Security

Built to be examined.

FraudBrain handles evidence about people and money. This page describes how we treat that responsibility. The full documentation set, including the architecture detail this page deliberately omits, is available during vendor review.

Hosted on Google Cloud

FraudBrain runs on Google Cloud infrastructure. Encryption in transit and at rest is the default posture, not an option someone remembered to enable.

Scoped per organization

Every request is evaluated against the caller's organization on the server. Each organization sees exactly its own book. The boundary is proven by isolation tests that block deploys when they fail.

Invite-scoped access

Sign-in uses one-time codes delivered to pre-loaded invites. Access exists because an administrator granted it, and it is revocable the same way.

Least data

We take the fields the graph needs and no more. The metrics on this website are aggregate counts only; nothing on the marketing surface touches record-level data.

Human accountability

Reviewer actions are logged: who looked, who decided, when and why. The audit trail is part of the product, not an afterthought.

Documentation on request

Security and data-handling documentation is available during vendor review. Bring your diligence process and your data people.

Start the review.

Request access and bring your vendor-review process.

Request access

A human reads every request.