Inkress · Real-time fraud, risk & KYC

0 signals
between a fraudster
and your money.

A 14-layer, real-time defense scores every checkout and every merchant — ~140 data points collected at the browser, hardened at the Cloudflare edge, and enforced before a single cent moves.

0Data points
0Defense layers
0Pipeline stages
<100msEdge decision
AES-256 · ENCRYPTED
SCROLL
The signal map

0 data points. One verdict.

Every node below is a real signal we score — 131 across the commerce platform plus the Cloudflare & gateway edge, clustered into 14 layers. Drift through them, click any point to see what it catches, or tap a layer to isolate its cluster.

● click a node · hover to inspect
0live signals mapped
Selected signal

Pick a point →

Click any node, or a layer chip

The map holds ~140 of the live anti-fraud, risk and KYC signals scored on every Inkress checkout and merchant. Colors group them into the 14 defense layers.

The pipeline

Six stages. Milliseconds. No blind spots.

A signal is collected at the browser, stamped at the Cloudflare edge, scored by the risk engine and enforced at the money gate — every checkout, in real time.

01

Browser

~22 device & behavioral signals

02

Cloudflare edge

Turnstile · bot score · WAF · trusted IP

03

Gateway

JA4 · geo/ASN · scanner detect · rate-limit

04

Risk engine

~91 signals → score 0–100

05

Decision

deny · step-up · allow

06

Money gate & 3DS

limits · KYC gate · strict Y+CAVV

enforced before a single cent moves
Defense in depth

Fourteen layers, each a wall.

No single signal decides anything. Defenses stack — network, device, identity, card, money — so a fraudster has to beat all of them at once. Expand any layer to see exactly what's inside.

Tiered KYC · L0–L4

Trust is earned in tiers.

Every merchant climbs a five-tier identity ladder. Each rung unlocks higher limits — and demands stronger proof. A merchant can never move more money than they've proven they should.

L0
LEVEL 0
J$100K
/ mo · onboarding
Account created
L1
LEVEL 1
J$500K
/ mo
Verified emailVerified phone (HLR)
L2
LEVEL 2
J$3M
/ mo · identity
Liveness checkGovernment IDSelfie + face match
L3
LEVEL 3
J$15M
/ mo · verified business
Proof of addressBank ownershipFour-eyes review
L4
LEVEL 4
J$150M
/ mo · enhanced due diligence
Business registrationSource of fundsSanctions / PEP screen
Card & 3-D Secure

The card never leaves a vault.

Cards are sealed end-to-end (ECDH + AES-256-GCM), hashed for fraud signals — never stored as a PAN — and forced through a visible 3-D Secure challenge. Only a fully authenticated card can take money.

INKRESS
4242  ••••  ••••  4242
VALID THRU  12/29SEALED · AES-256-GCM
•••
PAN HMAC · never the card number
Strict authentication gate

Only Y + CAVV moves money.

PowerTranz returns an authentication status. We accept exactly one outcome — and reject the rest, fail-closed, on the server.

✓Y + CAVVauthenticated → settles
✕A · attemptedno liability shift → rejected
✕U · unablerejected
✕N / R · failedrejected
Forced challenge on the raw PAN · ChallengeIndicator 04

The Cloudflare edge

Before a request ever reaches us, Cloudflare absorbs the attack and stamps trusted, hard-to-forge signals on it. Our risk engine treats them as ground truth — only when they arrive from the verified terminator.

Turnstile

The only step-up challenge. A step_up verdict only clears once Turnstile verifies — no puzzles, no tracking.

Bot Management

cf-bot-score 1–2 hard-deny, cf-verified-bot +30, plus cf-botmgmt-ja4 TLS fingerprint.

WAF · DDoS

L3/4 + L7 attack absorption and managed rules in front of every origin.

Workers + KV

The entire card environment (CDE) runs as a Worker; KV stores single-use nonces for anti-replay.

Trusted IP & geo

cf-connecting-ip — the real client IP — plus cf-ipcountry for geo-consistency.

Managed TLS

Total TLS termination — and where the JA4 fingerprint is derived.

Compliance & cryptography

Built to the standard, not the demo.

The defense isn't a marketing layer — it's anchored in payment-industry standards and real cryptography, end to end.

PCI-aligned card handling

CDE · NO PAN AT REST

Cards are sealed at the edge and tokenized; the raw PAN never touches our application database.

EMVCo 3-D Secure 2

STRICT Y+CAVV

Full 3DS2 with a fail-closed strength gate — frictionless device flow and visible challenge, liability-shifted.

AES-256-GCM + ECDH

SEALED ENVELOPE

Card data travels in an ephemeral ECDH-sealed envelope; tokens are encrypted at rest with per-record keys.

POCA AML controls

TRIPWIRE · STRUCTURING

A data-driven J$1M legal tripwire plus structuring detection that flags transactions clustered just under it.

HMAC-signed APIs

ts.nonce.method.path

Every inter-service call is HMAC-signed and nonce-protected, with single-use idempotency to stop double-charges.

Hash-chained ledger

TAMPER-EVIDENT

The payment audit ledger is append-only and hash-chained — every row cryptographically links to the last.

Watch one die

A fraud attempt, layer by layer.

One signal rarely stops anything. But stacked, they're lethal. Here's a real card-testing bot meeting the defense — and losing, in milliseconds.

⚠ Incoming

A card-testing bot hits a merchant checkout with a stolen BIN range.

01
Cloudflare edge

Bot score: 2 / 99

Headless automation is flagged before the request even reaches our origin.

cf-bot-score → +40 risk
02
Device intelligence

Webdriver + headless

The "browser" is driving itself — no human ever touched it.

BOT_SUSPECTED → +80 risk
03
Velocity

9 cards in 41 seconds

A textbook card-testing burst from one device and IP.

card-testing lockout · 10 min
04
Card identity

5 cardholder names across 9 cards

Synthetic identities fanned across stolen numbers.

CARD_MANY_NAMES → deny
05
Decision

Risk score 100 / 100

Independent layers all converge on the same verdict.

hardDeny
✕  BLOCKED

Stopped in 43 ms, before a single authorization. The card, device, IP and JA4 are now on the fast-path blocklist — the next attempt never even reaches a decision.

Security architecture

Engineered for adversaries.

The defense assumes the client is hostile, the network is watched, and the attacker is patient. Every design choice follows from that.

Fail-closed by default

When a check can't run, the safe answer wins. The 3DS gate, the card gate and the KYC gate all deny on doubt — security over convenience.

The browser is never trusted

Amounts, decisions and 3DS results are signed and resolved server-side. A tampered client can't pick what it pays or fake an "approved".

Isolated card vault

Cards live in a separate Cloudflare-Worker environment. The application never sees a PAN — only an opaque, encrypted reference it can't reverse.

Single-use everything

Decisions, nonces and checkout intents are one-shot and time-boxed. Replay a captured "allow" and it's already burned — 409, not a charge.

Tamper-evident ledger

The payment ledger is append-only and hash-chained. Mutate one row and the chain breaks — the audit trail can't be quietly rewritten.

Defense that learns

Every confirmed fraud auto-adds its email, card, device, IP and JA4 to a fast-path blocklist. The attacker's whole toolkit dies after one use.

0
Signals scored
0
Defense layers
0
Services in concert
<100ms
To a verdict
🔒

Fraud doesn't get a second chance.

The same 14-layer defense runs on every Inkress transaction today — quietly, in real time, before a single cent can move.