live on aws · real households on soak

Nothing harmful
gets past.

Forward the message. Agents verify the claims, walk the threat graph, and only a real decision reaches a human, with evidence.

decision queue● live
scamKotak claimed but link sits on spoof domain kotak.bank.inpapa
suspiciousLoan-bait with unverifiable URL shortener; gated, not guessedbhai
safeOfficial courier link verified; COD note has no collectable handlepapa

An investigation desk, not a chatbot.

It reads the message like an analyst

Triage on Bedrock Nova scores urgency across Hinglish scam scripts, authority impersonation, UPI collect abuse, and the quiet ones that must never wake a guardian.

PASS / FAIL, per claim
It checks the claim, not the vibe

Issuer registries and a curated trusted-service tier adjudicate every brand claim. kotak.bank.in fails. bluedart.com passes. Evidence, not vibes.

HMAC-SHA256, never reversible
It remembers attackers across families

Phone, VPA, and UTR references cross into the graph as keyed HMAC hashes. A mule account seen by one household raises taint for every other household.

It knows when to shut up

The graduated silence law: most messages are handled with zero sound. Gray bands get a calm hold-off, never an accusation. Only hard evidence escalates with a court-grade bundle.

Two messages. One difference you cannot see. The gate can.

escalated, with evidence

“Sent Rs.349 from Kotak Bank AC X3047 to navircbpmobilerec.cf@axisbank. Not you, kotak.com/KBANKT/Fraud”

Link on the bank's genuine surface. No hard fail. Conservative gate, guardian sees evidence, member holds. Correct.

caught as scam

“Sent Rs.7.00 from Kotak Bank A/c X3047. Not done by you? Tap kotak.bank.in/KBANKT/Fraud”

Spoof domain outside the registry. Hard fail. SCAM verdict, guardian notified, member warned. Caught.

0
adversarial dev cases
0.00
precision, CI [0.989, 1.0]
0.0%
false-gate after calibration
$0.00000
spend per investigation

The doctrine is silence. Most weeks the best thing it does is nothing at all.