Security & privacy
Collect less. Isolate everything. Decide deterministically.
FRAPE is designed so the most sensitive data never enters the platform, and what does enter stays inside the tenant that sent it.
Controls
How data is protected
No card numbers, ever
- Requests containing a PAN or CVV field anywhere in the payload are rejected with 400 forbidden_field.
- Cards are identified only by a fingerprint, the BIN (6–8 digits) and the last four digits.
- PAN-like numbers are redacted before anything is written to the audit log.
Tenant isolation in depth
- Every tenant-scoped table carries an organization_id and a PostgreSQL row-level security policy.
- Each request runs in a transaction scoped to the caller’s organisation; application checks are still enforced on top.
- Cross-tenant lookups return 404 rather than 403, so identifiers cannot be enumerated.
Minimised Decision Core inputs
- The Decision Core receives a whitelisted state built field by field — never PAN, CVV, passwords, tokens, API keys, raw email, raw phone, full address or full IP.
- IP addresses are reduced to a /24 network, ASN and country before they reach the Decision Core.
- Its answers are schema-validated; malformed or out-of-range answers are treated as unavailable, and its output is advisory only.
Personal data handled as hashes
- Identity aliases such as email and phone are stored as keyed hashes with an optional masked display value.
- Identities are never merged on weak signals like a shared IP address.
- Retention is an organisation setting.
Credentials and keys
- API keys are shown once and stored only as a prefix plus an HMAC; comparison is constant time.
- Provider credentials live in a secret manager, are write-only in the admin console and are never returned by any API.
- Admin sessions use short-lived tokens in HttpOnly, Secure, SameSite=Strict cookies with CSRF protection.
Telemetry without personal data
- Traces, metrics and logs never carry personal data, secrets or raw request bodies.
- All administrative changes are audited; audit rows are append-only and reading them is itself audited.
- Outbound webhooks are signed and protected against server-side request forgery.
Plain dealing
What we do not claim
- No customer logos or testimonials — FRAPE is working with its first design partners.
- No accuracy or loss-reduction percentages — those depend on your traffic and your rules.
- No certifications we have not earned. The controls we do have are listed on the Security page.
This website
No cookies, no trackers
This site is a static export served with a strict Content-Security-Policy. It sets no cookies, loads no third-party scripts or analytics, serves its own fonts, and collects no form data.
Design partners
Help shape what FRAPE decides next.
We are working with a small number of teams who score payments, sign-ups, logins or payouts and want decisions they can explain line by line. Bring your rules and your edge cases.