Platform Overview

From first signal to closed case

Eleven integrated modules span the full fraud control lifecycle — pre-authorization scoring, real-time detection, autonomous investigation, regulatory reporting, and structured alert analysis, connected in a single operational environment.

Pre-Authorization Scoring

Block fraud before settlement — not after the fact

Core banking systems can query Caspix before authorizing a transaction. A single API call returns a fraud decision — ALLOW, CHALLENGE, or BLOCK — in under 200 milliseconds, giving the bank the option to act before funds move. The channel is fail-open by design: if Caspix is unreachable for any reason, the transaction proceeds normally. Service continuity is never held hostage to a fraud check.

REST APISub-200ms response targetFail-open guaranteeFull audit log

Capabilities

  • Synchronous decision — ALLOW, CHALLENGE, or BLOCK — returned in under 200 milliseconds
  • Response includes composite risk score, risk tier, and the dominant contributing signals for analyst traceability
  • Fail-open by design: system unavailability never generates a false block or disrupts bank operations
  • Pre-check against the full Entity Intelligence Registry before scoring — confirmed fraudsters are caught before any rule fires
  • REST API with no session state — integrates cleanly into any core banking authorization flow
  • Every pre-authorization query is logged with a full audit trail regardless of the outcome returned

Transaction Monitoring

Real-time visibility across every transaction channel

Every debit, credit, transfer, and reversal passes through Caspix monitoring controls before or as it posts. Configurable thresholds, velocity limits, and behavioral baselines surface suspicious activity immediately.

REST API ingestBatch CSV/JSONWebhook alert pushSplunk/Wazuh log output

Capabilities

  • Real-time transaction ingestion via REST API or batch file upload
  • Per-account and per-product velocity controls (daily, weekly, rolling windows)
  • Threshold alerts with configurable severity tiers (Low, Medium, High, Critical)
  • Cross-channel correlation for mobile, agent, and teller activity
  • Time-of-day and geographic anomaly detection
  • Historical baseline comparison per account profile
  • Alert suppression rules to reduce expected operational noise

AI Risk Scoring Engine

Ten intelligence modules and a five-model ensemble, evaluated in parallel on every transaction

Every transaction passes through ten concurrent intelligence modules — covering device DNA, transaction patterns, card signals, PesaLink intelligence, user behavioral space, biometric markers, activity mapping, network intelligence, graph relationships, and sequence detection. Their outputs feed a five-model weighted ensemble (XGBoost classifier, fraud classifier, anomaly detector, isolation score, and graph score) that produces a single composite 0–100 risk score. Every decision carries full LIME-style signal attribution and an analyst-readable explanation — written to the audit log and visible in the case management interface.

10-module parallel pipelineFive-model weighted ensembleLive Neo4j graphLive telco enrichment

Capabilities

  • Ten concurrent intelligence modules evaluate every transaction in parallel: device DNA, transaction patterns, card signals, PesaLink intelligence, user behavioral space, biometric markers, activity mapping, network intelligence, graph analysis, and sequence detection
  • Five-model weighted ensemble combines XGBoost classifier, fraud classifier, anomaly detector, isolation score, and graph score into a single composite 0–100 risk score
  • Automated decision tiers — ALLOW, CHALLENGE, or BLOCK — returned in under 200 milliseconds with full signal attribution
  • Per-account behavioral anomaly detection with baselines updated automatically after every transaction scored
  • Fraud network graph analysis powered by a live Neo4j knowledge graph: fraud rings, mule patterns, insider-account linkages, and multi-hop fund tracing
  • Live telco enrichment: SIM swap history and subscriber status queried directly from Safaricom and Airtel Kenya within the scoring pipeline, before authorization
  • Behavioral biometric scoring: keystroke dynamics, touch pressure, and mouse trajectory analyzed passively for continuous session identity assurance
  • LIME-style feature attribution surfaces the dominant contributors to every score outcome — analyst-visible and written to the structured audit log
  • Champion/challenger model evaluation, shadow scoring, and drift monitoring run continuously — surfacing degradation before it affects detection quality
  • Fairness evaluation wired as a model promotion gate: no model reaches production without a documented channel and telco network parity assessment
  • Model cards required before any model can advance to champion status, satisfying SR 11-7 and CBK TRM model inventory obligations

Rule Engine

Detection logic you control without waiting for a dev sprint

Fraud analysts can write, test, activate, and retire detection rules directly in the interface. Rules are versioned, attributed, and reversible.

YAML rule definitionREST management APISimulation sandboxAudit log per change

Capabilities

  • Visual rule builder with condition chains (AND, OR, NOT)
  • Support for amount, frequency, channel, account type, geography, and time conditions
  • Rule simulation against historical transaction data before activation
  • Version history and rollback for every rule
  • Rule attribution to named analysts
  • Shadow mode for safe rule testing before production activation
  • Rule performance metrics (hit rate, true positive, false positive)

Alert Analysis Copilot

Natural language queries across your entire fraud intelligence platform

The Alert Analysis Copilot is a natural language analysis interface built for fraud analysts. Instead of building queries or navigating dashboards, analysts describe what they need and the Copilot assembles an analyst-grade response from live platform data — transactions, alerts, cases, account history, and network relationships.

Natural language interfaceLive data groundingSSE streaming responsesRole-based access

Capabilities

  • Plain English interface — no SQL or technical skills required for frontline analysts
  • Conversation context is maintained across a session — analysts can ask follow-up questions without restating the analysis thread
  • Phone number lookups automatically retrieve all linked accounts and recent alerts, not just the number itself
  • Live data retrieval from transactions, alerts, cases, account history, and network relationships
  • Streamed responses for long analysis sessions — grounded in current platform data, not static reports
  • East African fraud context built in: SIM swap, mobile money fraud, agent banking, insider collusion
  • Every response cites specific data points — account IDs, amounts, dates, signal attributions
  • Suggested queries driven by currently active high-priority alerts — always relevant to what is happening right now

Autonomous Analysis Agents

Six production agents that analyse, optimise, report, and triage without waiting for an analyst to start

A layer of six autonomous AI agents handles specific analysis and operational tasks on demand — from assembling full analysis briefs in seconds to drafting regulator-ready Suspicious Activity Reports. Every agent pulls live data from across the platform and returns structured, analyst-ready outputs grounded in current case evidence. All six agents are live in production today, not on a roadmap.

Six agents live in productionLive data groundingCBK/FRC-aligned SAR outputRole-gated access

Capabilities

  • Fraud Analysis Agent: pulls transaction history, device history, graph signals, and alert history for any assigned alert, traces the attack sequence, and returns a structured analysis narrative with recommended next actions
  • Rule Optimization Agent: analyzes false positive and false negative patterns across the detection engine and surfaces concrete rule tuning recommendations to sharpen signal accuracy over time
  • Insider Threat Agent: detects staff-to-account collusion through behavioral pattern analysis and network relationship mapping across the twelve built-in insider threat rule categories
  • SAR Drafting Agent: drafts CBK- and FRC-aligned Suspicious Activity Reports for any case where confirmed fraud exposure meets or exceeds KES 500,000 — pre-populated with case evidence, timeline, and regulatory narrative
  • Executive Intelligence Agent: generates daily institutional fraud posture summaries covering 24-hour alert volumes, top fraud vectors, financial exposure, seven-day trend analysis, and emerging threat patterns — automatically cached and refreshed
  • Alert Triage Agent: auto-prioritizes and routes incoming alerts by risk score, account history, and analyst queue depth, with a minimum five-percent sample of auto-suppressed alerts routed to a human review queue and every suppression decision written to the audit trail

Alert Triage & Case Management

From flagged alert to closed case in a structured, auditable workflow

Flagged alerts enter a priority triage queue. Analysts claim cases, log actions, escalate, or close with full attribution, timelines, and audit trail.

REST case APIFile attachment supportPDF report exportRole-based case access

Capabilities

  • Alert triage queue with priority ranking
  • Case assignment to analyst or team queues
  • Audit log across account history, transactions, and analyst actions
  • Structured note-taking with mandatory closure fields
  • Escalation workflow to senior analyst or fraud risk manager
  • Case linking across accounts, transactions, and actors
  • SLA tracking with breach notifications
  • Case export as a formal PDF case report

Entity Intelligence Registry

Known fraudsters blocked before they transact — across 11 entity types

A persistent registry of confirmed fraudulent entities checked against every incoming transaction in real time. Accounts, devices, SIMs, identity documents, and more — the moment a match is found, the transaction is flagged or blocked before any rule fires. Cross-institution attribution means one bank's confirmed fraud protects every other institution on the platform.

11 entity typesBulk CSV/Excel importCross-institution attributionRole-gated management

Capabilities

  • 11 entity types: account, phone number, national ID, passport, device ID, device fingerprint, IMSI, ATM ID, terminal ID, merchant ID, email
  • Real-time lookup integrated into every transaction score pass — no rule configuration required
  • Per-entry risk score (1–100), fraud type classification, and source case ID linkage
  • Cross-institution intelligence: entries carry source institution attribution for shared threat awareness
  • Bulk import via CSV or Excel — onboard historical fraud data on deployment day
  • Analyst-controlled additions with role-gated removals and full audit trail
  • Duplicate prevention with soft-delete for inactive entries — full history preserved

SIEM Integration

Structured logs for your existing SOC and monitoring stack

Caspix emits structured JSON events for transaction, alert, case, rule, auth, and admin actions, ready for SIEM ingestion.

Splunk HECWazuh/Elastic FilebeatQRadar SyslogCEF-aligned schema

Capabilities

  • JSON event schema with consistent field mapping
  • Event categories for transaction, alert, case, rule, auth, and admin
  • Severity classification aligned to CEF concepts
  • Syslog forwarding for on-prem SIEM collectors
  • HTTP event collector output for Splunk
  • Filebeat-compatible output for Wazuh/Elastic
  • Configurable retention and rotation
  • Synthetic test event generation for onboarding validation

Regulatory Reporting

Submission-ready outputs for management and regulators

Case outcomes can generate structured reports covering timeline, evidence, conclusion, and action recommendations.

PDF generationCSV exportScheduled deliveryFIU-aligned templates

Capabilities

  • Case analysis report (PDF) from case data
  • Suspicious Transaction Report templates aligned to FIU patterns
  • Aggregate fraud statistics dashboards
  • Alert-to-case conversion and false positive metrics
  • Time-to-detect and time-to-close reporting
  • Loss quantification by channel and fraud type
  • Scheduled report delivery by email or shared folders

Audit Trail and Forensics

Tamper-aware records for every user and system action

The audit layer captures authenticated activity with integrity markers for forensic review and supervisory examination.

Hash-chained logsTamper detection alertsCSV/JSON exportConfigurable retention

Capabilities

  • Append-only audit records with strict mutation controls
  • Coverage for logins, access failures, role changes, case actions, and rule edits
  • Analyst attribution for notes, dispositions, and escalations
  • Integrity hash chain checks for tamper detection
  • Filterable search by user, entity, date, and action
  • Export subsets for regulator or legal workflows
  • Retention policy enforcement with secure archive

Deployment flexibility

Caspix can run on-premises, in private cloud, or as managed hosted infrastructure. Containerized deployment supports restricted-network environments.

On-PremisesPrivate CloudManaged HostedAir-Gapped CompatibleDocker/Kubernetes

Want to test it against your fraud scenarios?

We run structured walkthroughs aligned to your institution type, current controls, and high-risk transaction paths.