What Data FraudTrace AI Stores
FraudTrace AI’s database contains intelligence about fraud actors — not about your customers or their transactions. The data stored is limited to:- Fraud-actor UPI Virtual Payment Addresses (VPAs): The UPI IDs associated with mule accounts, scam operations, and fraudulent merchant registrations, indexed from publicly observable fraud signals.
- Source URLs of fraud sites: Web addresses of phishing pages, fake investment platforms, and scam storefronts identified by our intelligence pipeline.
- Archived screenshots: Visual evidence of fraud pages at the time of detection, retained as evidentiary artefacts.
- Timestamps: The date and time each fraud signal was first and most recently observed.
- Fraud category metadata: Classification labels such as
MULE_ACCOUNT,PHISHING,INVESTMENT_SCAM,FAKE_MERCHANT, and associated confidence scores.
None of the above constitutes personal data of a bank customer, payment sender, or payment recipient. The indexed entities are fraud actors — not the victims of those fraud actors.
What FraudTrace AI Never Stores
Your customers’ data stays entirely within your systems. The only thing you send to FraudTrace AI is the UPI VPA string you want to check — nothing else is required or transmitted.
What You Send to the API
A typical FraudTrace API call looks like this:Data Residency
All FraudTrace AI data — the fraud intelligence database, archived screenshots, audit logs, and API infrastructure — is hosted exclusively on AWS Mumbai (ap-south-1).No data is replicated to, processed in, or accessible from any region outside India. This satisfies RBI data localisation requirements for third-party API integrations at banks and regulated payment institutions.
DPDP Act 2023 Compliance
India’s Digital Personal Data Protection Act 2023 applies to the processing of personal data of individuals. FraudTrace AI’s compliance position is straightforward:- The data FraudTrace AI processes consists of fraud-actor identifiers (UPI VPAs) sourced from publicly observable fraud sites and intelligence feeds — not personal data of bank customers or payment users.
- FraudTrace AI does not act as a Data Fiduciary under DPDP for any of your customers’ personal data, because it never receives or stores that data.
- You do not need to obtain your customers’ consent for FraudTrace API calls, because you are not sharing your customers’ personal data with FraudTrace.
Audit Logs
Every API request your system makes to FraudTrace AI is recorded in an immutable audit log that includes:- The timestamp of the request
- The API key identifier used (not the key value itself)
- The endpoint called
- The response status and fraud signal returned