Milliseconds, an app on someone else's phone, credentials that were correct. In broking, the question is never whether the order was valid — it is whether the client placed it.
Correct credentials, a valid TOTP, orders inside every risk limit. The client watches it happen and cannot stop it.
A risk engine can only judge the order it is given. It cannot see whose hand is on the phone.
Pick a surface to read the exposure in the terms your risk and compliance committee uses.
Sense does not price risk. It tells your OMS and risk stack whether the order in front of it came from your client, on a device they own, in a session nobody else was driving.
Open a line to read the mechanism and the control that answers it. Most of these arrive as client complaints, arbitration and regulatory correspondence rather than as a fraud number.
SEBI's CSCRF holds the regulated entity answerable for the security of every client-facing app and API it operates, its own and its vendors'. When the exchange audit arrives, the device and session evidence is already assembled, per order, per release.
A device-and-session assessment across your trading app, web terminal and API clients — remote-control sessions, device reuse across UCCs, tampered builds, emulator clusters, credential-stuffing pressure on login and scraper load on market-data endpoints.