Skip to content
CAI
Software that uses CAICheck a score

festinalli/BankMore-Challenge

46.0

Weak · 21 September 2026

5.4k

lines of production code

C#

with Python, TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a simulated instant payment platform (PIX) that processes transactions through a .NET-based API while enforcing security standards like ISO 20022 signing and mTLS. It integrates a real-time machine learning fraud detection service built with PyFlink and XGBoost to score and block suspicious transfers. The platform also provides an operational dashboard and an AI-assisted investigation module for reviewing fraud alerts and case dossiers.

Features

Introduce BankMore Fraud Intelligence investigation MVP with MCP and Ollama integration

Adds a new fraud investigation service that ingests transfer events from Kafka, persists case dossiers in PostgreSQL (with pgvector for semantic search), and generates analyst reports via a local Ollama LLM. The service exposes a FastAPI backend and an MCP server (stdio transport) with six tools for listing alerts, retrieving evidence, fetching behavioral summaries, searching procedures, finding similar reviewed cases, and drafting reports. It supports hybrid lexical/vector retrieval (RRF), pseudonymizes customer data, and integrates with the existing Angular ops dashboard at /ops/investigacao for case review.

investigation · high confidence

Introdução do frontend bancário e do serviço de detecção de fraude ML

A aplicação agora inclui uma interface web completa (Angular) com telas de login, cadastro, dashboard, extrato e transferência, além de definir os contratos de eventos Avro para o fluxo de transferências. Paralelamente, foi introduzido um serviço de Machine Learning (Flask) que serve um modelo XGBoost embutido para scoring de fraude em tempo real, expondo métricas via Prometheus e operando na porta 5003.

(repo-wide) · high confidence

The BankMore.Pix.Api service is now available, exposing endpoints for managing Pix keys, initiating payments, generating static and dynamic QR codes, processing NFC payments, and handling return (MED) and automatic payment (Pix Automático) consents. The API is secured via JWT authentication and integrates with the Central Bank simulator (bacen-sim) using optional mutual TLS for channel security and a separate signing certificate (CERTPIA) for ISO 20022 message signatures as required by Manual Pix v6.0. Additionally, the service includes an inline fraud-checking step before settlement, publishes liquidation events to Kafka for post-transaction analysis, and features a background scheduler to automatically trigger recurring payments based on authorized consents.

src/BankMore.Pix.Api · high confidence

New infrastructure stack for PIX, fraud detection, and intelligence modules

This change introduces a comprehensive local development environment for the BankMore platform. It adds a Docker Compose setup provisioning PostgreSQL 16, Redis, Kafka with Schema Registry, and Flink 1.18 for streaming fraud detection. A new 'intelligence' overlay adds a dedicated Postgres instance and API for fraud investigation using MCP and RAG. The infrastructure also includes a certificate generation script that creates separate mTLS (CERTPIC) and message-signing (CERTPIA) certificates to comply with PIX security standards, along with Prometheus and Grafana configurations for monitoring fraud decisions, ML latency, and transaction throughput.

infra · high confidence

New operational scripts for benchmarking, end-to-end testing, and schema management

Added four new shell scripts to the \scripts/\ directory to support development and testing workflows. \bench.sh\ provides a micro-benchmark for the PyFlink fraud detector, measuring end-to-end latency and throughput for PIX transfers. \e2e-pix.sh\ and \e2e.sh\ introduce comprehensive end-to-end test suites: \e2e-pix.sh\ covers the full PIX lifecycle (key registration, payments, QR codes, MED, automatic PIX, NFC, and Open Finance) with specific assertions for ISO 20022 message persistence and SPI signature enforcement, while \e2e.sh\ validates core transfer behaviors including fraud alerts, burst detection, and ML-based rejections. Additionally, \register-schemas.sh\ automates the registration of Avro schemas into the Confluent Schema Registry with BACKWARD compatibility, serving as documentation and preparation for binary serialization.

scripts · high confidence

Ops fraud monitoring and investigation UI with zoneless change detection

The frontend now includes a live Ops/Fraud monitoring dashboard (ops/fraude) that displays real-time fraud alerts and rejections via Server-Sent Events, showing event details, fraud scores, and latency, along with filters for alert types. Additionally, a new fraud investigation interface (ops/investigacao) allows operators to review cases, view evidence and AI-generated reports, and submit human review outcomes. The application has also migrated to Angular's zoneless change detection (provideZonelessChangeDetection) to reduce bundle size and improve predictability, and the app configuration now uses withInterceptorsFromDi for HTTP interceptors.

frontend · high confidence

Outbox-based reliable delivery with DLQ management and admin controls

The Transferencia API now guarantees reliable message delivery to Kafka via an outbox pattern, replacing the previous direct KafkaFlow producer. A new background relay service polls the database for pending messages and publishes them to Kafka, handling retries and moving failed messages to a Dead Letter Queue (DLQ) after a configurable number of attempts. Admin endpoints are available at /api/admin/outbox to list DLQ items and manually replay them, protected by a shared-secret Bearer token (configured via Outbox\_\_AdminToken) that fails closed if unset. DLQ entries are automatically purged after a configurable retention period. Additionally, messages for the 'transferencia.solicitada' topic are now serialized as Avro binary using the Schema Registry, while other topics remain JSON, and the API exposes Prometheus metrics for monitoring.

src/BankMore.Transferencia.Api · high confidence

Simulated BACEN environment and PIX infrastructure for instant payments

This change introduces the core components for a simulated Central Bank (BACEN) environment and the corresponding PIX payment infrastructure. The \BankMore.BacenSim\ project provides an in-memory DICT (transaction account identifier directory) for key resolution and an SPI (Instant Payment System) settler that processes ISO 20022 pacs.008 payment orders, validates them against the DICT, and returns pacs.002 status reports. It also implements XMLDSig message signing and verification using a dedicated CERTPIA certificate, distinct from the mTLS channel certificate, and enforces IP allowlisting and mTLS authentication for access to the simulated ICOM. On the client side, \BankMore.Pix.Infrastructure\ adds the \DictClient\ for DICT lookups, \FraudeClient\ for ML-based fraud scoring with correct timezone handling, \Pacs008Builder\ for generating payment messages, and \PixEventPublisher\ for publishing liquidation events to Kafka. The \PixRepository\ handles persistent storage of payments and keys using Dapper and PostgreSQL, ensuring atomic accounting entries.

src/BankMore.BacenSim, src/BankMore.Pix.Infrastructure · high confidence

Removals

Removal of legacy Angular dashboard, login, extrato, and transferencia components

The legacy Angular components for the dashboard, login, bank statement (extrato), and transfer (transferencia) views have been deleted from the frontend application. This change removes the existing UI implementation for these core banking features, likely as part of a broader refactoring to a new architecture or framework (referenced as 'BankMore' and 'PyFlink' in commit metadata), preparing the codebase for replacement with new implementations.

(repo-wide) · high confidence

Removal of legacy Avro schemas and frontend template files

The \BankMore\_CaseTop/contracts\ area has removed the Avro schema definitions for \TransferenciaDecidida\ and \TransferenciaSolicitada\, as well as the default Angular frontend template files (\app.html\ and \app.css\). This indicates that the contract definitions for transfer events and the associated starter UI components are no longer maintained in this specific location, likely having been migrated or replaced by other parts of the system.

_BankMore\CaseTop/contracts · high confidence

Behavioural changes

Removal of legacy Dockerfiles, account statement handler, and SHA256 password hashing

This change removes several legacy components from the BankMore codebase: the Dockerfiles for the Conta Corrente API, Tarifa Worker, and Transferencia API services; the ObterExtratoQuery handler responsible for fetching account statements; the PasswordHasher service which previously used SHA256; and the Transferencia domain entity. These deletions reflect a shift away from the previous Docker-based .NET 8 deployment structure, the old statement retrieval logic, and the less secure SHA256 password hashing algorithm, likely in preparation for the new PyFlink-based infrastructure and PBKDF2 security measures mentioned in the commit history.

_BankMore\CaseTop/src · high confidence

Repository restructuring and addition of core infrastructure scaffolding

The project has been promoted to the repository root, moving files from the previous \BankMore\CaseTop\ directory. This change introduces essential scaffolding for local development and operations: a \.env.example\ file defining Postgres, JWT, and Kafka configuration; a \LICENSE\ file adopting the MIT license; and a comprehensive \Makefile\ that automates Docker Compose orchestration, environment setup, database seeding, and end-to-end testing. Additionally, the \BankMoreSolution.sln\ has been updated to include new project references for the PIX bounded context (\BankMore.Pix.\\) and the BacenSim service, while \.gitignore\ rules have been added to exclude large PyFlink wheels and locally generated mTLS certificates.

(repo-wide) · high confidence

Test coverage

Added unit tests for CPF validation, account balance/extract retrieval, and Pix signature compliance; Removed unit tests for account statement and balance handlers.

Dependencies

Dependency updates and infrastructure shifts across .NET and Python services

This change updates dependencies and shifts infrastructure libraries across multiple services. In the .NET services, the Transferencia API and Application layers replace the KafkaFlow library with Confluent.Kafka, Confluent.SchemaRegistry, and Confluent.SchemaRegistry.Serdes.Avro to support binary Avro with Schema Registry, while also upgrading Microsoft.IdentityModel.Tokens and System.IdentityModel.Tokens.Jwt to version 8.15.0 and adding prometheus-net for metrics. The ContaCorrente.Application layer removes Dapper and Npgsql, moving those dependencies to the Infrastructure layer, and adds Newtonsoft.Json. The Tarifas.Worker adds StackExchange.Redis and prometheus-net. New .NET projects (BacenSim, Pix.Api, Pix.Application, Pix.Infrastructure, Pix.Domain) are introduced, targeting .NET 8.0 and using libraries like MediatR, Dapper, Npgsql, Confluent.Kafka, and System.Security.Cryptography.Xml. In Python, new requirements files are added for the investigation service (FastAPI, uvicorn, httpx, pydantic, SQLAlchemy, psycopg, pgvector, confluent-kafka, mcp, pytest, python-dotenv) and the ML service (numpy, pandas, scikit-learn, xgboost, joblib, flask, gunicorn, redis, prometheus-client).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 46 (-0.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 79 → 76 (-3.7)
  • Architecture 79 → 79 (+0.3)
  • Maturity 82 → 82 (+0.0)
  • Readiness 25 → 26 (+1.1)
  • Security 49 → 43 (-5.7)
  • Domain Modelling 98 (new)
  • Event-Driven 100 → 100 (+0.0)
  • Accessibility 80 (new)

Resolved (57)

  • Bounded contexts not declared
  • Critical CVE: [GHSA redacted] (frontend/package-lock.json)
  • Critical CVE: [GHSA redacted] (frontend/package-lock.json)
  • Duplicated block (10 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (12 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (13 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (15 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (7 lines × 2) (src/BankMore.Pix.Infrastructure/PixRepository.cs)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • …and 37 more

New (119)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (frontend/package-lock.json)
  • Critical CVE: [GHSA redacted] (frontend/package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (17 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (25–28 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (28 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • Duplicated block (6 lines × 3) (src/BankMore.Tarifas.Worker/Handlers/RejeicaoConsumer.cs)
  • Duplicated block (7 lines × 2) (src/BankMore.Pix.Infrastructure/PixRepository.cs)
  • Duplicated block (7 lines × 3) (src/BankMore.Tarifas.Worker/Handlers/RejeicaoConsumer.cs)
  • Duplicated block (7–33 lines × 2) (src/BankMore.ContaCorrente.Domain/Entities/ContaCorrente.cs)
  • Duplicated block (8 lines × 2) (src/BankMore.BacenSim/Iso20022/PacsAssinatura.cs)
  • FraudDecider.process_element (cognitive 19) (pyflink/fraud_detector_job.py)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • High CVE: [GHSA redacted] (frontend/package-lock.json)
  • …and 99 more

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • docs/showcase — 1 commit
  • investigation/bankmore_intelligence — 1 commit

Notable commits

  • change: feat(investigation): add MCP and RAG fraud investigation MVP
  • change: feat(investigation): validate live transfer detection through MCP and Ollama

API surface

  • Unchanged — 17 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

festinalli/BankMore-Challenge was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 419828ad5eea7750ae9c1f1f15abcfc4fab7a3bf — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.