Enterprise Networks

August 10, 2026

Fintech connectivity that can withstand a CNBV audit

Reseller SLAs do not hold up to a CNBV audit. How Telecom District operates fintech connectivity using its own backbone and verifiable evidence.

Network engineer reviewing telemetry and availability logs on a console with multiple monitors

By Eduardo Martino, COO of Telecom District.

The connectivity issue faced by a regulated fintech company in Mexico arises the day the auditor requests traceability of the connection, and all that’s on the table is an Excel spreadsheet containing a reseller’s SLA. This is the model that actually stands up to scrutiny, from the perspective of someone who operates it with thirteen fintech companies in production.

The day the CNBV auditor asks to see the link

Almost all regulated Mexican fintech companies discover their connectivity issue on the same day: the day the National Banking and Securities Commission requests concrete operational evidence regarding the link that supports their platform. What it is asking for is the ability to reconstruct what happened on the link during a specific time window, who was operating it at that moment, how each incident was resolved, and why critical traffic to Banxico was or was not prioritized.

That’s where the gap lies. Because the model that’s usually underneath—contracted during the fintech’s first two years of operation, when the priority was to get the product up and running quickly—is a reseller. Someone who bought capacity from a large operator, repackaged it as a service under their own brand, and sold it with a PDF SLA. When the auditor asks to see telemetry, availability logs, incident tickets, and who handled each stage, the fintech realizes that a “99.9% SLA” on paper doesn’t answer a single one of the questions the regulator is asking.

What's Wrong with the Reseller Model?

The problem isn't that the reseller is malicious. It's structural. A reseller doesn't have its own backbone, so it doesn't have its own telemetry. Nor do they have engineers operating the nodes, so they lack the authority to reconstruct an incident without relying on the root operator. And their diagrams of your specific link are always incomplete, because your link is a shared portion of a generic service. When an audit requires traceability—which is essentially the ability to reconstruct what happened, when it happened, and why—the reseller cannot provide it because they never had it in the first place.

What is offered instead is the promise of an SLA. An SLA is a contractual clause. The clause states what should happen; the evidence shows what actually happened. The regulator cares about the latter.

What Changes When the Operator Owns the Backbone?

An operator that owns its own backbone operates under a different model. At Telecom District, all enterprise links run over our own EVPN infrastructure based on SRv6, which we’ve had in production since March 2025. That has two practical implications for a regulated fintech company.

First: All traffic that passes through our network generates telemetry that we manage ourselves. When an auditor requests an availability log for your specific link during a quarter, there’s no need to ask a third party for it. It’s in our systems, time-stamped, with no intermediaries, and can be reconstructed in detail.

Second: every incident is opened and closed by a Telecom District engineer who knows exactly which nodes are involved, which routing policy governs them, and which QoS applies. This is the natural consequence of the fact that the network is ours. When the fintech company needs to submit an incident post-mortem to the regulator, there is a post-mortem report available, with the root cause identified, corrective actions outlined, and signed by an identifiable engineer.

Kontrol Edge, our enterprise connectivity platform, is where all of this takes place. AI assists the human team: it detects patterns, cross-references signals, and suggests initial hypotheses. But the operational decision and the validation of the evidence remain the responsibility of the person. We’re clarifying this because there’s a lot of buzz in the market about “AI-operated networks.” Ours is operated by people, and that’s a design choice.

Thirteen Fintech Companies in Production: What Really Changes

Today, there are thirteen Mexican fintech companies operating under this model. We cannot disclose specific names or segments because the information is confidential. We can, however, describe the typical profile of these companies and the problems they typically address.

A typical fintech company has between 50 and 400 employees, is in active production, and has at least one critical integration with Banxico or a regulated financial services provider. These are operations that are already processing payments in production and are subject to audits.

The most common starting point is a connectivity overhaul that began because the previous setup failed a recent audit, or because an availability incident exposed the fragility of the reseller model. In both cases, the discussion begins at the boardroom table with the legal and risk departments, not just with the CIO.

What you gain by migrating is an enterprise-grade connection that is fully auditable, with its own telemetry, identifiable engineering, and reconstructible documentation for each segment. Incident response times measured in minutes, with no need for escalation between two companies. And a direct business relationship, with no intermediaries separating you from the operator that actually carries your traffic.

What Really Matters in the Regulatory Review

The CNBV and Banxico review the connectivity of fintech institutions based on criteria that evolve with each cycle. Without going into specific details—which depend on the nature of the fintech company, the type of services it provides, and the scope of the review—there are three areas that consistently come up.

Operational continuity. It is not enough to have a redundant link; you must be able to demonstrate that the redundancy is functioning. An in-house backbone with active alternate paths and logged switching provides that evidence. A reseller model can rarely provide this without relying on the goodwill of the root operator.

Traceability of critical traffic. Traffic flows to Banxico, to payment processors, and to core integrations must be identifiable, prioritizable, and auditable. A model with true QoS, enforced by the operator that owns the backbone, addresses this by design.

Documentation and evidence upon request. The regulator may request operational evidence covering specific time periods and at a specific level of detail. The only response that stands up to scrutiny is “here it is.” That “here it is ” comes from an operator who runs its own network and has authority over the data that describes it.

If you're the CIO or CFO of a regulated fintech company, how do you begin to evaluate

You don't have to complete the migration on day one. You need to start asking yourself the right questions before the next review.

  • Can your current provider give you a timestamped availability log for your specific link, directly from the source, within 48 hours?
  • Does your current provider assign engineers with first and last names to your account, or do you always have to go through a rotating support team?
  • Do the post-mortems for your last three incidents include the identified root cause, or just the restoration of service?
  • Does your critical link to Banxico or your payment processor have QoS applied at the backbone level, or does it depend on the network not being congested?

If any of those answers make you uncomfortable, the problem lies with the model.

Where does Telecom District fit into this?

At Telecom District, we do a specific type of work: enterprise connectivity for audited institutions, using a specific model that includes our own network, traceable engineering, and verifiable evidence. The thirteen fintech companies currently in production came to us after an audit or an incident, when they realized that paperwork is no substitute for a human operator.

Eduardo Martino, COO of Telecom District

Eduardo Martino is the COO of Telecom District. He oversees the company's commercial and regulatory operations, as well as its enterprise projects in Latin America.

See how a network is operated on its own backbone

The layer on which the thirteen fintech companies in production operate: proprietary telemetry, traceable engineering, and reconstructible evidence for each stage.