Visual journey builder
Drag screens, decisions, API calls, and device checks into a flow. Publish immutable versions. Change the login without shipping code.
Self-hosted device intelligence
TSEC is device intelligence and identity orchestration that runs entirely inside your own infrastructure. Score every login, catch bots and account takeover, and step up risk — without shipping a single byte of your users' data to a third-party fraud vendor.
The problem
Every cloud device-intelligence and fraud service works the same way: it ingests your users' device, network, and behavior data into their cloud. If you're in fintech, healthcare, government, or under GDPR, that isn't a vendor choice — it's a residency, compliance, and trust problem you can't wave away.
TSEC flips the model. The intelligence runs where your data already lives, so recognizing a device never means exporting one.
Same job — recognize devices, catch fraud, step up risk. Opposite trust model.
| TSEC · self-hosted | Cloud fraud & identity SaaS | |
|---|---|---|
| Where your users' data lives | Your cluster / VPC | The vendor's cloud |
| Risk logic | Yours — readable, editable rules | Black-box score |
| Every decision | Full, auditable evidence trail | Opaque |
| Data residency & sovereignty | By default | Region add-on, if offered |
| Deployment | Helm · runs anywhere | SaaS only |
| Change a flow | Visual builder, no redeploy | Ticket the vendor |
The platform
Design the flow and the device checks together — screens, decisions, API calls, and risk — as one versioned journey.
Drag screens, decisions, API calls, and device checks into a flow. Publish immutable versions. Change the login without shipping code.
High-entropy canvas, WebGL, and audio signals collected in the browser and matched server-side. The client is never trusted.
Bind accounts to devices. Recognize a returning customer and let them straight through; challenge everyone else.
Catch automation and shared-device / account-takeover patterns with configurable, weighted risk rules — not a mystery number.
Every score keeps a trail: which rules fired, which signals matched, and how the number was built. Auditable end to end.
Route on risk: allow, challenge, step up, or block. Call your own APIs, reuse sub-flows, and gate exactly where it matters.
How it works
Build login, registration, and step-up journeys in the visual builder — device checks included — and publish a version.
The runtime fingerprints the device server-side and scores risk with rules you wrote and can read.
Trusted devices sail through. Risky ones step up. Bots get blocked. Every decision is on the record.
On the record
Cloud fraud tools hand you a number and a shrug. TSEC hands you the receipt: the exact signals that matched, their weight, and the rule that fired — for every session, in your own logs. When compliance or a customer asks “why was I challenged?”, you have an answer.
Deploy
Container images and a Helm chart. Runs on your cloud or on-prem — nothing phones home.
# runtime, builder, and PostgreSQL — in your cluster
helm upgrade --install tsec oci://ghcr.io/tricaso/charts/tsec \
--namespace tsec --create-namespace
Pricing
No per-check metering on your own hardware. No data-egress surprises. Straightforward licensing sized to your deployment — tell us what you're running and we'll give you a number.
One product, one self-hosted deployment.
Multiple environments, SLAs, security review.
Questions, answered straight
No. The runtime, builder, and database all run in your cluster. Device signals are collected in the browser and evaluated on your servers. Nothing is sent to us.
Yes. Rules are yours — editable in the visual builder or as raw JSON, versioned and inspectable. No black box, no waiting on a vendor.
No — and on purpose. TSEC gives you your own device intelligence, not a consortium that pools your users' data with everyone else's. That's exactly why it's safe to run in-house.
No. TSEC orchestrates the flow and calls your existing services and APIs — credential checks, MFA, your IdP. It sits in front of what you already have.
A Helm chart and container images. Kubernetes on your cloud or on-prem, air-gap friendly. Up in an afternoon; we'll help.
See it running against your stack, and get pricing sized to your deployment.