Fraud decisions your systems can defend.
A controlled fraud decisioning layer for fintech operations — evaluating event context against governed policy, preserving the reasoning, and routing uncertainty to review rather than a bare score. Shield is in pilot and enabled per account on request.
Pilot. Shield is enabled per account on request; it is not open to self-serve signup. The illustration does not represent a public endpoint or a live customer event.
01 · Event
transfer.created
€2,450
new beneficiary · from device
02 · Signals
- NEW_DEVICE
- NEW_BENEFICIARY
- HIGH_VALUE
03 · Policy
ATO sequence
tenant policy · v4
Shadow mode04 · Decision
Review required
Three contextual signals matched policy. The customer keeps the response.
05 · Evidence
FC-20481
e7a3…92c1 sealed
Observe the signal. Decide with policy. Prove it later.
Shield keeps the three jobs a fraud decision needs distinct: read the event context, resolve it against policy you own, and keep the evidence. No single signal and no bare score is the whole story.
01Observe
Every event carries context: device, beneficiary, velocity, value. Shield reads the signals that describe what changed, without acting on any of them alone.
02Decide
Tenant-owned policy resolves the signals into an explicit outcome: approve, review or block. Rules run in shadow first, so nothing enforces until you promote it.
if velocity_10m > 5 and payee_age < 1d → REVIEW
03Prove
Every decision seals a Fraud Capsule (event, signals, rule, outcome and a content-integrity hash) so the reasoning survives long after the moment.
Illustrative event · not live telemetry.
Every event resolves to one explicit outcome.
Transfer, withdrawal, payout or session action — the same three outcomes apply. Shield records what its rules evaluated, not just a number.
Every decision leaves a record.
One self-contained evidence record — the event, the signals, the rules, the outcome and a content-integrity hash — sealed at the moment of decision.
- Event
- evt_illustrative_4800 · transfer · €4,800
- Signals
- new device · new recipient · high value
- Rules
- ATO sequence · velocity policy
- Decision
- REVIEW REQUIRED
- Policy
- tenant policy v1
- Sealed
- 12:04:31 UTC
- Integrity
- sha256 4b1d…a7c9
Illustrative record · not a live customer event.
The patterns policy is built to catch.
Account takeover
new device · new recipient · velocity
Card testing
many small auths · rising decline rate
Payout anomaly
first-time payee · 3× baseline value
Fraud and compliance decisions stay separate.
Shield can read bounded compliance context where configured — but a fraud result never becomes a sanctions result, and the reverse never happens either.
Shield
Fraud decisions
Event context, tenant policy, approve / review / block.
Screening
Compliance decisions
Sanctions, PEP and watchlist coverage, kept distinct.
How a Shield pilot runs.
Shield is enabled per account during the pilot. Every pilot starts with evidence and keeps any change to active policy explicit.
- 01
Shadow
Observe rules and recommendations with no enforcement outcome. Nothing changes for the customer.
- 02
Review
Evaluate the evidence and tune tenant-owned policy with the operating team.
- 03
Active policy
Promote approved rules to active mode, with the customer-owned response kept explicit.
Request Shield pilot access.
Shield is in pilot. Bring an event model and the decision you need to control, and we will tell you whether a pilot is likely to fit.