A fraud flag is not a decline
Challenge, step up, or accept liability. The vendor score is an input. It is not the chargeback.
Payments and fraud · ŌURA · Austin
I own payments and fraud at ŌURA. Node and TypeScript. Card vault, 3DS and SCA, multi-PSP routing, retries, reconciliation. $59.6M GMV recovered in seven months without putting PANs in app scope.
Exceptional work
Fraud was declining good ŌURA orders. I built a step-up pipeline that challenges Kount, Forter, and hCaptcha flags with 3DS instead of dropping them, then added email OTP. In seven months it recovered $59.6M of GMV that would have been lost. 57% of challenges converted. 65.6% of challenged volume shifted liability. Cards stay in Basis Theory. Adyen and Braintree fail over without putting PANs in our PCI scope. The work is idempotent webhooks, liability shift, and reconciliation.
Work
Also: Heads, 2021–2023. Square-like retail POS. React, Node, iOS. Money at a register.
How I think about money movement
Challenge, step up, or accept liability. The vendor score is an input. It is not the chargeback.
PANs live in a vault. Processors are adapters. Failover and 3DS should not expand PCI scope.
Webhooks retry. Clients double-submit. If the system is not idempotent it will charge twice or never reconcile.
Auth, capture, settlement, refund, and rounding are ledger events. If you cannot explain the money, it is not shipped.
Stack
MS Distributed Systems, KTH. I design these systems in Node and TypeScript on AWS. I have not built card issuing. I have lived on the authorization, capture, settlement, and reconciliation side of that ledger.
Ownership
Founded iSpect and iControl. Helped found Buildcraft. Grew iSpect ERP to $4M ARR. Took iControl through 500 Startups Batch 19 ($150K seed) to $55K MRR. Built and led teams of up to 18 across four timezones. Offline-first sync from that decade is still in production.