Open Source Feedzai Alternatives
A curated collection of the 2 best open source alternatives to Feedzai.
The best open source alternative to Feedzai is Tirreno. If that doesn't suit you, we've compiled a ranked list of other open source Feedzai alternatives to help you find a suitable replacement. Other interesting open source alternative to Feedzai is Marble.
Feedzai alternatives are mainly Fraud Prevention but may also be Threat Detection & Response. Browse these if you want a narrower list of alternatives or looking for a specific functionality of Feedzai.
Self-hosted security framework that watches user activity inside your application to catch account takeover, fraud and abuse.

Most breaches do not arrive through the network perimeter. Tirreno is a security framework that sits inside your product and reads the events it generates, so compromised accounts and application logic abuse surface in the one place firewalls, WAFs and SIEM tools never look.
The application is hand-written PHP backed by PostgreSQL, with few dependencies and a five-minute install. You send events through the API or through one of the trackers for PHP, Python, Node.js and WordPress, and a real-time threat dashboard fills in immediately.
The moving parts are deliberately few.
- Rule engine: risk scores are calculated automatically from preset rules or from ones you write for your own product.
- Single user view: behavior patterns, risk scores, connected identities and an activity timeline for one account.
- Review queue: threshold settings suspend risky accounts automatically or flag them for a human to look at.
- Field audit trail: changes to important fields are tracked, including what changed and when.
- Preset rules: account takeover, credential stuffing, bot detection, multi-accounting and promo abuse ship ready to use.
Requirements are modest. PHP 8.0 to 8.3, PostgreSQL 12 or later, Apache with mod_rewrite, and roughly 3 GB of storage per million events. A Docker Compose command, a Heroku button and a Composer package all work, and a cron entry every ten minutes handles background jobs. It suits SaaS platforms, marketplaces, internal and legacy apps, and air-gapped deployments.
Transaction monitoring and AML screening engine for fintechs and banks that want a detection system they can inspect and change.

Marble monitors transactions and screens customers for fraud and compliance teams that need to see how a decision was reached. It is positioned against Comply Advantage, Actimize and Fiserv, and the complaint it answers is opacity: when scoring is hidden, precision suffers and troubleshooting a detection program becomes guesswork.
The data model is custom and mirrors your own warehouse, connecting to transaction databases, KYC solutions, core banking systems and third-party data providers. That makes Marble an engine on top of systems you already run, not a silo with its own copy of the truth. KYC services are out of scope by design.
The product spans detection through to case closure.
- Transaction monitoring: real time or post trade, with rules tailored to the business rather than a template.
- Screening: customers, companies and payments checked against sanctions, PEP and adverse media lists updated several times a day.
- Continuous monitoring: customers rechecked against current lists without adding manual workload.
- Investigation suite: one case manager for exploring, annotating and acting on alerts.
- Audit trail: searchable, unalterable logs covering detection programs, workflows and case actions.
- Governance: role-based access control, OIDC single sign-on, IP whitelisting and SOC 2 Type II certification.
A quick start runs on Docker and Docker Compose with 4GB of RAM and 10GB of disk, and a full installation guide covers real deployments. Embedded analytics and direct database access serve BI tools, and a licensed edition adds enterprise features, self-hosted or as SaaS. It reports use by over 100 fintechs, banks and crypto exchanges in more than 15 countries.