game system belonging to Milli Piyango İdaresi, the national lottery administration, through its chief dealer.
What those years left behind is independent of the product: the experience of running a system that decides in seconds, stays up when the load peaks, and can account for every movement afterwards.
Today's focus: payments and finance
Our weight today sits on the payments and finance side:
- Payment systems and payment institutions
- Electronic money institutions
- Closed-loop wallets
- Loyalty and points systems
- Crypto-asset service providers regulated by the Capital Markets Board (SPK)
Their question is much the same: onboarding, transaction monitoring, sanctions and PEP screening and case management are spread across four separate products, while an audit expects one coherent account. TruvaLI runs all four in one decision engine, on the institution's own servers.
Offices
Manisa, Türkiye. Home of the engineering and compliance teams.
Podgorica, Montenegro. Work across the Balkans and the European Union.
What kind of company this is
When we say we are not a technology company hiding behind an enormous marketing budget, we mean something simple: there is working software behind every capability we describe, and where it has limits we write them down.
We do not invent certificates, figures or customer names. Where a feature is not ready, we would rather say "on the roadmap" than present it as finished.
Working together
Open positions are on the careers page, and partnerships on the partner programme page.
ISO/IEC 27001
Information security: protects information assets end to end.
Certified management systemSOC 2 Type II
Security, availability and confidentiality, evidenced over an audit period: the control report global banks and financial institutions ask for.
Independent attestationSix more management systems
Each one a live, audited certificate you can hand to a supervisor, not a one-off assessment.
-
ISO 22301Business continuity: keeps the service resilient through disruption.
-
ISO/IEC 20000-1IT service management: structured enterprise IT service processes.
-
ISO 9001Quality management: continuous, measured quality improvement.
-
ISO 37001Anti-bribery: ethical governance across the supply chain.
-
ISO 10002Customer satisfaction: structured complaint handling and resolution.
-
ISO 45001Occupational health & safety: a safe working environment for the team.
Common questions
- Which certificates do you hold?
- An ISO/IEC 27001 information security management certificate and a SOC 2 Type II independent attestation report, alongside ISO 22301 (business continuity), ISO/IEC 20000-1 (IT service management), ISO 9001 (quality), ISO 37001 (anti-bribery), ISO 10002 (customer satisfaction) and ISO 45001 (occupational health and safety). Scope and validity details are shared on request.
- Are there compliance specialists on the team, or only engineers?
- Both. The founding team includes compliance officers who have carried personal responsibility in supervisory audits, and they usually run the product demonstrations.
- Which sectors use TruvaLI?
- Today's focus is payment systems and institutions, electronic money institutions, closed-loop wallets, loyalty systems and SPK-regulated crypto-asset service providers. Before those, the decision engine was hardened in high-volume regulated gaming infrastructure, where real-time decisions are mandatory.