Proven Results Across Fraud Detection, Data Analytics & Enterprise Support
Real engagements, real outcomes — from AI-powered identity verification protecting federal student aid to 3rd-line escalation support keeping legacy enterprise systems running.
Cerberus ID: Stopping Ghost Student Financial Aid Fraud
The challenge. US higher-education institutions are facing a sharp rise in “ghost student” enrollment fraud — fraud rings and bot-driven applicants enrolling using stolen or synthetic identities for the sole purpose of triggering federal financial aid (FAFSA) disbursements. Beyond the direct financial loss, it exposes institutions to serious compliance risk.
Our approach. IT-ISS is the technology architecture partner behind Aletheia Systems’ Cerberus ID, a NIST IAL2-aligned identity verification API. Every applicant is scored with a single confidence score, built from a blended set of behavioral, document, and data-quality features — the higher the score, the stronger the evidence the enrollment is legitimate; the lower, the stronger the fraud signal. Because the system evaluates sensitive applicant data, we treated data minimization as a first-class architectural requirement rather than an afterthought: no PII is retained beyond what a scoring decision strictly requires, and anything that must persist is encrypted at rest.
The result. The scoring service runs on versioned AWS Lambda functions behind a CI/CD pipeline, so if a model update or logic change ever behaves unexpectedly in production, it can be rolled back to the previous known-good version in minutes — not hours — without touching the rest of the system.
AWS Lambda
Versioned CI/CD
Encryption at Rest
PII Minimization
Confidence Scoring
Turning 15,000+ Support Tickets Into a Product: CLEAN_Update
The challenge. Runner Technologies needed to understand what was actually driving its support ticket volume before deciding where to invest engineering effort — years of free-text tickets, no reliable categorization.
Our approach. IT-ISS applied TF-IDF term-weighting and unsupervised clustering across the historical ticket archive, grouping free-text issue descriptions into coherent high-level categories without manual tagging.
The result. The analysis surfaced that 75% of all tickets traced back to installation and update failures — a single, addressable root cause hiding inside years of noisy data. That finding directly shaped the roadmap for CLEAN_Update, an automated install/update reliability solution IT-ISS designed, developed, deployed, and continues to manage for Runner Technologies — now running across their entire customer base.
Text Clustering
Python / Data Analysis
Managed Services
3rd-Line Escalation Support Across Oracle, Sybase & Unix
The challenge. Enterprise clients running legacy Oracle and Sybase database platforms alongside Linux, AIX, and Solaris systems need a senior escalation tier that can be trusted with the incidents 1st- and 2nd-line support can’t resolve — without carrying a full-time specialist on staff for every platform.
Our approach. IT-ISS provides ongoing 3rd-line consulting for Penta Consulting and Linnk Support, acting as the deep-technical escalation point for Oracle and Sybase database issues and Linux/AIX/Solaris operating system incidents across their client base.
The result. Faster resolution of the hardest tickets, direct access to 25+ years of multi-platform DBA and systems experience on demand, and continuity across a mix of legacy and modern infrastructure that’s difficult to staff for internally.
Sybase
Linux
AIX
Solaris
3rd-Line Support
SPAM Escudo: AI Spam Filtering Without the Compliance Risk
The challenge. Contact-form spam filters routinely process and store the exact personal data — names, emails, message content — that GDPR, CCPA, and similar regulations exist to protect. Inconsistent data localization and retention practices are one of the biggest compliance exposures a spam-filtering SaaS can create for its customers.
Our approach. IT-ISS engineered SPAM Escudo’s three-phase detection pipeline — rules-based filtering, embedding similarity, and LLM analysis — with compliance built into the architecture rather than bolted on afterward: submissions are encrypted at rest, PII is minimized and not retained longer than needed to make a spam/not-spam decision, and data handling is designed around GDPR/CCPA localization requirements rather than a one-size-fits-all model.
The result. Two integration paths cover both ends of the market: a lightweight JavaScript snippet for static HTML sites, and a native WordPress plugin — so the same privacy-first filtering pipeline works whether a client’s site is hand-coded or WordPress-based.
Encryption at Rest
LLM Classification
WordPress Plugin
Static HTML Integration
Have a Similar Challenge?
Whether it’s fraud detection, data analysis, database escalation support, or a privacy-first product build — talk directly with the architect who’ll be doing the work.