| Deployment model | SaaS or on-premise inside your own environment — same product either way. On-premise engagements cover Kubernetes or Docker deployment, HA, backup/restore rehearsal, and restricted-egress or air-gapped environments. | SaaS only — a cloud API. There is no self-hosted edition. | Cloud and, for enterprise contracts, private-cloud or on-premise deployment. Deployment shape is negotiated per contract. | Yours by definition — it runs wherever your core system runs. |
|---|
| Where transaction data lives | On the self-hosted deployment, every transaction and every decision stays inside your own environment. Nothing leaves it. | Vendor cloud, outside Indonesia. Sift also publicly markets a cross-customer global data network as a core part of its model. | Vendor-managed regions on the cloud edition; your environment on an on-premise contract. | Your environment. |
|---|
| How a decision is explained | Every decision is traceable to the rule that matched — a scored allow/flag/block returned with the matched-rule reason, and a full audit trail. Explicitly not a black box. | Machine-learning risk scores. The console surfaces contributing signals, but the model itself is proprietary and continuously retrained by the vendor. | Machine learning with vendor-published explainability tooling on top; the models remain the vendor's. | Whatever your team wrote — usually readable, rarely documented, and rarely audited. |
|---|
| Who changes a rule, and how fast | Your risk team, in a visual rule builder built for non-technical staff. Velocity checks over time windows are configurable the same way. | Analysts can layer rules and workflows over the vendor's score, but the score itself is not yours to tune. | Rules are authored in the vendor's case-management layer; model work typically involves the vendor's professional-services team. | An engineering ticket, a deploy, and a regression risk — every single time. |
|---|
| Latency | Synchronous rule evaluation on the authorization path, returning a scored allow/flag/block with the matched-rule reason. We do not publish a latency figure we have not measured against your traffic. | Real-time scoring API; no public latency figure. | Real-time scoring; figure on request. | Whatever you built. Usually unmeasured until it becomes an outage. |
|---|
| Indonesian regulatory framing | Mapped to OJK PBI No. 23/6/PBI/2021 fraud risk management, PPATK transaction-monitoring requirements, and BI payment-system-operator obligations. | Global fraud framing. No published Indonesian control mapping. | Global fraud and financial-crime framing. No published Indonesian control mapping. | You map it yourself, and you defend the mapping to the examiner yourself. |
|---|
| Ships integrated with the rest of the stack | Yes — one estate. Fraud sits beside AML Monitoring, KYC/KYB, the Reconciliation Engine, and the Payment Gateway, on one contract and one deployment. | A point solution. Wiring it to your gateway, your AML case queue, and your recon is your integration project. | A point solution. Same integration project, at enterprise scale. | Integrated with your own system by construction — and integrated with nothing else. |
|---|
| Pricing model | Flat monthly: Rp 2.500.000/mo Starter, Rp 8.000.000/mo Growth. On-premise pricing on request. Directional — billing is not yet active. | Volume/usage-based, quoted on request. No published list price. | Enterprise licence, quoted on request. No published list price. | No licence fee — you pay in engineer-months, on-call, and the fraud you missed while the rule was in review. |
|---|
| Who answers when it misfires at 03:00 | A Jakarta-based engineering team, in your timezone; on-premise deployments include a dedicated implementation team and SLA-backed support. | The support tier you purchased, offshore. | Your enterprise account and support team, offshore. | You. |
|---|