A 14-layer, real-time defense scores every checkout and every merchant — ~140 data points collected at the browser, hardened at the Cloudflare edge, and enforced before a single cent moves.
Every node below is a real signal we score — 131 across the commerce platform plus the Cloudflare & gateway edge, clustered into 14 layers. Drift through them, click any point to see what it catches, or tap a layer to isolate its cluster.
The map holds ~140 of the live anti-fraud, risk and KYC signals scored on every Inkress checkout and merchant. Colors group them into the 14 defense layers.
A signal is collected at the browser, stamped at the Cloudflare edge, scored by the risk engine and enforced at the money gate — every checkout, in real time.
~22 device & behavioral signals
Turnstile · bot score · WAF · trusted IP
JA4 · geo/ASN · scanner detect · rate-limit
~91 signals → score 0–100
deny · step-up · allow
limits · KYC gate · strict Y+CAVV
No single signal decides anything. Defenses stack — network, device, identity, card, money — so a fraudster has to beat all of them at once. Expand any layer to see exactly what's inside.
Every merchant climbs a five-tier identity ladder. Each rung unlocks higher limits — and demands stronger proof. A merchant can never move more money than they've proven they should.
Cards are sealed end-to-end (ECDH + AES-256-GCM), hashed for fraud signals — never stored as a PAN — and forced through a visible 3-D Secure challenge. Only a fully authenticated card can take money.
PowerTranz returns an authentication status. We accept exactly one outcome — and reject the rest, fail-closed, on the server.
Before a request ever reaches us, Cloudflare absorbs the attack and stamps trusted, hard-to-forge signals on it. Our risk engine treats them as ground truth — only when they arrive from the verified terminator.
The only step-up challenge. A step_up verdict only clears once Turnstile verifies — no puzzles, no tracking.
cf-bot-score 1–2 hard-deny, cf-verified-bot +30, plus cf-botmgmt-ja4 TLS fingerprint.
L3/4 + L7 attack absorption and managed rules in front of every origin.
The entire card environment (CDE) runs as a Worker; KV stores single-use nonces for anti-replay.
cf-connecting-ip — the real client IP — plus cf-ipcountry for geo-consistency.
Total TLS termination — and where the JA4 fingerprint is derived.
The defense isn't a marketing layer — it's anchored in payment-industry standards and real cryptography, end to end.
Cards are sealed at the edge and tokenized; the raw PAN never touches our application database.
Full 3DS2 with a fail-closed strength gate — frictionless device flow and visible challenge, liability-shifted.
Card data travels in an ephemeral ECDH-sealed envelope; tokens are encrypted at rest with per-record keys.
A data-driven J$1M legal tripwire plus structuring detection that flags transactions clustered just under it.
Every inter-service call is HMAC-signed and nonce-protected, with single-use idempotency to stop double-charges.
The payment audit ledger is append-only and hash-chained — every row cryptographically links to the last.
One signal rarely stops anything. But stacked, they're lethal. Here's a real card-testing bot meeting the defense — and losing, in milliseconds.
Headless automation is flagged before the request even reaches our origin.
cf-bot-score → +40 riskThe "browser" is driving itself — no human ever touched it.
BOT_SUSPECTED → +80 riskA textbook card-testing burst from one device and IP.
card-testing lockout · 10 minSynthetic identities fanned across stolen numbers.
CARD_MANY_NAMES → denyIndependent layers all converge on the same verdict.
hardDenyStopped in 43 ms, before a single authorization. The card, device, IP and JA4 are now on the fast-path blocklist — the next attempt never even reaches a decision.
The defense assumes the client is hostile, the network is watched, and the attacker is patient. Every design choice follows from that.
When a check can't run, the safe answer wins. The 3DS gate, the card gate and the KYC gate all deny on doubt — security over convenience.
Amounts, decisions and 3DS results are signed and resolved server-side. A tampered client can't pick what it pays or fake an "approved".
Cards live in a separate Cloudflare-Worker environment. The application never sees a PAN — only an opaque, encrypted reference it can't reverse.
Decisions, nonces and checkout intents are one-shot and time-boxed. Replay a captured "allow" and it's already burned — 409, not a charge.
The payment ledger is append-only and hash-chained. Mutate one row and the chain breaks — the audit trail can't be quietly rewritten.
Every confirmed fraud auto-adds its email, card, device, IP and JA4 to a fast-path blocklist. The attacker's whole toolkit dies after one use.
The same 14-layer defense runs on every Inkress transaction today — quietly, in real time, before a single cent can move.