AI Fraud Detection Pipeline
A coordinated warm-path pipeline ingests transactions via REST API, runs them through sequential AI scoring agents, and returns a risk score and action in real time.
- Configurable fraud rule signals per transaction
- Watchlist matching — IP, device, email, domain
- High-risk country and velocity anomaly detection
- Risk scores 0.0–1.0 with CLEAR / FLAG / BLOCK outcomes
- Explainable AI: every flag includes signal breakdown
Case Management
A full investigative workflow covering every stage from alert triage to case close. Investigators document findings, attach evidence, write notes, and record a resolution outcome — all captured in an immutable case timeline.
- Status state machine: open → investigating → escalated → resolved
- Evidence attachments and investigation notes
- Immutable case timeline (append-only events)
- Resolution outcomes: true positive, false positive, inconclusive
- Assignee tracking with role-based access
Real-Time Threat Alerts
Every BLOCK or FLAG decision by the fraud pipeline creates a structured alert with severity routing. Investigators receive alerts via WebSocket push, can acknowledge, resolve, or escalate them, and create investigation cases with one click.
- Alert severity levels: low, medium, high, critical
- WebSocket real-time push to connected sessions
- Acknowledge, resolve, and escalate workflows
- One-click case creation from any alert
- Webhook delivery to external endpoints
Audit Trail & Compliance
Every platform action — login, role change, case update, rule edit, API key creation — is appended to a tamper-evident, hash-chained audit log. Nightly chain integrity verification detects any tampering. Full logs are exportable for compliance review.
- Hash-chained audit log (SHA-256 forward linking)
- Scheduled nightly chain integrity verification
- Per-org audit trail isolation
- Filterable by actor, action type, and time range
- CSV export for regulatory or legal review
REST API & Developer Docs
A full REST API with OpenAPI 3.1 specification, interactive Swagger explorer, and Bearer token authentication. Ingest transactions, query cases and alerts, and manage org settings programmatically from any stack.
- OpenAPI 3.1 spec — importable into any API client
- Bearer token auth via org-scoped API keys
- POST /api/transactions/ingest — score a transaction
- GET /api/cases, /api/alerts, /api/admin/* — full resource access
- Swagger UI explorer available at /api-docs/swagger
Enterprise Security & Multi-Tenancy
Strict org-level data isolation, a 5-role RBAC model enforced at every API endpoint, mandatory TOTP MFA for all users, idle-timeout session management, and AES-256 encryption for all stored secrets.
- 5 roles: super_admin, org_admin, investigator, analyst, viewer
- Mandatory TOTP MFA with 10 bcrypt-hashed backup codes
- 15-minute idle timeout, 8-hour absolute session limit
- AES-256-GCM encrypted MFA secrets at rest
- Per-org feature flags, fraud rules, and watchlists
Also included
Additional platform capabilities at no extra cost.
Bulk Transaction Import
Upload transaction batches in a single CSV. Each row is scored by the full pipeline and returned with a per-row risk decision.
User & Org Management
Invite users by email, set roles, enable or disable accounts, and manage multiple organizations from a single super-admin account.
Scam Report Intake
A public /report-scam form lets anyone submit fraud tip-offs. Reports are queued for investigator review and linked to existing watchlist entries.