TRUST CENTRE

Security built for the Australian trades floor

Every invoice, email, and payment request is run through 15 independent verification layers — 14 deterministic forensic checks plus a Gemini 3 Flash reasoning layer — before you transfer a dollar. Here is exactly how we protect you.

Live · updated every 30s
Last flag: moments ago
Fraud $ blocked
$0

Protected for Australian businesses, calculated on a conservative $4,200 average invoice value.

Scams blocked
0

High-risk invoices, emails, SMS and supplier requests caught before payment was sent.

Decision-support, not a fraud guarantee

RILLA Shield is a decision-support and risk-scoring tool. It signals, flags, and indicates potential risk by running invoices, emails, bank details, and suppliers through 15 verification layers. It does not detect, prevent, stop, or guarantee the absence of fraud, scams, invoice redirection, payment diversion, business email compromise, or cybercrime. The final decision to pay, delay, cancel, or report any transaction always rests with you and should be independently verified.

15
Fraud-detection layers
100%
Australian data hosting
<2s
Verdict SLA (p95)
0
Payment data retained

Performance SLA

A verdict on your desk before you finish reading the invoice.

p95 verdict latency
< 2s

95% of scans return a full risk verdict in under 2 seconds. Measured end-to-end from upload to badge.

p50 verdict latency
< 800ms

Median scan completes in under 800ms. Small text-only scans typically resolve in 300–500ms.

Uptime target
99.9%

Rolling 30-day API availability target. Live status at /status. Credit-back if we miss it two months in a row.

What "verdict" means

All 15 live detection layers complete, a risk band is assigned (Safe / Verify / High Risk), and the signed result is returned to your browser, API caller, or Zapier webhook.

If we're slower than 2s

Large PDFs (>10MB) or scans requiring live ABR / RDAP round-trips can exceed 2s. Every scan is timestamped — check the audit trail on any verdict page.

SLA measured from RILLA's edge worker on receipt of a valid scan request through to the signed response. Excludes client network time and third-party bank / accounting round-trips.

Real-time verification layers

Each layer runs independently. A single red flag is enough to pause a payment. Multiple green checks are required before we ever recommend "safe."

01LIVE

ABN Checksum & Format

Every ABN is validated against the official Australian Business Register checksum algorithm. Invalid or malformed ABNs are blocked immediately.

02LIVE

ASIC Entity Status

Connected to the ABR web service. We surface cancelled, deregistered, or wound-up entities that still pass the raw checksum.

03LIVE

Domain Age Forensics

Invoices from domains registered less than 30 days ago trigger an automatic HIGH risk flag. We query RDAP (Registration Data Access Protocol) in real time.

04LIVE

AI Prompt-Injection Defence

Before our AI reads any document, we strip zero-width characters and neutralise hidden instructions designed to manipulate the risk score.

05LIVE

Email Header & BEC Forensics

Reply-To mismatches, display-name spoofing, and failed DKIM/SPF/DMARC authentication are flagged as high-severity BEC indicators.

06LIVE

Cousin-Domain Detection

Levenshtein distance + homoglyph normalisation catches lookalike domains (e.g., rilla-shleld.com) registered to impersonate known suppliers.

07LIVE

PDF Metadata & Tamper Detection

We extract Producer, Creator, CreationDate and ModDate from the raw PDF bytes. Consumer word-processors, modification gaps, and stripped metadata are all flagged.

08LIVE

Behavioural Supplier Baselines

We compare each invoice amount against the supplier's own historical pattern. Amounts 200%+ above the mean trigger high-risk escalation.

09READY

Sanctions & PEP Screening

OpenSanctions integration checks supplier names against DFAT, OFAC, and global sanctions lists. Configurable on request.

10PLANNED

Confirmation of Payee (CoP)

Direct integration with Australian bank CoP APIs (Azupay / Monoova) to verify the account name matches the supplier before you transfer.

11PLANNED

Xero / MYOB Native Integration

Auto-scan invoices as they arrive in your accounting software. No manual upload required — friction drops to zero.

12PLANNED

WhatsApp / SMS Scan Inbox

Forward suspicious invoices via WhatsApp or SMS and receive an instant risk score reply. No app install needed for one-off checks.

13LIVE

Bank-Details-Change Detection

Compares each invoice against the last N invoices from the same supplier for this customer. A BSB or account swap is the #1 BEC signal — we surface it immediately.

14LIVE

Cross-Tenant Network Signal

One-way hashed, zero PII: has this BSB, account, or domain been flagged by another RILLA customer in the last 90 days? Herd immunity for Australian trades.

15LIVE

Gemini 3 Flash Reasoning Layer

Reads all 14 deterministic signals plus the invoice body and writes a plain-English explanation for the verdict. Deterministic first, AI second — every verdict is explainable and reproducible, never a black box.

ASD Essential Eight Alignment

Australian Cyber Security Centre baseline

Application control
Signed uploads only. File-type validation on every scan.
Partial
Patch applications
Dependency audit runs on every build. Auto-updates via CI/CD.
Aligned
Configure MS Office macro settings
Not applicable — we do not process Office macros.
N/A
User application hardening
Browser-only app. No local install, no admin rights required.
Aligned
Restrict administrative privileges
Role-based access control (RBAC) with least-privilege defaults.
Aligned
Patch operating systems
Cloud-hosted — managed by platform provider.
N/A
Multi-factor authentication
Supabase Auth with MFA support. Enforceable per organisation.
Aligned
Daily backups
Automated point-in-time recovery via Lovable Cloud / Supabase.
Aligned

Data residency & privacy

Australian-hosted

All data is stored in Australian data centres (Supabase / Sydney region). No offshore replication without explicit consent.

End-to-end encryption

All traffic is TLS 1.3. Database connections are encrypted at rest and in transit.

Retention limits

Scans are retained for the life of your subscription plus 30 days, then purged. You can delete earlier.

No payment data

We never see, store, or process your bank credentials, card numbers, or internet banking passwords.

No third-party AI training

Your invoice data is not used to train external AI models. Our LLM calls are stateless and anonymised.

SOC 2 Roadmap

We are actively preparing for SOC 2 Type II assessment. Current controls include:

  • RBAC with role separation (admin / moderator / user)
  • Rate-limiting & abuse prevention on all endpoints
  • Audit logging on every scan, login, and data change
  • Secure development lifecycle (CI/CD, secret scanning)
  • Penetration test scheduled (Q3 2026)
  • External auditor engagement pending

How we compare

RILLA Shield is the only fraud-detection platform built specifically for Australian trades that combines document forensics, email/BEC detection, and real-time regulatory data.

CapabilityRILLA ShieldEftsureXBertTrustmi
ABN validation Yes Yes No No
ASIC status check Yes Yes No No
Domain age forensics Yes No No No
AI prompt-injection defence Yes No No No
Email header / BEC forensics Yes Partial No No
Cousin-domain detection Yes No No No
PDF metadata tamper check Yes No No No
Supplier amount baseline Yes No No Yes
Sanctions screening Ready No No Yes
Confirmation of Payee Planned Yes No No
Built for tradie price point Yes No Yes No
Australian data hosting Yes Yes No No

Questions about our security?

If you're a finance team, builder, or procurement officer and need our full security questionnaire, incident-response plan, or penetration-test timeline, reach out directly.