How it works
RedFlag sits in the event stream between your systems and your decisions. Here's what happens in those 340 milliseconds.
Ingest
Your system sends events to the RedFlag API — user actions, transactions, authentication events, whatever matters for your risk surface. Batches or real-time, REST or webhook.
Enrich
Every event is enriched with context from our global threat network — IP reputation, device fingerprints, known bad actor patterns — before a single model runs.
Score
A cascade of streaming ML models evaluates the enriched event in parallel. Each model has a specific job: velocity checks, behavioural anomalies, graph-based fraud rings.
Explain
The final risk score is packaged with a plain-language rationale and the top contributing signals — so analysts don't just know what to do, they know why.
Act
The response lands back in your system via API, or fires a webhook to your SIEM, case management tool, or Slack. You define the threshold — we deliver the signal.