Ebor Labs

Records that hold up when somebody checks.

Ebor Labs builds assessment, certification and data-readiness tools for regulated businesses — mostly financial institutions in the Gulf, and the training providers who serve them.

What goes in, and what comes back out

A room of bank staff sitting a compliance paper

Certificates an auditor can verify by scanning the code on them

A customer master file exported from an accounting system

Clean records, and a list of the ones a person needs to decide about

A trainer asking how the cohort actually did

Weak on sanctions screening — not weak on question seven

Two things, both running today

Neither is a demo. Both are live, in use, and built for the specific paperwork a regulator asks for rather than for a general market.

Assessment platform

exam.eborlabs.com

Candidates sit compliance papers, trainers run the room, certificates issue themselves. Built for training providers who have to prove to a regulator that a named person passed a named course on a named date.

  • Marking happens on the server, so the answer key never reaches the candidate's browser
  • Every certificate carries a QR code that verifies against the record
  • Pre-tests measure what the training actually moved
  • Reporting by subject, so you can say which topic a cohort struggled with
  • Renewal reminders before a certificate lapses
  • Arabic throughout, and extra time for People of Determination

E-invoicing data check

einvoicecheck.eborlabs.com

Tools for UAE businesses getting their customer data in order before connecting to an accredited service provider under the Ministry of Finance e-invoicing programme.

  • Reads exports from fourteen common accounting systems
  • Corrects what has one right answer — spacing, labels, country codes
  • Sends anything needing judgement to an exception list instead of guessing
  • Checks invoice files against the UBL and PINT AE formats
  • Runs entirely in your browser; nothing is uploaded anywhere

How it's built

These are properties of the systems, not promises in a brochure. They are the reasons a compliance team can put their staff's records into them.

An identity provider says who someone is, never what they may do

Signing in with a work account proves an email address. It does not grant access. An unrecognised trainer becomes a request somebody has to approve — never an account.

A submitted assessment cannot be re-marked

Enforced in the application and again by the database itself. A record of what happened stays a record of what happened.

Deleting a record needs two people

One person asks, another approves, and the request is logged either way. Nothing quietly disappears.

Separation between clients is a permission, not a naming convention

One organisation cannot reach another's records, because the check happens on the server against the signed-in session — not because the keys happen to look different.

Candidate data stays in the United Kingdom

Records are held in London. Email is sent from Ireland. Both are named in writing, because a client's compliance team will ask.

Every change is tested before it ships

An automated suite runs against the platform before any release, and every fixed bug gains a permanent test so it cannot come back unnoticed.


Talk to a person

Ebor Labs is Mohammad Ibrahim — an engineer in York, building tools for an industry that has to be able to prove things. If you have a compliance process held together by spreadsheets and goodwill, that is usually where the interesting work is.

ibrahim@eborlabs.com