Features
Every tool your fraud team needs, in one platform.
Score every risky moment in real time. Write the rules yourself. See who is really behind each event, and work the hard cases with the full story in front of you. This page lists what FRAPE does today and which plans include it.
Real-time decisions
One API call. A clear answer.
Five moments, one endpoint
Score sign-ups, logins, profile changes, payments and payouts through the same API. Each event is judged against the same customer and the same policy.
Where to find it: API · POST /v1/score
Four decisions you can act on
Every response returns approve, challenge, review or decline. You also get a score from 0 to 100, a risk level and reason codes your code can branch on.
Where to find it: API · POST /v1/score
Protected from day one
New accounts start on a ready-made policy that FRAPE maintains. It already covers shared cards, devices and accounts, Tor exits and hosting networks. Change any rule whenever you like.
Where to find it: Console › Decisioning › Policies
Country checks that respect travellers
A card from one country and an IP from another is normal for a lot of good customers. FRAPE adds risk for a mismatch only when reuse or velocity backs it up.
Where to find it: Default policy
Step-up challenges
When the answer is challenge, the response lists the methods your policy allows, such as a one-time code or a passkey. You run the check and report the result. FRAPE links it to the event and the customer.
Where to find it: API · /v1/challenges · Console › Challenges
Card numbers never accepted
Send a card as its fingerprint, BIN and last four. Any request that carries a card number or CVV is refused, so there is no card data to leak.
Where to find it: API · every request
Policy builder
Your rules, built without code.
Visual policy builder
Pick a field, an operator and a value. The builder checks each condition as you go and will not let you publish a version the engine would reject.
Where to find it: Console › Decisioning › Policies
Hundreds of fields to work with
Write rules over device, identity, velocity, email, phone, network and card data. Hard rules stop known fraud at once, signal rules add to the score, and your policy makes the call.
Where to find it: Console › Decisioning › Rules
Commit, compare, roll back
Commit a draft with a message. Compare two versions line by line, revert a change or restore an earlier version when something looks wrong.
Where to find it: Console › Decisioning › Policies
Four-eyes approval
Turn on approvals and no policy goes live until a second person signs it off. Authors cannot approve their own changes, and an emergency restore needs approval too.
Where to find it: Console › Decisioning › Policies › Approval queue
Rule hit statistics
See how often each rule fires. Retire the ones that never do and tune the ones that fire too often.
Where to find it: Console › Decisioning › Rules
Thresholds you set
Decide where challenge, review and decline begin. Set the countries you serve and your default currency in one settings page.
Where to find it: Console › Operations › Settings
Lists
Stop known fraud at the first gate.
Eight kinds of list
List devices, card fingerprints, emails, IPs and IP ranges, countries, BINs and account IDs. Values are stored as hashes and shown masked.
Where to find it: Console › Decisioning › Lists
Bulk import from a file
Upload a large file and FRAPE imports it in the background. You can watch the progress and get a line-by-line report of anything it could not read.
Where to find it: Console › Decisioning › Lists
Find any value
Check whether an exact email, card or IP is on a list, even though every value is stored hashed.
Where to find it: Console › Decisioning › Lists
Entries that expire on their own
Give an entry an end date and it stops matching when the date passes. Add it again later and it comes straight back.
Where to find it: Console › Decisioning › Lists
Tor and hosting networks built in
FRAPE keeps its own lists of Tor exit nodes and cloud hosting ranges up to date. They are checked locally on every event, with no outside call.
Where to find it: Rule fields · ip.tor_exit_listed, ip.hosting_listed
Decision Core
AI that advises. Your rules decide.
A second opinion on the grey zone
Clear cases are settled by your rules and never wait for the AI. Decision Core looks only at the events where its view could change the outcome.
Where to find it: Every scored event
Advice, never the verdict
Its answer feeds your policy like any other signal. Your rules make the final decision every time. If the AI is unavailable, your fallback applies and scoring carries on.
Where to find it: Every scored event
Starts by watching
New accounts begin in watch mode. You can see what Decision Core would have said long before it plays any part in a live decision.
Where to find it: Console › Decisioning › Overview
Usage in plain sight
A status card shows whether Decision Core is off, watching or active, and how many calls you have used this month. When the allowance runs out, scoring continues on your rules alone.
Where to find it: Console › Decisioning › Overview
Available on Every plan1,000 to unlimited Decision Core calls a month, by plan
Sees only what it needs
It receives a minimised summary of the event. Never card data, secrets, raw email addresses, raw phone numbers or full IP addresses.
Where to find it: Every Decision Core call
Its view on every event
Analysts see the AI hint beside each event, marked as advisory, so they know what it thought without mistaking it for the decision.
Where to find it: Console › Investigate › Events
Identity and fraud rings
See the person behind every event.
One customer, many identifiers
Strong identifiers such as an account, card fingerprint, email or phone link events to the same person. Weak signals like a shared IP never merge two people.
Where to find it: Console › Investigate › Identities
Merges you control
Review a proposed merge with the evidence behind it. Approve it, reject it or undo it later, and split an identity that was joined by mistake.
Where to find it: Console › Investigate › Identities
Find an identity fast
Look up a customer by exact email, phone, device ID or card fingerprint. Lookups are open to analysts and admins, and every one is recorded.
Where to find it: Console › Investigate › Identities
Identity graph
Explore how identities connect through shared devices and cards. Ask for the path between two of them to see exactly why they are linked.
Where to find it: Console › Investigate › Networks
Fraud ring detection
FRAPE groups identities that act together, such as accounts that share a device or a card or were created in a coordinated burst. Each ring shows how strong the link is, and you can open a case from it.
Where to find it: Console › Investigate › Fraud rings
Velocity on every identifier
Counts and amounts per card, device, email, IP, account and identity, over minutes, hours and a full day. Bursts of logins per identity are tracked as well.
Where to find it: Rule fields · velocity.*
Device signals
Know the device behind the click.
Device recognition
A first-party device ID recognises returning devices, so you can see when a known device turns up on a brand new account.
Where to find it: Browser agent · Console › Events
Bot and automation hints
Spot headless browsers, webdriver flags, tampered browser functions and software rendering. These are the marks scripted attacks leave behind.
Where to find it: Rule fields · device.*
Mismatch checks
Flag a device whose time zone, language or browser hints do not match what it claims to be.
Where to find it: Rule fields · device.*
Behaviour, never content
The agent counts interactions like clicks, scrolls and pastes. It never reads keystrokes, form values, the clipboard or location.
Where to find it: Browser agent
Email, phone and IP
Signals from every detail a customer gives you.
Email checks
Catch disposable domains, privacy relays, role accounts, random-looking addresses and suspicious top-level domains. All of it is checked locally.
Where to find it: Rule fields · email.* · Console › Events
Phone checks
Validity, number type and country for every phone number, worked out locally on every plan.
Where to find it: Rule fields · phone.*
Email domain checks in the background
FRAPE looks up each new email domain while you carry on scoring. Does it exist? Can it receive mail? Does it publish SPF and DMARC? How old is it, and is there a website behind it?
Where to find it: Rule fields · email.* · Console › Identities
Seen it before?
Know when an email or phone number first showed up in your traffic and how many identities have used it since.
Where to find it: Console › Events · Console › Identities
IP and card origin
Every IP is placed in a country and network, and every card BIN in a country, from reference data FRAPE holds itself. Test traffic uses the same data.
Where to find it: Rule fields · ip.*, card.*
Investigations
Every decision, explained in full.
Events explorer
Filter your events and open any one for the full story, with country flags and decision colours you can read at a glance.
Where to find it: Console › Investigate › Events
Signals overview
A strip at the top of each event shows what stood out in the device, network, card, velocity and contact checks. The detail is one click below.
Where to find it: Console › Events › Event
The policy result, in plain words
See where the score landed against your thresholds and what actually decided the event. It might be the score, a hard rule, a list or your fallback.
Where to find it: Console › Events › Event › Policy
What if, on a single event
Run one event against another policy version and compare the answer with the recorded decision. Nothing is saved.
Where to find it: Console › Events › Event › What if
Timing on every event
Each event shows how long its decision took, measured against the time budget for its path.
Where to find it: Console › Events › Event
A dashboard that explains the mix
Follow your approval, challenge, review and decline rates over time, along with your top reason codes and how often Decision Core was consulted.
Where to find it: Console › Dashboard · Decisioning › Overview
System health for your account
Keep an eye on errors, request volume, decision times and failing webhooks for your own traffic.
Where to find it: Console › Operations › System health
Alerts and cases
From alert to closed case, in one place.
Alerts without the flood
Review and decline decisions raise alerts automatically. Repeats are grouped by identity and rule, so one busy fraudster does not bury your queue.
Where to find it: Console › Investigate › Alerts
Case management
Assign cases, track SLA due dates and link the events and alerts that belong together. Comments and a full timeline live in the same record.
Where to find it: Console › Investigate › Cases
A queue for each analyst
Everyone gets an assigned-to-me view, so no case falls between two people.
Where to find it: Console › Investigate › Cases
Summaries that stick to the facts
Case summaries are written from templates and the case data. They say what the data says and nothing more.
Where to find it: Console › Cases › Case
Backtesting
Test a policy before it touches a customer.
Decision Lab
Replay past traffic against a candidate policy and see each decision that would change, from approve to review or from review to decline.
Where to find it: Console › Decisioning › Backtesting
Available on Starter and up10 to unlimited backtest runs a month, by plan
Rule impact
Find out which rules drive the changes and how many events each one touches.
Where to find it: Console › Decisioning › Backtesting
Runs you can repeat
Each run records what it replayed and how, so you can explain a result later and run it again.
Where to find it: Console › Decisioning › Backtesting
Webhooks
Updates pushed to your systems, safely.
Signed deliveries
Every delivery carries a signature you can verify. Rotate the signing secret whenever you need to.
Where to find it: Console › Operations › Webhooks
An API key in a header
Does your endpoint expect a key? Add one as a custom header. It is stored encrypted and never shown again.
Where to find it: Console › Operations › Webhooks
Delivery log and redelivery
Send a test message, see every attempt in the delivery log and redeliver any message with one click.
Where to find it: Console › Operations › Webhooks
Outside checks, redacted
Scored-event webhooks sum up the outside checks behind a decision by category, status and time taken. Provider names, keys and costs stay inside FRAPE.
Where to find it: Webhook · event.scored
Team and security
Access that stays under control.
Roles for every job
Viewers, analysts and admins each get clear permissions. Invite teammates by email and change their role as the team grows.
Where to find it: Console › Operations › Users
Two-factor sign-in
Authenticator-app codes with recovery codes. Two-factor is required for admins, and sensitive actions ask for a fresh code.
Where to find it: Console › Account › Security
Sign in with Google
Your team can sign in with their Google accounts. The two-factor check still applies.
Where to find it: Sign-in page
Audit log
Every admin change is recorded with who made it and what changed, before and after. Reading the audit log is recorded too, and the log is kept for your plan’s retention period.
Where to find it: Console › Operations › Audit
Available on Every planAudit log kept 30 days to 730 days, by plan
Session control
See where you are signed in and end any session you do not recognise.
Where to find it: Console › Account › Security
Developers
Simple to integrate. Safe to retry.
Test keys from the start
Build against test keys that are never billed and never call outside providers. Switch to a live key when you are ready.
Where to find it: Console › Operations › API keys
Scoped API keys
Give each key only the scopes it needs and an optional expiry date. A key is shown once and stored as a hash.
Where to find it: Console › Operations › API keys
Safe retries
Send an idempotency key and a retried request returns the original answer instead of scoring the event twice.
Where to find it: API · Idempotency-Key header
Errors you can handle
Errors come back as standard problem+json with a stable code, so your client knows what went wrong and what to do next.
Where to find it: API · every endpoint
Browser agent
Add the agent as a package or a single script tag. It has no dependencies and keeps its payload small.
Where to find it: Browser agent · package or script
Privacy
Privacy built into the data model.
Hashed personal data
Emails and phone numbers are stored as keyed hashes and shown masked. Event snapshots hash protected identifiers as well.
Where to find it: Everywhere
Erasure on request
When a customer asks to be forgotten, an admin can erase their identity data from the console.
Where to find it: Console › Investigate › Identities
Retention you control
Choose how long event data is kept, up to your plan’s limit. Older data is removed for you.
Where to find it: Console › Operations › Settings
Available on Every planEvent data kept 30 days to 730 days, by plan
Your data stays yours
Database row-level security fences off every account, with application checks on top. Other customers can never see your records.
Where to find it: Everywhere
No personal data in telemetry
Traces, logs and metrics never carry personal data, secrets or raw request bodies.
Where to find it: Everywhere
Get started
Start stopping fraud today.
Start free with test keys and the AI switched on, and see every decision explained on your own traffic. Or tell us what you need to protect, and we will walk you through how FRAPE would decide it. Compare plans.