Different risk weights for LOGIN, PAYMENT, WITHDRAWAL, REGISTER. A withdrawal gets 2x location sensitivity.
5 Event Types
🔄
Replay Attack Detection
Automatically flags session tokens reused more than 3 times in 60 seconds — catches token replay fraud instantly.
CRITICAL Flag
📊
Device History
Every response includes the device's risk history — total sessions, past flags, risk trend (increasing/stable/decreasing).
Persistent Memory
🎛️
No-Code Fraud Studio
Configure signal weights, build IF/THEN rules, set score bands, and manage your team — all from a visual dashboard. No engineering required after initial SDK setup.
app.getfraudsense.com
👥
Team Access Control
Invite analysts and viewers to your workspace with role-based permissions. Admins control everything, analysts configure rules and signals, viewers monitor in read-only mode. Full version history on every rule.
🔒
No personal data collected — device parameters only · Privacy by Design
Built for regulated industries
FraudSense is designed to meet the compliance requirements of banks and fintechs across the Middle East & Africa
🇦🇪
UAE PDPL
✓ Aligned
🇸🇦
Saudi PDPL
✓ Aligned
🏦
SAMA Framework
✓ Aligned
🏛️
CBUAE Guidance
✓ Aligned
🇪🇺
GDPR
✓ Ready
🔒
ISO 27001
In Progress
Data Residency
Your data stays where you need it
Every MENA bank and fintech has data localization requirements. FraudSense is the only fraud API in the region that offers sovereign cloud deployment as standard.
FraudSense never collects names, emails, photos, contacts, or financial data. We collect anonymous device parameters only — numbers like movementScore: 0.4 and typingWPM: 45. No parameter can identify a specific person.
UAE Sovereign Cloud
AWS Middle East (UAE) · Data never leaves UAE
Saudi Sovereign Cloud
AWS Riyadh · SAMA compliant deployment
On-Premise Deployment
Your infrastructure · No data leaves your network
Shared Cloud
Default · Instant setup · Best for developers
🔐
TLS 1.3 Encryption
All API communication encrypted in transit. HTTP connections rejected.
🗄️
AES-256 at Rest
All database data encrypted at rest. Backups encrypted with the same standard.
🛡️
Replay Attack Detection
Automatic detection of session token reuse. CRITICAL flag on 4th attempt.
📋
Data Processing Agreement
DPA available on request for enterprise clients. Required for PDPL compliance.