Aurora — real-time fraud and risk scoring (Go, gRPC + HTTP).
Folders under internal/ are business domains, not layers.
| Slice | Owns |
|---|---|
internal/scoring |
The assessment use case: HTTP surface, engine, request/response contracts |
internal/rules |
Weighted rule catalog, transaction signals, merchant-category and country risk tables, risk bands |
internal/velocity |
Sliding-window movement counters, per-account registry, thresholds and headroom |
internal/casefile |
Investigation records, the case-file state machine, analyst priority queues |
internal/settlement |
The ledger.settled Kafka consumer and the projection that folds settled movements into the read models |
internal/identity |
Client for the customer profile owned by aurora-identity |
internal/ledger |
Client for the postings owned by aurora-ledger |
| Verb | Path |
|---|---|
| POST | /api/v1/fraud/assessments |
| GET | /api/v1/fraud/cases |
| POST | /api/v1/fraud/rules |
| GET | /api/v1/fraud/velocity |
gRPC: proto/fraud/v1/fraud.proto, service FraudScoring.
GET http://aurora-ledger/api/v1/ledger/postingsGET http://aurora-identity/api/v1/customers/profile- Kafka consumer on topic
ledger.settled
- Velocity counters are advanced only from settled ledger events, never from authorisations, so a declined or reversed movement never inflates a subject's rate.
- A profile lookup failure is not fatal: an assessment proceeds on transaction facts alone rather than failing the authorisation path.
- The case-file state machine is closed. States absent from the transition table are terminal and their audit trail is sealed.