Self-hosted device intelligence

Know the device.
Own the data.
Write the rules.

TSEC is device intelligence and identity orchestration that runs entirely inside your own infrastructure. Score every login, catch bots and account takeover, and step up risk — without shipping a single byte of your users' data to a third-party fraud vendor.

Runs in your cluster· No data leaves your VPC· Explainable by design· Kubernetes-native

The problem

Your fraud vendor is a data-export decision you didn't mean to make.

Every cloud device-intelligence and fraud service works the same way: it ingests your users' device, network, and behavior data into their cloud. If you're in fintech, healthcare, government, or under GDPR, that isn't a vendor choice — it's a residency, compliance, and trust problem you can't wave away.

TSEC flips the model. The intelligence runs where your data already lives, so recognizing a device never means exporting one.

Built for teams that can't send user data to someone else's cloud
Fintech & crypto Healthcare Public sector EU / data residency Regulated platforms

The difference is where it runs.

Same job — recognize devices, catch fraud, step up risk. Opposite trust model.

TSEC · self-hosted Cloud fraud & identity SaaS
Where your users' data livesYour cluster / VPCThe vendor's cloud
Risk logicYours — readable, editable rulesBlack-box score
Every decisionFull, auditable evidence trailOpaque
Data residency & sovereigntyBy defaultRegion add-on, if offered
DeploymentHelm · runs anywhereSaaS only
Change a flowVisual builder, no redeployTicket the vendor

The platform

One system for the whole login.

Design the flow and the device checks together — screens, decisions, API calls, and risk — as one versioned journey.

Visual journey builder

Drag screens, decisions, API calls, and device checks into a flow. Publish immutable versions. Change the login without shipping code.

Device fingerprinting

High-entropy canvas, WebGL, and audio signals collected in the browser and matched server-side. The client is never trusted.

Trusted-device binding

Bind accounts to devices. Recognize a returning customer and let them straight through; challenge everyone else.

Bot & takeover signals

Catch automation and shared-device / account-takeover patterns with configurable, weighted risk rules — not a mystery number.

Explainable risk

Every score keeps a trail: which rules fired, which signals matched, and how the number was built. Auditable end to end.

Step-up & orchestration

Route on risk: allow, challenge, step up, or block. Call your own APIs, reuse sub-flows, and gate exactly where it matters.

How it works

Model it. Score it. Route on it.

1

Model the flow

Build login, registration, and step-up journeys in the visual builder — device checks included — and publish a version.

2

Score every session

The runtime fingerprints the device server-side and scores risk with rules you wrote and can read.

3

Route on risk

Trusted devices sail through. Risky ones step up. Bots get blocked. Every decision is on the record.

On the record

No mystery scores. Ever.

Cloud fraud tools hand you a number and a shrug. TSEC hands you the receipt: the exact signals that matched, their weight, and the rule that fired — for every session, in your own logs. When compliance or a customer asks “why was I challenged?”, you have an answer.

  • Per-decision evidence trail, stored in your database
  • Rules you edit as a form or raw JSON — no redeploy
  • Reproducible: same signals, same score, every time

Deploy

Your infrastructure. Your rules. Your data.

Container images and a Helm chart. Runs on your cloud or on-prem — nothing phones home.

# runtime, builder, and PostgreSQL — in your cluster
helm upgrade --install tsec oci://ghcr.io/tricaso/charts/tsec \
  --namespace tsec --create-namespace
KubernetesHelmPostgreSQLSelf-hostedAir-gap friendly

Pricing

Pricing that respects self-hosted.

No per-check metering on your own hardware. No data-egress surprises. Straightforward licensing sized to your deployment — tell us what you're running and we'll give you a number.

Team

One product, one self-hosted deployment.

  • Runtime, builder & SDK
  • Device fingerprinting & matching
  • Configurable risk rules
  • Helm chart & container images
  • Email support
Get pricing

Questions, answered straight

The things you're actually going to ask.

Does any user data leave our infrastructure?

No. The runtime, builder, and database all run in your cluster. Device signals are collected in the browser and evaluated on your servers. Nothing is sent to us.

Can we read and change the risk logic?

Yes. Rules are yours — editable in the visual builder or as raw JSON, versioned and inspectable. No black box, no waiting on a vendor.

Is this a shared fraud network?

No — and on purpose. TSEC gives you your own device intelligence, not a consortium that pools your users' data with everyone else's. That's exactly why it's safe to run in-house.

Do we have to replace our identity provider?

No. TSEC orchestrates the flow and calls your existing services and APIs — credential checks, MFA, your IdP. It sits in front of what you already have.

How do we deploy it?

A Helm chart and container images. Kubernetes on your cloud or on-prem, air-gap friendly. Up in an afternoon; we'll help.

Bring device trust in-house.

See it running against your stack, and get pricing sized to your deployment.