Platform Services

Everything shipped. Nothing promised.

Every feature listed below is live in the platform today. No roadmap items, no beta flags — if it's on this page, you can open it right now.

Detection

AI Fraud Detection Pipeline

A coordinated warm-path pipeline ingests transactions via REST API, runs them through sequential AI scoring agents, and returns a risk score and action in real time.

  • Configurable fraud rule signals per transaction
  • Watchlist matching — IP, device, email, domain
  • High-risk country and velocity anomaly detection
  • Risk scores 0.0–1.0 with CLEAR / FLAG / BLOCK outcomes
  • Explainable AI: every flag includes signal breakdown
Investigation

Case Management

A full investigative workflow covering every stage from alert triage to case close. Investigators document findings, attach evidence, write notes, and record a resolution outcome — all captured in an immutable case timeline.

  • Status state machine: open → investigating → escalated → resolved
  • Evidence attachments and investigation notes
  • Immutable case timeline (append-only events)
  • Resolution outcomes: true positive, false positive, inconclusive
  • Assignee tracking with role-based access
Monitoring

Real-Time Threat Alerts

Every BLOCK or FLAG decision by the fraud pipeline creates a structured alert with severity routing. Investigators receive alerts via WebSocket push, can acknowledge, resolve, or escalate them, and create investigation cases with one click.

  • Alert severity levels: low, medium, high, critical
  • WebSocket real-time push to connected sessions
  • Acknowledge, resolve, and escalate workflows
  • One-click case creation from any alert
  • Webhook delivery to external endpoints
Compliance

Audit Trail & Compliance

Every platform action — login, role change, case update, rule edit, API key creation — is appended to a tamper-evident, hash-chained audit log. Nightly chain integrity verification detects any tampering. Full logs are exportable for compliance review.

  • Hash-chained audit log (SHA-256 forward linking)
  • Scheduled nightly chain integrity verification
  • Per-org audit trail isolation
  • Filterable by actor, action type, and time range
  • CSV export for regulatory or legal review
Integration

REST API & Developer Docs

A full REST API with OpenAPI 3.1 specification, interactive Swagger explorer, and Bearer token authentication. Ingest transactions, query cases and alerts, and manage org settings programmatically from any stack.

  • OpenAPI 3.1 spec — importable into any API client
  • Bearer token auth via org-scoped API keys
  • POST /api/transactions/ingest — score a transaction
  • GET /api/cases, /api/alerts, /api/admin/* — full resource access
  • Swagger UI explorer available at /api-docs/swagger
Security

Enterprise Security & Multi-Tenancy

Strict org-level data isolation, a 5-role RBAC model enforced at every API endpoint, mandatory TOTP MFA for all users, idle-timeout session management, and AES-256 encryption for all stored secrets.

  • 5 roles: super_admin, org_admin, investigator, analyst, viewer
  • Mandatory TOTP MFA with 10 bcrypt-hashed backup codes
  • 15-minute idle timeout, 8-hour absolute session limit
  • AES-256-GCM encrypted MFA secrets at rest
  • Per-org feature flags, fraud rules, and watchlists

Also included

Additional platform capabilities at no extra cost.

Bulk Transaction Import

Upload transaction batches in a single CSV. Each row is scored by the full pipeline and returned with a per-row risk decision.

User & Org Management

Invite users by email, set roles, enable or disable accounts, and manage multiple organizations from a single super-admin account.

Scam Report Intake

A public /report-scam form lets anyone submit fraud tip-offs. Reports are queued for investigator review and linked to existing watchlist entries.

Ready to see it in action?

All six services are live. Create a free account or request a guided demo.