Scope
Extended audit of all POST events logged by the aro_nexusBridge_v2.py module against endpoint https://api.nexpay.sg/v2/external/ingest. Event records were reconstructed from server-side egress logs surviving the firewall purge, cross-referenced against NexPay API gateway records received under international cooperation.
API Call History โ Monthly Breakdown
| Period | Events | Data Volume (est.) | Note |
| Sep 2023 | 42 | 504 MB | First recorded activity โ low-volume test phase |
| Oct 2023 | 67 | 804 MB | Volume increase โ model output batching adjusted |
| Nov 2023 | 58 | 696 MB | Reduced activity โ PaySpark Q3 audit period |
| Dec 2023 | 89 | 1.068 GB | Significant increase post-audit clearance |
| Jan 2024 | 102 | 1.224 GB | NexPay FraudShield v2 enters beta โ correlation noted |
| Feb 2024 | 94 | 1.128 GB | |
| Mar 2024 | 118 | 1.416 GB | |
| Apr 2024 | 127 | 1.524 GB | FATF advisory notice issued against NexPay (04 Apr) |
| May 2024 | 150 | 1.800 GB | Highest monthly volume โ activity ceased upon repo deletion |
| TOTAL | 847 | ~10.16 GB | 8 months, 27 days of sustained operation |
Endpoint Analysis
The receiving endpoint
api.nexpay.sg/v2/external/ingest was examined under the international cooperation request. NexPay's API gateway logs confirm this endpoint was purpose-built to receive data in PaySpark's exact fraud model output schema โ including field names, data types, and transaction ID structure. The endpoint predates the first API call by at least 6 weeks.
This endpoint did not exist for any other client. It was engineered specifically to receive PaySpark's model output. The integration was not opportunistic โ it was designed in advance of the first data transfer.
API Key Lifecycle
The API key
NXP-2024-โโโโโโโโโโโโโโโโ was issued by NexPay on 22 August 2023 โ two weeks before the first recorded transfer event. The key carried a 12-month expiry. It was set to auto-renew. Renewal occurred in August 2024, confirming that the arrangement was intended to be ongoing beyond the period of operation.
The key was issued and set to renew before a single byte of PaySpark data had been transmitted. Both parties anticipated long-term, continuous operation.