SumUp
Software EngineerComplexAug 6, 2026

Enforce credential rejection with fewer false declines

Payment protection rules can be clear in principle and costly at the boundary.

Blocking compromised use and preserving legitimate sales can require different interpretations of the same transaction signals.

I can’t explain a decline to someone when their card worked everywhere else.

Soojin Yamamoto · Independent café owner

Runs a high-turnover café where every declined card can mean a lost sale and an awkward customer interaction.

What pulls against what

  • fraud interception vs. legitimate approval rate
  • fixed compliance deadline vs. exhaustive verification
  • centralized control vs. terminal-context precision
  • machine-ranked evidence vs. human-reviewed policy

What is at stake

A fixed compliance deadline requires a permanent authorization-policy change. The challenge is protecting payment acceptance without turning legitimate sales into declines

Why SumUp

At SumUp, these decisions often matter because a false decline is immediate for a merchant, while a missed control can threaten acceptance continuity.

Written for

Payments security engineerHigh-assurance distributed systems engineerRisk-aware platform engineer

This is the setup. The work is inside.

Running it puts you in the room: the full situation and its constraints, stakeholders who push back in their own words, and the decisions that are yours to make. What you produce becomes a Day One Plan — work you can show someone instead of describing.