Stop the SIM swap, the takeover and the subscription fraud before the money moves, and let the fraud system make the call.
Bounded rules and models score SIM, subscription, account-takeover, payment, traffic and roaming fraud, and pass the signal to the authorised fraud or transaction-control system with its reasons.
For Fraud, risk, security and digital identity teams protecting customers and revenue.
A password reset, a SIM change and a wallet transfer arrive on one account within an hour.
This sequence as a takeover or not, the value of the signal, and the system that acts on it.
Pass a high-risk signal with its reasons to the transaction-control systemConsidered
Refer the account for human follow-upConsidered
Suppress the signal, where the customer verified through a held channelConsidered
No action, where the sequence has a known causeConsidered
Before anything reaches the customer: Signal quality, consent, customer verification and the control system's own policy checks pass.
What would reach them: The control system steps up, pauses or rejects; the customer is told through a channel the attacker does not hold. On SMS, App, Call.
This sequence as a takeover or not, the value of the signal, and the system that acts on it.
A password reset, a SIM change and a wallet transfer arrive on one account within an hour. Each is ordinary on its own.
Pass a high-risk signal with its reasons to the transaction-control system
Refer the account for human follow-up
Suppress the signal, where the customer verified through a held channel
No action, where the sequence has a known cause
What it does
Three things it helps you decide or do.
Detect and prioritise the risk with the reasons attached
SIM, subscription, account takeover, payment, recharge, traffic, roaming, API, SIM box and international revenue share fraud are scored from customer, device and transaction signals, with identity theft detection and KYC verification beside them.
customer_id
account_type
tenure_days
active_products
recharge_30d
usage_30d
revenue_30d
last_contact
consent_status
outcome_label
Pass the signal to the system that acts
The authorised fraud or transaction-control system steps up, pauses or rejects; the decision here is to suppress, refer for human follow-up or do nothing, never to move the money itself.
Offer
service message
reward
channel change
human follow-up
suppress
do nothing
Audit every decision and approval
The decision log, the eligibility snapshot and the approval record are kept for every signal, so a customer who was blocked and a fraud that was missed can both be examined.
Decision log
eligibility snapshot
price/order response
delivery receipt
control assignment
revenue/outcome ledger
The journey
Stop an account takeover before the transfer, and let the fraud system decide
No demonstration is configured for this product yet.
Fraud, risk, security and digital identity teams
Step
What the customer experiences
What the operator does
The momentThe moment that started it.
A password reset, a SIM change and a wallet transfer arrive on one account within an hour.
Reads the event sequence and its timing, device, sim and identity verification signals, consent and customer verification history, the control system's own policy.
The decisionThe decision to be made.
Nothing reaches the customer yet.
Scores the sequence as a takeover risk with its reasons, and passes the signal to the fraud or transaction-control system.
The safeguardsThe conditions that stop it.
Still nothing. No action is sent until every check has passed.
Signal quality, consent, customer verification and the control system's own policy checks pass.
The actionThe action that reaches the customer.
The control system steps up, pauses or rejects; the customer is told through a channel the attacker does not hold. Reaches them on SMS, App, Call, in Kiswahili, English.
Recommends. The system that holds the right confirms, charges or provisions.
When it goes wrongRefusal, failure and recovery.
A customer who replaced a lost phone and moved money the same day is held, and cannot be reached because the notification goes to the new SIM.
The notification goes to a channel the customer held before the change, the hold is lifted on verification, and the case is kept so the score learns the pattern.
The resultThe change it made.
What changed for them is what is counted; nothing else is claimed.
Takeovers stopped before a loss, against legitimate customers wrongly held.
The proofThe proof anyone can check.
Can be answered for, later, from the record.
Event sequence, score and reasons, signal passed, control system's decision, customer notification and outcome.
Nothing has been observed for this product. Every line above is the record's own design intent; measurement begins in a pilot's validate stage, on your systems, with the comparison agreed first.
The business side
The change
Takeovers stopped before a loss, against legitimate customers wrongly held.
Detect and prioritise fraud management risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0252
HeuriTel SIM FraudDecision definitionHT-0253
Detect and prioritise sim fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0253
HeuriTel SIM Swap FraudDecision definitionHT-0254
Return or subscribe to the last SIM-change signal for an authorised number so an enterprise risk policy can step up, pause or reject a sensitive action.
Detect and prioritise subscription fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
Detect and prioritise account takeover prevention risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0256
HeuriTel Payment FraudDecision definitionHT-0257
Detect and prioritise payment fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0257
HeuriTel Recharge FraudDecision definitionHT-0258
Use customer affordability, usage, renewal and margin data to improve recharge fraud while controlling cannibalisation and measuring incremental value.
/d/HT-0258
HeuriTel Traffic FraudDecision definitionHT-0259
Detect and prioritise traffic fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0259
HeuriTel Roaming FraudDecision definitionHT-0260
Detect and prioritise roaming fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0260
HeuriTel API FraudDecision definitionHT-0261
Detect and prioritise api fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
Identify eligible records for customer verification, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
Identify eligible records for device verification, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
Identify eligible records for kyc verification, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
Identify eligible records for consent management, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
/d/HT-0265
HeuriTel AI ComplianceDecision definitionHT-0266
Identify eligible records for ai compliance, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
/d/HT-0266
HeuriTel Decision AuditDecision definitionHT-0267
Identify eligible records for decision audit, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
Identify eligible records for approval management, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
/d/HT-0268
HeuriTel SIM Box FraudDecision definitionHT-0269
Detect and prioritise sim box fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0269
HeuriTel International Revenue Share FraudDecision definitionHT-0270
Detect and prioritise international revenue share fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
Detect and prioritise identity theft detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
Detect and prioritise mule account detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
Detect and prioritise promo abuse detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0273
HeuriTel Dealer FraudDecision definitionHT-0274
Detect and prioritise dealer fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.
/d/HT-0274
HeuriTel Social Engineering RiskDecision definitionHT-0275
Identify eligible records for social engineering risk, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.
Four stages, and what has to be true before the next one starts.
12-16 weeks to pilot; 2-4 additional weeks per market after reusable interfaces exist. A team of 8 roles, named in the record rather than promised.
01
Scope
One use case, one value unit and a denominator finance has agreed to. Without these there is nothing a later result can be compared against.
Confirm value unit
select use case
baseline denominator
02
Connect
The attributes mapped from your systems, and the decision and outcome interfaces working in both directions.
map attributes
integrate decision and outcome APIs
03
Validate
Eligibility agreed, a dry run with nothing sent, then a controlled pilot with a holdout that is actually respected.
build eligibility
dry run
controlled pilot
04
Operate
The live loop: decide, check, execute through your systems, capture what came back, and measure against the control.
Ingest
qualify
score
apply limits/consent
assign control
execute approved action
capture delivery and business outcome
monitor/retrain
Who does it. 1 telecom product lead · 1 CVM specialist · 1 data engineer · 1 ML engineer · 1 integration developer · 0.5 QA · 0.5 DevSecOps · 1 deployment coordinator
Four states are tracked, and each is assessed against your systems.
Readiness is assessed per client: nothing is offered as pilot-ready until your data, your integration and your authority have been checked.
Readiness
Needs client data and integration review
The client’s data and integration position.Runtime / build state
Target product definition
What exists as running software.Surface state
Not audited
Whether this product shows the entry anywhere.Client status
Not assessed
Where a named client has reached.
Next steps from here.
24 definitions sit under Fraud, Identity & Customer Protection. The two links that matter first are the journey this page describes, and the rest of the family it belongs to.
What can the network itself do for a bank, an agency or a planner?
CAMARA & GSMA Open Gateway APIsLet a bank or an app verify a number, a SIM change or a location from the network itself, with the customer's consent recorded.
Network Investment & IntelligencePut the next site, upgrade or fibre route where the customers and the revenue are, and show afterwards what the money did.