Risk signals
Device, velocity and address checks travel with the request instead of running after it.
- Reason code kept
- Issuer response stored
- Retry rule per scheme
Tessen clears card, bank transfer and wallet payments onto one ledger. Every movement carries the record that explains it, so finance and compliance stop reconciling two versions of the same day.
Each control below maps to a named report, a review date and the person who signed it. When an auditor asks for evidence you send a reference, not a description.
Reports are issued by an independent firm and reissued annually. Between issues, any change to a control is published to the change log within a day, with the affected report section listed alongside it.
Five stages, one identifier. The same reference follows an amount from the authorization request to the line in your monthly report.
Money arrives from six kinds of counterparty, and every one of them has its own file format, its own cutoff and its own idea of what a reference number looks like. Tessen normalises them at the door. After that point a card capture and a bank credit are the same shape of record.
The request reaches the issuer with the risk signals already attached. A decision comes back with the reason code intact, not flattened into a pass or fail.
Decision returned in 240 ms medianCaptures batch by scheme and currency. Each batch keeps the list of payments inside it, so a disputed amount resolves to a file you can open rather than a total you have to trust.
Batches close on a two-hour cycleBank statements match against expected settlement before anyone opens a spreadsheet. Unmatched lines surface with the difference already calculated and the likely cause named.
94% matched without reviewPayouts leave on the schedule you set, split across accounts by rule. Held funds show the rule that held them and the date they release.
Payout windows configurable per entityMonth end reads from the same ledger the payment wrote to. Drill from a summary figure to the individual authorization without leaving the report.
Close in 3 days, down from 11A leg is not finished when the money moves. It is finished when the check behind it has run and the result has a place to live. These are the checks, in the order the route meets them.
Device, velocity and address checks travel with the request instead of running after it.
Every capture belongs to exactly one batch, and the batch total is the sum of its rows.
Bank credits match expected settlement on amount, date and reference before a human sees them.
Splits, holds and reserves are rules with dates, so a held balance always answers why.
Each movement writes a double entry. Nothing is edited later; corrections are new entries.
A figure in a report carries the query that produced it, so the drill-down is exact rather than approximate.
The part of a payment that survives the payment is the record. Five entries are written on the way through, and none of them can be edited afterwards. This is what an auditor reads a year later.
The issuer's answer is kept whole. A decline that arrived as insufficient funds stays that way in the record, so a support agent six weeks later reads the same reason the terminal did.
When a batch closes it stops accepting rows. The seal keeps the count and the total that were true at that second, which is what makes a later dispute resolvable rather than arguable.
Matched, partially matched or unmatched, with the tolerance that was applied and the difference in cash terms. An unmatched line names its likely cause rather than waiting for someone to guess it.
The instruction stores the rule version that produced it. Change the split next quarter and last quarter's payout still explains itself under the rule that was live when it left.
Closing locks the period and records who locked it. Anything that arrives afterwards becomes a restatement with its own entry, and the original figures stay readable.
Eight stamps are written when a period closes. They are the short answer to the question an auditor opens with, and each one links to the entries that produced it.
CTL-01
Ledger balanced
Debits equal credits for every entry in the period.
CTL-02
Settlement matched
Bank credits reconciled against expected payouts.
CTL-03
Breaks cleared
Open items carried into the next period are listed with an owner.
CTL-04
Holds explained
Every held balance names its rule and release date.
CTL-05
Access reviewed
Who could approve a payout, and when that changed.
CTL-06
Retention held
Entries kept for the term your regulator asks for.
CTL-07
Restatements linked
Corrections point back to the figure they replaced.
CTL-08
Export reproducible
The same period exported twice returns the same file.
Most teams run these as separate tools and spend the month proving they agree. Here they write to the same record, so agreement is the default state rather than the outcome of a reconciliation.
Authorizations, captures and refunds stay linked to the payment that started them. A chargeback opens with the evidence already assembled.
Bank files land, match against expected settlement, and post. What is left is a short list of genuine exceptions with the delta computed.
Funds sit where policy says they should. Sweeps, holds and payout schedules are configuration, so a change is a review rather than a release.
Close reads from the ledger the payments wrote to. Any figure in the report expands to the entries behind it, down to the original request.
A control is only worth the drill that tests it. Each layer below lists what it protects and what happens the day it does not hold.
AES-256 on stored records, TLS 1.3 between every service. Card data never lands in application logs; the tokenizer sits in front of the write path.
Keys live in a hardware module under dual control. Rotation runs quarterly and on demand; every use is logged with the service that requested it.
Each customer holds a separate database schema and its own encryption context. A query cannot reach across tenants even if the application layer is wrong.
Production access is time-boxed and approved by someone who is not the requester. Sessions record what was read, not only who connected.
Anomaly rules watch authorization patterns, payout destinations and administrative actions. Alerts carry the query that produced them so the on-call engineer starts from evidence.
Restores are rehearsed against production-shaped data every quarter, and the timing is published. A drill that is never run is a plan, not a control.
Connectors are maintained, versioned and monitored like any other part of the platform. When a partner changes a field, the change log says so before your job fails.
Read across a row to see what changes between plans. Everything listed is included at the stated rate; there is no separate charge for support, sandbox access or the audit reports.
No minimum. One entity.
One entity, one record. Clearing, disputes and a daily payout, with the bank leg reconciled for you and the rest left where you can see it.
Start on Ledger
From $40k monthly volume.
Scheme and FX legs reconcile alongside the bank file, payouts follow rules instead of a clock, and the record can sit in the EU or the US.
Move to Clearing
Committed volume, annual term.
Custom sources, treasury sweeps, residency you choose and an engineer whose name you know before the first incident.
Talk to the desk| Capability | Ledger 0.28% + $0.14 | Clearing 0.19% + $0.09 | Enterprise Negotiated |
|---|---|---|---|
| Payment clearing and disputes | Included | Included | Included |
| Automated reconciliation | Bank files only | Bank, scheme and FX | Bank, scheme, FX and custom sources |
| Entities and sub-accounts | 1 entity | Up to 12 | Unlimited |
| Payout scheduling | Daily | Rule-based, per entity | Rule-based, with treasury sweeps |
| Data residency choice | — | EU or US | EU, US, APAC or dedicated |
| Audit reports and evidence pack | On request | Included | Included |
| Support response | Next business day | 4 hours | 1 hour, named engineer |
| Sandbox environments | 1 | 3 | Unlimited |
Bank files alone stop being enough the week a second scheme goes live. Ledger will still balance the bank leg and hand you the card leg.
Marketplace · two schemes · sample
Negotiated is not a hidden tier. Send us a month of settlement volume and the rails you run on, and we price against those instead of a bracket. Committed volume, an annual term, an engineer with a name.
sales@tessen.exampleSix to ten weeks for a single entity, longer where historical balances need to be carried across. The first two weeks run in parallel with your existing processor so you can compare both ledgers on live traffic before switching.
You choose the region at account creation and it does not move afterwards. Backups stay in the same region. Sub-processors and their locations are listed in the processor register, which is versioned and dated.
You export the full ledger in the same format the reporting API returns, including the authorization detail behind every entry. Export stays available for ninety days after termination, then the data is destroyed and a certificate is issued.
Authorization fails over between regions without operator action. Clearing and reporting queue and replay in order, so nothing is lost and nothing is double-posted. Incident notes are published with a timeline rather than a summary.
Yes. Tessen routes to acquirers you already hold contracts with and reconciles their settlement files alongside its own. Several customers run it purely as the ledger layer over existing processing relationships.
Scheme and interchange costs pass through at cost with the breakdown attached to each settlement. Everything Tessen charges for is in the table above. Implementation is quoted once, before the contract, and does not change after signature.
Send a month of settlement files and we will run them through a sandbox ledger before the call. You get the reconciliation result either way, whether or not you go further.