Product · Intelligence rules engine

Policy as code — with the safety net of a compiler.

A typed, versioned rules language your fraud team writes, your engineers review, and every regulator can read.

< 50ms
Median latency
99.99%
Uptime SLA
3
Decision outcomes
POST /v1/rules/eval
rule "velocity_window" {
when: user.txn_1h > 5
then: flag("velocity")
}
} → compiled, versioned, enforced

Scorift's Rules Engine gives you a flexible way to express risk policy — IF/THEN logic over any signal, output, or entity. Every rule is versioned, testable in a sandbox, promotable through test mode, and rollback-able with a single click.

Built-in validation

Catch signal name typos and unit mismatches before a rule ever goes live.

Test → enforce

Every rule can run in test mode to measure fire rate against production before enforcing.

Deterministic backtests

Point a rule at last month's events and see exactly what would have happened.

Policy pack marketplace

Battle-tested packs for chargebacks, mule, ATO, and marketplace abuse.

  • Author in the dashboard or in code — the DSL is the same either way.
  • Rules ship with tests. Break a test in CI and the deploy blocks.
  • Every rule is tagged and traceable to a policy owner and a business rationale.
  • Import from FICO, Sardine, and other legacy rule engines with our converter.
How it works

From event to decision in four steps

01
Author

Write a rule in the dashboard editor or from your code repo with CI.

02
Backtest

Replay against 30/60/90 days of production traffic — see fire rate and expected outcomes.

03
Test

Enable in test mode alongside production to measure the impact against current policy.

04
Enforce

Promote to enforce with a policy-owner sign-off captured in the audit trail.

Where teams use it

Built for every risk moment

Velocity limits

Cap transaction count / value per user, device, or card in flexible windows.

Blocklists

Deny known-bad devices, BINs, and IPs across your entire account base.

Step-up policy

Trigger 3DS or MFA when composite score crosses a threshold.

Return / refund abuse

Cap refunds per user cohort and detect serial returners across accounts.

SOC 2 · PCI DSS · ISO 27001

Independently audited and continuously monitored.

99.99% uptime SLA

Multi-region active-active with graceful degradation.

Explainable by default

Every decision ships with a signal breakdown for your analysts.

Stop fraud before it hits your P&L.

Talk to a fraud engineer or spin up a sandbox today — no credit card required.