Fraud Intelligence Platform

Stop fraud before a transaction is executed.

Detection · Analysis · Reports

Caspix integrates into your authorization step — before any transaction is approved. A single API call returns a decision in under 200ms, verified against live Safaricom and Airtel Kenya network intelligence. Every alert that comes through has a complete analysis workflow behind it.

Built for institutions across

Tier-1 BanksTier-2 BanksTier-3 BanksMicrofinance Institutions

Built by practitioners with direct fraud operations experience at Kenyan financial institutions.

Fraud is quicker than the available controls

Losses often surface long after funds have already moved.

72 hrs

Average detection time without automated monitoring

Delayed detection increases financial and evidentiary loss.

34%

Losses associated with internal fraud and collusion

Access-based fraud requires behavior-aware monitoring of staff activity.

60%

False-positive rate in untuned systems

Alert noise burns analyst time and masks genuine high-risk activity.

Based on ACFE Global Fraud Study data and sector estimates from East African financial institutions.

What makes Caspix different

Where Caspix invests differently

01

Block before funds move

Most fraud systems generate an alert after a transaction has settled and the money is already gone. Caspix integrates into your authorization step before the transaction is approved. A single API call returns a decision in under 200 milliseconds. If Caspix is unreachable for any reason, the transaction proceeds normally.

CRITICAL
BLOCK
HIGH
REVIEW
MEDIUM
ALLOW + LOG
LOW
ALLOW
See pre-authorization →
02

Verified against the live network

When a transaction involves a mobile-linked account, Caspix queries SIM swap history and subscriber status directly with Safaricom and Airtel Kenya and not batch check against a static database before returning a score. A live query, in the same pipeline pass that evaluates every transaction so that a SIM swap confirmed an hour ago is caught before the funds are spent.

Safaricom M-PesaSIM Swap API
Airtel KenyaSubscriber KYC API
See telco verification →
03

The full analysis in plain English

An analyst types a question about a transaction, a phone number, a pattern across accounts, or an open case and receives a structured analysis drawn from live platform data. SIM swap history, linked accounts, recent alerts, and risk signal attribution all in seconds, without building a query or navigating multiple dashboards. Every frontline analyst has the same capability as the most technically skilled member of your team.

› Show me what is unusual about 0712 456 789 in the last 10 days

3 alerts. Two transactions between 01:20–03:47 EAT — outside the account's 14-month activity window. Safaricom SIM swap confirmed 9 days ago...

See the Copilot →
Live network verification

Confirmed directly with Safaricom and Airtel Kenya at the moment of scoring

Every mobile transaction triggers a direct network query before a score is returned. This is not a cached record from a third-party database. The network's own answer, in real time.

Safaricom M-PesaAirtel Kenya

Eleven capabilities in one analysis environment

Pre-authorization scoring, real-time detection, autonomous analysis agents, plain-English Copilot, and reporting connected in a single workflow.

Pre-Authorization Scoring

Query Caspix before a transaction is authorized — ALLOW, CHALLENGE, or BLOCK in under 200ms. Fail-open by design: unavailability never generates a false block.

Transaction Monitoring

Every transaction is analyzed in real time against threshold, velocity, and behavioral controls — across every channel simultaneously.

AI Risk Scoring Engine

Composite 0–100 score from ten concurrent intelligence modules, a five-model weighted ML ensemble, and a live fraud network graph — ALLOW, CHALLENGE, or BLOCK in under 200 milliseconds.

Rule Engine

Create, test, and deploy fraud rules without waiting for engineering cycles.

Alert Analysis Copilot

Analysts describe what they need in plain English and receive analyst-grade responses from live platform data — no SQL, no dashboard navigation.

Autonomous Analysis Agents

Six specialist agents live in production: analysis briefs, rule optimization, insider threat detection, SAR drafting, executive intelligence reporting, and alert triage — all pulling live platform data.

Alert Triage & Case Management

Structured workflows from alert triage through closure with full analyst attribution and SLA tracking.

Entity Intelligence Registry

Known fraudulent accounts, devices, SIMs, and IDs checked on every transaction. One confirmed fraud protects every institution on the platform.

SIEM Integration

Structured event output for Splunk, Wazuh, Elastic, and QRadar.

Regulatory Reporting

Submission-ready case and escalation reporting for CBK and supervisory requirements.

Audit Trail and Forensics

Immutable activity records for formal review, legal process, and regulator examination.

The analysis interface analysts actually use

Frontline analysts should not need database skills to query a suspicious account. They describe what they need, and the Copilot assembles a structured analysis response from live transaction, alert, case, and account data with full source attribution on every claim it makes.

  • Ask about any account, phone number, device, or transaction by name
  • Follow-up questions carry the full conversation context — no need to restate the analysis
  • Every response cites specific data points: account IDs, amounts, dates, signal attributions
  • East African fraud context built in — SIM swap, mobile money, agent banking, insider collusion
See full Copilot capabilities
Alert Analysis Copilot

Show me what is unusual about account 284710 in the last 10 days

Four anomalies flagged. Three transactions occurred between 01:20 and 04:05 EAT — this account shows no prior activity in that window across 14 months of records. Two transfers went to beneficiaries added and used within the same session, totalling KES 87,500. The transacting device does not match any of the five registered handsets on this account. A Safaricom SIM swap was confirmed 9 days ago, 14 hours before the first anomalous transaction.

Draft a Suspicious Activity Report for this account

SAR drafted for account 284710. Subject: mobile banking customer, 14 months active, average monthly outflow KES 28,000, no prior fraud flags. Reportable activity: KES 87,500 in transfers across three sessions following a confirmed SIM swap. Access throughout from an unregistered device. Recommended classification: Unauthorised Account Access — Mobile Channel. Transaction records, device evidence, and SIM swap confirmation attached.
Ask anything about your fraud data...

The journey from a transaction to a closed case

A structured workflow that shortens analysis time and strengthens audit posture.

01

Ingest

Transactions enter through API or batch channels

02

Score

Risk scored across behavioral signals, trained classifiers, and fraud network graph analysis

03

Alert

High-risk activity is routed for analyst review

04

Investigate

Evidence captured, linked, and escalated when needed

05

Report

Cases are closed with full reporting and audit trace

Built around real fraud typologies

Fraud in a Tier-1 bank may not be exactly the same as fraud in a Tier-3 bank or an MFI. Caspix is tuned to institution type and East African operating realities.

Explore Solutions by Institution

Tier-1 Banks

Insider risk, high-volume alert management, mobile banking integration fraud

Tier-2 Banks

SIM swap, agent banking abuse, cross-channel fraud

Tier-3 Banks

Account takeover, mobile banking fraud, insider privilege abuse

Microfinance (Kenya)

Mobile banking fraud, social engineering, internal fraud and collusion

Included for Caspix Clients

Fraud Incident & Intelligence Tracker (FIIT)

Caspix flags fraud. FIIT is where your team takes it from alert to recovered funds — incident tracking, partner validations, hold requests, chargeback management, and recovery analytics. Included with every Caspix subscription.

Security and compliance are built-in controls

RBAC, encrypted audit logs, secrets management, and deployment patterns aligned to CBK regulatory expectations.

RBACTLS 1.3Audit LogsEncrypted at RestOn-Prem Ready

Map the platform to your highest-risk fraud scenarios.

Book a structured demo and we will map the platform to your highest-risk transaction scenarios.