Data minimisation
Only the intelligence required for the fraud use case is exchanged. Not the record it was derived from, and not fields that do not serve the decision.
Alerra is designed so institutions can contribute fraud intelligence without exposing their underlying customer database. The bank keeps its data, its policy and its decision. What crosses the boundary is a narrow, derived object the institution chose to publish.
Everything in this box stays inside the institution. Alerra has no route to it and exposes no function that could reach it.
Runs under the institution’s control. It decides what may be derived, what may be published, and who may ask.
A simulated payment, sitting inside the bank boundary. Press the button and watch exactly which fields cross it.
Synthetic record. None of these values is transmitted.
On identity matching. Hashing alone does not anonymise customer information, and Alerra does not claim that it does. Production identity matching can use controlled tokenisation, keyed cryptographic identifiers, privacy-preserving record linkage or institution-approved matching mechanisms depending on deployment requirements.
Only the intelligence required for the fraud use case is exchanged. Not the record it was derived from, and not fields that do not serve the decision.
Each institution determines which capabilities and which signals its own gateway exposes, and to whom. The default is that nothing is exposed.
There is no query surface for browsing a bank’s records. The functions that would make it possible do not exist in the protocol.
Every intelligence request, every contribution and every decision-support response can be logged, attributed and reviewed after the fact.
A risk assessment returns the supporting evidence, not an unexplained score. An institution can interrogate every point it was given.
Alerra provides intelligence and evidence. The financial institution makes the decision, applies its own policy, and owns the outcome.
The complete set of capabilities an institution’s gateway can expose. Short enough to print, which is the point.
get_customer()
get_transactions()
search_bank_database()
list_accounts()
export_customer_profile()