> For the complete documentation index, see [llms.txt](https://docs.reachplatform.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.reachplatform.com/operations-and-reporting/platform-level-security-controls.md).

# Platform-Level Security Controls

Platform-wide fraud and SMS-abuse controls, including pre-payment risk screening and eSIM QR code restrictions for new activations.

### Overview

Reach operates **platform-level security controls** across **Reach Common** to reduce **fraud** and **SMS abuse**. These controls are designed to stop abuse early, before payment or activation, while preserving smooth experiences for legitimate customers.

This is an ongoing platform capability. Reach continues to refine these controls as threat patterns evolve.

* **What it is:** Platform-wide controls for **pre-payment transaction screening** and **eSIM QR code issuance**.
* **What problem it solves:** Elevated **fraud risk**, **abuse attempts**, and **SMS-related misuse** across the industry.
* **Where it applies:** Standard Reach Common journeys for **new purchases** and **new-number eSIM activation**.

{% hint style="info" %}
These controls are applied at the **platform level**. They protect both **partners** and **customers** without adding unnecessary friction for legitimate transactions.
{% endhint %}

### At a glance

| Control                           | Applies to                                 | Outcome                                                           |
| --------------------------------- | ------------------------------------------ | ----------------------------------------------------------------- |
| **Pre-payment risk screening**    | All **new purchase attempts**              | High-risk transactions are blocked **before** the payment gateway |
| **eSIM QR code restriction**      | **New number activations** via web and app | QR codes are not issued through self-service flows                |
| **Agent-assisted QR issuance**    | Supported new-number activation flows      | Agents can issue eSIM QR codes in **Reach Common**                |
| **Immediate port-in QR issuance** | **Port-in activations**                    | eSIM QR codes continue to be issued immediately                   |

### Scope

#### Included

* **Mandatory pre-payment risk screening** for all new purchase attempts
* Evaluation of **IP reputation**, **geographic consistency**, **email risk**, **device and network behavior**, and **transaction velocity**
* Restriction of **self-service eSIM QR code issuance** for new number activations via web and app
* Removal of QR code access from **customer profiles** for new number activations
* Continued support for **agent-assisted eSIM QR code issuance** in Reach Common
* Continued support for **immediate eSIM QR codes** for port-in activations

#### What remains unchanged

* Legitimate transactions that pass screening continue through the standard checkout flow
* **Port-in customers** continue to receive immediate eSIM QR codes
* **Agents** can continue issuing eSIM QR codes during assisted activation flows

### Core capabilities

#### Pre-payment transaction risk screening

All new purchase attempts are evaluated by a **mandatory screening layer** before they reach the payment gateway. Transactions that exceed defined risk thresholds are blocked immediately. No authorization attempt is made, and no card data is passed downstream.

**Signals evaluated**

* **IP reputation** and **geographic consistency**
* **Email risk patterns**, including disposable or high-risk identities
* **Device and network behavior** associated with automated or abusive activity
* **Velocity and repetition** across recent transactions

**Impact**

* Legitimate customers experience **no added friction**
* Suspicious activity is stopped **before payment is attempted**
* Risk to **payment infrastructure** and **merchant accounts** is reduced

{% hint style="warning" %}
For blocked transactions, **no authorization attempt is made** and **no card data is passed downstream**.
{% endhint %}

#### eSIM QR code restrictions for new number activations

To eliminate zero-friction abuse paths, Reach restricts **self-service eSIM QR code issuance** for **new number activations**.

| Activation type           | Web and app behavior                                                               | Agent behavior                                   |
| ------------------------- | ---------------------------------------------------------------------------------- | ------------------------------------------------ |
| **New number activation** | eSIM QR code is **not issued** and is **not accessible** from the customer profile | Agents can issue the QR code in **Reach Common** |
| **Port-in activation**    | eSIM QR code is issued **immediately**                                             | Agent support remains available if needed        |

**Why this matters**

* Legitimate customers are not blocked from eSIM activation
* Additional verification can occur before QR code issuance
* Abuse paths stay closed while **operational flexibility** is preserved

### Business rules

| Rule                        | Detail                                                                                           |
| --------------------------- | ------------------------------------------------------------------------------------------------ |
| **Pre-payment screening**   | All new purchase attempts must pass risk screening before reaching the payment gateway           |
| **Blocked transactions**    | Transactions above the risk threshold are blocked immediately                                    |
| **Payment handling**        | Blocked transactions do not create an authorization attempt and do not pass card data downstream |
| **New number QR issuance**  | Web and app flows do not issue eSIM QR codes for new number activations                          |
| **Customer profile access** | QR codes are not accessible from customer profiles for new number activations                    |
| **Port-in behavior**        | Port-in customers continue to receive immediate eSIM QR codes                                    |
| **Agent-assisted support**  | Agents can issue eSIM QR codes through Reach Common                                              |

### Operational workflow

{% stepper %}
{% step %}

#### Pre-payment risk screening

1. Customer initiates a new purchase attempt.
2. The mandatory risk screening layer evaluates the transaction before it reaches the payment gateway.
3. Screening evaluates **IP reputation**, **geographic consistency**, **email risk**, **device and network behavior**, and **transaction velocity**.
4. If the risk threshold is not exceeded, the transaction proceeds to the payment gateway.
5. If the risk threshold is exceeded, the transaction is blocked immediately.
   {% endstep %}

{% step %}

#### eSIM QR code for new number activation

1. Customer completes a new number activation via web or app.
2. The eSIM QR code is not issued and is not accessible from the customer profile.
3. An agent issues the eSIM QR code via Reach Common as part of an assisted activation flow.
   {% endstep %}

{% step %}

#### eSIM QR code for port-in

1. Customer completes a port-in activation.
2. The eSIM QR code is issued immediately.
   {% endstep %}
   {% endstepper %}

### Reporting and visibility

The following data points are available in the **Subscriber Report**.

| Field                         | Type       | Description                                                                                                       |
| ----------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------- |
| `IP_Address`                  | `varchar`  | Public IP captured at transaction time                                                                            |
| `IP_Risk_Score`               | `number`   | Fraud probability score associated with the IP                                                                    |
| `Email_Quality_Score`         | `number`   | Email trust and deliverability score                                                                              |
| `IP_Quality_Score`            | `number`   | IP trust and abuse reputation score                                                                               |
| `Last_Verified_Email_Time`    | `datetime` | Last email verification timestamp in EST (`YYYY-MM-DD HH:MM:SS`)                                                  |
| `Last_Verified_IP_Time`       | `datetime` | Last IP verification timestamp in EST (`YYYY-MM-DD HH:MM:SS`)                                                     |
| `IP_Quality_Score_Strictness` | `varchar`  | Strictness level applied during IPQS evaluation                                                                   |
| `Email_Valid`                 | `boolean`  | `True` means the email can proceed with purchase. `False` means the purchase is blocked based on email validation |
| `IP_Valid`                    | `boolean`  | `True` means the IP can proceed with purchase. `False` means the purchase is blocked based on IP validation       |

### Controls and safeguards

#### Validation checks

* **Mandatory pre-payment risk screening** is applied to all new purchase attempts before the payment gateway
* Transactions exceeding defined risk thresholds are **blocked immediately**
* No authorization attempt is made and no card data is passed downstream for blocked transactions

#### Access restrictions

* eSIM QR codes are not accessible from customer profiles for new number activations via web and app
* eSIM QR code issuance for new number activations is restricted to **agent-assisted activation** via Reach Common

{% hint style="info" %}
Questions or clarification? Reach out to your respective account manager or email us at <account-desk@reachplatform.com> for help and support.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.reachplatform.com/operations-and-reporting/platform-level-security-controls.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
