ValiDeck is building a privacy-first transaction data infrastructure for loyalty and payments, based on the line-item purchase data that sits behind every transaction. That data is valuable to merchants, customers, and regulators alike, but using it has always meant storing personal identifiers alongside it. Every stored identifier introduces a liability — a breach to disclose, a regulator to answer to, a consent to maintain. Our architecture, specified as the PCX protocol, ties each transaction record to a token instead of to a person. The data stays useful for analytics, audit, and controlled data-sharing purposes, while the liability that normally travels with it is reduced by design.
This page is intended for engineers and specialists who wish to be contacted when funded roles formally open. We are currently collecting expressions of interest only. Formal hiring will begin after Phase I funding is secured.
ValiDeck’s Phase I is a 24-month execution program. The prototype build runs from month 1 to month 18. Integration engineering begins at month 12 and overlaps the closing stretch of that build, so connector and SDK work is underway before the prototype is finished. In the final six months (months 18 to 24), the program converts the prototype into integration readiness through architectural hardening, privacy auditing, early partner engagement, and pre-integration work with PoS vendors.
The objective of phase I is to demonstrate — with working software and audit evidence — that pseudonymized, tokenized customer transaction records can be captured, linked, and analyzed across merchants without storing card numbers or personal identity, while remaining compliant with applicable data-protection regimes including PIPEDA and GDPR. It is not a public launch and does not use commercial customer data. The program exits as a pre-MVP integration platform awaiting capital to connect to live rails.
The work suits engineers and specialists who want to build privacy-preserving infrastructure from first principles, including secure transaction workflows, controlled analytics, cryptographic safeguards, and auditable system behavior.
Most early-stage engineering starts with an unsettled architecture and discovers the design while building it. Phase I is the opposite case. The core token pipeline is protected by a granted patent family in the United States, Australia, and India, with national-phase prosecution continuing in Canada, Europe, and China, and the Phase I design is complete before the first line of code. The engineering task is to convert that legal and architectural position into practical assets: tested reference components, documented responsibilities, independent evidence, and partner knowledge. That is unusual work at any career stage, and the skills involved transfer directly to any regulated data environment.
While the initial focus is delivering the prototype, our objective is also to identify and retain the core technical leadership that carries into the next funded phase and the commercial pilot integrations after it. ValiDeck remains the reference implementation of PCX rather than its governing body, so the knowledge built here is knowledge of a protocol intended for others to implement.
We expect to draw on senior engineers anchored in the Waterloo and Toronto corridor, the University of Waterloo co-op and new-graduate pipeline through our Communitech and IPON relationships, and an academic research partnership for the specialized trusted-execution work.
These roles are planned for the Phase I feasibility build and will open only after funding is secured. Durations are the currently planned engagement windows and may be re-baselined for the selected jurisdiction.
Owns end-to-end technical delivery of the feasibility prototype, including microservice architecture, PoS simulation, card-issuer token integration, pseudonymized ledger services, analytics modules, API design, datastore modeling, token lifecycle enforcement, and system observability. This role sets the technical direction for Phase I and provides continuity into the pre-MVP bridge.
Implements core backend services including token issuance, the interface to the separately deployed token-resolving service, pseudonymized ledger write paths, authorization flows, API endpoints, and validation tests. Works closely with the full-stack lead to deliver stable, auditable services aligned with privacy-by-design and R&D documentation requirements.
Designs pseudonymized aggregation logic, enforces re-identification thresholds, implements access-controlled analytics, and validates privacy guarantees at defined build milestones.
Responsible for secure infrastructure setup, deployment pipelines, observability, reliability, and environment hardening for the feasibility build.
Delivers the SDK-level integration blueprint and a reference connector demonstrating standardized CTR ingestion and token linkage for one target PoS or commerce ecosystem, together with the architectural hardening that external integration requires: boundary contracts and observability. The goal is provider-level technical enablement, so that a single integration reaches many merchants; commercial activation and merchant onboarding remain separate.
Builds the test coverage that the reference implementation has to survive to be independently reviewable: conformance tests for the CTR schema across representative transaction formats, token lifecycle and negative-access cases, aggregation and suppression thresholds, integrity-proof and audit-log verification, and failure handling at the integration boundary. Scope is set at the start of the integration phase.
Focused engagement covering cryptographic design validation, key management, enclave usage, integrity proofs, and security review of token and pseudonymization flows. Scoped as a fractional senior engagement or an academic research partnership across an eleven-month window rather than a full-time hire.
Designs operator-facing and analyst-facing interfaces required to demonstrate feasibility, auditability, and controlled data access.
Independent review validating applicable data-protection posture, audit logs, attestation artifacts, and compliance documentation prior to investor and regulator disclosure. Engaged twice, at design stage and at the close of the program.
Project management, R&D and SR&ED documentation, and regulatory liaison will be performed directly by the founder throughout Phase I.
Because we are presently at the expression-of-interest stage, detailed salary, contract, and equity discussions will begin only after funded roles formally open.
For the small number of long-tenure core hires, compensation blends below-market cash with equity participation, allocated by role and tied to scope, execution responsibility, and commitment. Short specialist engagements use cash plus milestone-completion bonuses, where standard option vesting would not apply. Core equity-bearing roles are engaged as employees; short specialist roles are retained as independent contractors.
On the Canadian path, options on the company’s shares carry CCPC tax treatment that improves after-tax value relative to comparable early-stage equity in the United States. Option terms are structured in consultation with Canadian tax counsel, and candidates should obtain their own legal and tax advice.
Phase I may be executed in Canada or in Germany and the wider EU, depending on funding source and institutional alignment. Canadian execution is Waterloo-based and prioritizes SR&ED eligibility; German or EU execution prioritizes institutional co-funding, regulatory proximity, and EU research alignment.
Roles may be filled by Canada-based or Germany and EU-based contributors. ValiDeck expects Phase I to operate as a focused, distributed technical build, with compliant onboarding appropriate to the selected jurisdiction and funding structure.
If you wish to be notified when these roles open, send a short introduction, not a CV, to alok.narula@valideck.com with the subject line “Phase I: Expression of Interest.”
In your note, please briefly include your area of specialization, relevant systems or products you have helped build, your current location, and links to GitHub, LinkedIn, portfolio work, or other relevant material, if available.
What you send is used only to assess potential fit and to contact you about funded Phase I roles. Access is limited to people involved in recruitment, and information is retained only as long as reasonably needed for that purpose and for applicable obligations.
You may request correction or deletion by emailing the address above, subject to any required retention. Please do not send government identifiers or financial information.