VeritasIQ sits inline between your platform and the rail — scoring every transaction against deterministic rules and a live transaction graph, then returning a verdict within a sub-150 ms decision budget.
Supported rails & standards
Six engines run on every transaction — each built for the hot path and capped to a slice of the latency budget. One round trip, one signed verdict.
A verdict on every transaction before it settles — allow, challenge, block, or alert — returned within a hard p99 budget.
Per-tenant models that learn online, alongside the rules — not instead of them.
A live transaction graph surfaces mule rings as clusters, not isolated flags.
Velocity, amount, KYC, geo, blocklist — shipped per tenant from Rule Studio, no deploy.
Every party screened against sanctions, PEP, and KYC status — inline, before the verdict.
Every verdict carries its full reason path — hashed into an append-only, Merkle-anchored log that makes tampering mathematically detectable.
One round trip, one verdict. All six engines resolve into a single signed decision — returned to the rail in well under 150 milliseconds.
ALLOW·0.97A transaction enters the gateway and leaves with a verdict. Everything in between happens before the money moves.
mTLS · auth · tenant resolution · idempotency · rate limit
Bloom / Count-Min short-circuit · kills 60–80% of decisions
Device · geo · KYC level · sanctions / PEP · FRI lookup
Velocity · amount · geo · graph · ML — fanned out in parallel
Weighted verdict · EFRuP overrides · threshold evaluation
Append-only · Merkle-anchored · regulator report auto-filed
Reporting is a first-class feature, not paperwork. India-first, with the architecture ready for five regions from day one.
RBI Master Directions on Fraud Risk Management · DPDP 2023
Same images, same charts — only the regulator kit varies
US
EU
UK · SG · UAE
Cross-cutting
Every record, cache key, message subject and log line carries a tenant_id the platform enforces at the infrastructure level — never left to application code.
Each tenant's DEK is wrapped by a KEK in KMS. A full DB dump without KMS access is just ciphertext.
PostgreSQL row-level security blocks cross-tenant reads below the application — not inside it.
Probes try every API, cache key and subject for a leak. Any success fails the build.
The things every risk, platform, and compliance team asks in the first call.
Open the console and push a transaction through the full pipeline — verdict, score, and reason path, end to end.