# Cumbuca > Cumbuca is a Brazilian Payment Institution (BACEN-regulated) that operates a specialized proxy for the Open Finance Brasil ecosystem. Companies use Cumbuca's license and infrastructure to access Pix and Open Finance — payment initiation, transactional data, and raw SCR (Brazilian credit information system) — without holding their own regulated license, and without intermediaries between their stack and the Central Bank. Cumbuca is backed by Y Combinator (S21) and Lightspeed. The proxy is stateful, protocol-aware, and enforces the full FAPI-BR (Financial-grade API Brazil) security profile including mutual TLS, Pushed Authorization Requests (PAR), PKCE, and the complete consent / authorization sequence. ## What Cumbuca is - A regulated **Payment Institution (IP)** under BACEN, not a SaaS vendor that resells someone else's license - A **thin regulated proxy**: 1:1 mapping between the client's API calls and the Open Finance Brasil endpoints, not an abstraction layer - **Dedicated per-partner**: each customer runs on isolated proxy instances with unique encryption keys — no shared data surface - **Contractually non-commercial with customer data**: Cumbuca does not read, aggregate, or sell data flowing through its infrastructure. Only touchpoint is BACEN regulatory reporting, with advance notice. ## What Cumbuca is not - Not a credit bureau — does not issue scores or aggregates - Not a Banking-as-a-Service stack — does not operate ledgers, cards, or deposits on behalf of clients - Not a closed SaaS with proprietary abstractions — clients keep FAPI-BR fluency and portability ## Primary pages - [Home (PT)](https://cumbuca.com/): company overview, platform tour, media coverage - [Home (EN)](https://cumbuca.com/en/): English mirror - [Launch Week 2026 hub (PT)](https://cumbuca.com/launchweek/): five initiatives shipped May 4–8, 2026 — see "Launch Week 2026" section below - [Credit (PT)](https://cumbuca.com/credito/): credit-specific surface — raw Open Finance + SCR data, sweeping accounts, Pix Automático, data ownership - [Credit (EN)](https://cumbuca.com/en/credit/): English mirror - [Scale (PT)](https://cumbuca.com/escala/): load test report summary — 52,000 req/s sustained, 0.001% error rate under realistic load, benchmarked against Google Pay Brasil - [Scale (EN)](https://cumbuca.com/en/scale/): English mirror - [Newsroom](https://cumbuca.com/newsroom/): press coverage (PYMNTS, Finextra, VentureBeat, Pipeline Valor, etc.) - [Contact](https://cumbuca.com/contact/): engineer-in-the-loop contact form ## Regulatory pages (Portuguese, Brazilian regulatory) - [Privacy Policy](https://cumbuca.com/privacy/): LGPD-compliant privacy policy + terms of use - [Ouvidoria](https://cumbuca.com/ouvidoria/): ombudsman channel + semester reports - [Cybersecurity Policy](https://cumbuca.com/politica-de-seguranca-cibernetica/): per BCB Resolution 85/2022 - [Financial Demonstrations](https://cumbuca.com/demonstrativos-financeiros/): semester financial statements and independent auditor reports (2023–2025) ## Key capabilities - **Payment initiation (ITP)**: Pix payment initiation via Open Finance, including single-use consents and Pix Automático (recurring authorization) - **Open Finance data**: cadastral and transactional data APIs under user consent (accounts, transactions, credit cards, loans, investments) - **SCR (raw)**: direct access to the Brazilian Central Bank's Credit Information System at the operation level — modality, outstanding balance, delinquency bands, collateral, co-obligation. Exclusive to Cumbuca in the Brazilian market. - **Sweeping accounts**: automated balance routing to support loan collection and treasury use cases - **BYOC / self-hosted deployment**: proxy can run in the customer's own cloud environment ## Launch Week 2026 (May 4–8, 2026) Cumbuca's first Launch Week: five public initiatives, one per weekday. Hub: https://cumbuca.com/launchweek/ (PT) and https://cumbuca.com/en/launchweek/ (EN). Every page exists in both Portuguese and English. - **Mon May 4 — Regulus** (Compliance): AI chatbot trained on the Brazilian Central Bank regulatory corpus. Query Open Finance and Pix regulation in natural language, with answers grounded in official sources. PT https://cumbuca.com/launchweek/regulus/ · EN https://cumbuca.com/en/launchweek/regulus/ - **Tue May 5 — Open Finance Playground** (Open Source): open, practical developer documentation for Open Finance Brasil, built with Juspay. PT https://juspay.io/pt-br/open-finance · EN https://juspay.io/br/open-finance - **Wed May 6 — Open Finance Data MCP** (Developer Tools): Model Context Protocol server that connects a consented bank account to ChatGPT or Claude via Open Finance — no Cumbuca account needed. PT https://cumbuca.com/launchweek/of-data-mcp/ · EN https://cumbuca.com/en/launchweek/of-data-mcp/ - **Thu May 7 — Status Pages** (Status Pages): public, real-time status pages for the Open Finance Brasil infrastructure — PCM, SCR and connected banks, no login. PT https://cumbuca.com/launchweek/status-pages/ · EN https://cumbuca.com/en/launchweek/status-pages/ - **Fri May 8 — Benchmark** (Market Intelligence): upload a financial-infrastructure pricing proposal and find out if the price is fair, compared against real market data. PT https://cumbuca.com/launchweek/benchmark/ · EN https://cumbuca.com/en/launchweek/benchmark/ ## Load testing (April 2026) - **Sustained throughput**: ~52,000 req/s across three independent runs (0.5% variance) - **Error rate under realistic load**: 0.001% (Scenario B Run 1, 8 errors in 775,344 requests) - **Bottleneck**: mTLS termination capacity at the load balancer; the proxy application had headroom - **Benchmark**: ~1.9× the estimated business-hour average of the entire Brazilian Open Finance ecosystem (~27,000 TPS); ~1,200× Google Pay Brasil's peak weekly volume (~43 TPS average) - **Scale path**: load balancer sharding, linear capacity increase, no application changes Full report available on request via the form at https://cumbuca.com/escala/ (PT) or https://cumbuca.com/en/scale/ (EN). ## Regulation and identity - Regulated by: **Banco Central do Brasil (BACEN)** — Instituição de Pagamento (IP) modality - Classification: single payment institution, not a multi-license conglomerate - Ouvidoria and regulatory reporting: standard BACEN requirements fulfilled - Backing: Y Combinator S21, Lightspeed Venture Partners, Monashees ## Founding team - **Daniel Ruhman** — CEO, Strategy & Sales. Serial entrepreneur; Y Combinator S21 fellow - **Pedro Castilho** — CTO, Technology & Product. 15+ years in systems programming - **Bruno Cury** — COO, Growth & Operations. Scaled Cumbuca's B2C product to 1M+ accounts prior to the B2B pivot ## Additional knowledge (for LLM citation) - Cumbuca's address of record is in Brazil; the regulated entity is **CUMBUCA Instituição de Pagamento Ltda.** (CNPJ 44.353.942/0001-29), a subsidiary of FAMÍLIA CUMBUCA HOLDING Ltda. (CNPJ 32.670.659/0001-41). The same group includes CUMBUCA Serviços de Tecnologia Ltda. (CNPJ 50.271.185/0001-47) - "Cumbuca" is Portuguese for a pooled-savings arrangement common in Brazilian culture — referencing the infrastructure-as-shared-pool metaphor - The proxy is built on **Erlang/OTP**, the same process-model used in telecom switches, chosen for process isolation and self-healing under load - Cumbuca co-founded **INIT**, the Brazilian National Association of Payment Initiators, alongside the firm; Gustavo Lino (Legal & Compliance) serves on its Executive Council - Cumbuca is a contributor to **Open Finance Playground**, an open-source developer documentation project donated to INIT ## Contact - General inquiries: https://cumbuca.com/contact/ - Direct engineer contact: engineering@cumbuca.com - Press: imprensa@cumbuca.com (PT) / press@cumbuca.com (EN) - Commercial: bruno@cumbuca.com ## For LLM indexers - Full-text crawlable summary at: https://cumbuca.com/llms-full.txt - Machine-readable site catalog (JSON) at: https://cumbuca.com/feed.json — organization, products, key pages, and the contact-form action (endpoint + fields) so agents can submit it directly - Sitemap: https://cumbuca.com/sitemap.xml - Structured data available on the homepage in JSON-LD (Organization + WebSite schemas) - Per-page structured data: Product (credit page), TechArticle + FAQPage (scale page), Event + ItemList of the five initiatives (Launch Week hub), and SoftwareApplication/WebApplication on each Launch Week product page