SignalBrain-OS combines account, device, payment, graph, and policy signals into signed fraud decisions. It catches attacks, explains the evidence, and creates case packets that analysts can act on.
Every attempt entered the same shared Sentinel cross-domain path: domain routing, existing payment safety, fast council, Titan policy, certification, and an auditable outcome. The treatment improved fraud recall without hiding its conversion cost.
Known edge: one mature stolen wallet token remained undetected. Known tradeoff: one legitimate post-recovery purchase was challenged. Powerful controls start with honest failure evidence.
Designed next: a narrow mature-token tier using issuance/recovery provenance, ownership-continuity drift, token→account→device binding, and issuer outcomes. It is explicitly not counted in the result above until provider data and a focused cohort exist.
Inspect the cohort, method, and failures →Fraud is not AML. It is account compromise, payment abuse, identity manipulation, and loss prevention under conversion pressure.
Detect new device, impossible travel, credential reset, phone change, and first high-value transaction in one timeline.
Identify rapid low-value attempts, issuer decline patterns, merchant concentration, and linked IP/device reuse.
Score refund velocity, repeat merchant disputes, policy exploitation, multi-account couponing, and suspicious fulfillment loops.
Trace funds through new beneficiaries, rapid cash-out, shared devices, shared addresses, and clustered counterparty risk.
Combine identity proofing, account age, behavioral inconsistency, phone/email risk, and payment instrument reuse.
Flag urgent narratives, new payees, unusual amounts, remote-access indicators, and sudden behavior change before transfer.
SignalBrain links accounts, cards, devices, IPs, addresses, beneficiaries, merchants, wallets, phone numbers, and payment instruments. A single transaction can inherit risk from its neighborhood.
Every fraud decision returns a compact proof packet: risk score, reason codes, linked entities, model version, policy version, and Merkle proof. It is built for analyst review, dispute handling, and control testing.
{
"decision": "HOLD",
"risk_score": 0.86,
"reason_codes": [
"DEVICE_FANOUT",
"NEW_BENEFICIARY",
"ATO_TIMING"
],
"linked_entities": 7,
"case_packet": "case_31a...",
"certificate_id": "cert_b92...",
"merkle_proof": "proof_6db..."
}{
"domain": "fraud",
"event": {
"type": "payment_attempt",
"customer_id": "cus_8847",
"amount": 1250.00,
"currency": "USD",
"merchant_id": "m_48291",
"device_id": "dev_91a",
"beneficiary_id": "ben_42"
},
"signals": {
"password_reset_minutes_ago": 18,
"new_device": true,
"new_beneficiary": true,
"device_account_count_24h": 18,
"velocity_1h": 5
}
}{
"decision": "HOLD",
"recommended_action": "MANUAL_REVIEW",
"risk_score": 0.86,
"reason_codes": [
"RECENT_CREDENTIAL_RESET",
"NEW_DEVICE",
"DEVICE_FANOUT",
"NEW_BENEFICIARY"
],
"review_sla": "15m",
"case_packet": "case_31a..."
}Deploy beside your payment processor, wallet, identity provider, or case-management stack.