Cortex HDC · a technology by UMA Consulting

Catch fraud at authorization and failures before anyone notices.

Cortex is a platform installed in the institution's own data center. Shield scores every card purchase and answers approve, review or decline, with its reasons. Anomalía watches your servers' logs and alerts when something falls outside the normal.

  • On-premise
  • Every decision explained
  • The card number is never stored
Cortex Shield · scoring

Incoming purchase

Card
tok_7f3a…c91e
Amount
S/ 1,850.00
Merchant
Electronics · Lima
Entry
Magnetic stripe

Cortex's answer

Review

  • The card has a chip, but the purchase came in by magnetic stripe
  • Amount far above this card's habit
  • First purchase by this card at this merchant
Illustrative example, with made-up data.

Cortex Shield

Card fraud prevention, at the moment of authorization

The institution's switch sends each purchase to Cortex as JSON, with the ISO 8583 fields it already handles. Cortex scores it and answers with a decision and its reasons. The institution stays in control: Cortex decides, explains and alerts; it does not block cards or touch the core.

  1. 1

    The purchase arrives

    The switch sends the authorization. The card number is replaced by a token as soon as it comes in, and the original is discarded.

  2. 2

    It is scored in layers

    The institution's rules, usage velocity, that card's habits and a model trained on the bank's own history.

  3. 3

    The answer goes back

    Approve Review Decline with the reasons in plain language. Whatever goes to review reaches the analyst's queue with its case file.

What it looks at in every purchase

The institution's rules

Amounts, merchant categories, countries and time windows your team defines from the console, each amount in its own currency.

Velocity and bursts

Recognizes card testing: many small attempts in a short time, at one merchant or spread across several.

Each card's habits

A per-card memory learns with every approved purchase where, how much and how its cardholder buys, without waiting for a retraining.

Your own supervised model

Trained on the institution's labeled history. It can start in shadow mode: it reports its opinion alongside each decision without changing it.

Card present and cloning

Signals such as a chip card that comes in by magnetic stripe, or ATM and POS uses that don't fit the cardholder.

Impossible travel

Purchases in different countries separated by less time than it takes to travel between them.

Common point of purchase

When several cards with fraud went through the same merchant, it flags it as a possible origin and lists the exposed cards.

Cases and chargebacks

Analyst queue with the case file for each alert. A confirmed chargeback corrects what the card had learned.

Alerts

Email with validated TLS and webhooks signed under the open Standard Webhooks specification, configurable from the console.

Performance

Built to answer while the purchase is being authorized

Shield runs on commodity servers and returns each decision with its reasons. How it performs under your institution's load is not promised from a web page: it is measured on your own hardware.

A few ms Response time

It answers while the purchase is being authorized. In the lab it does so in a few milliseconds; the time under each institution's load is measured on its server.

No GPU Commodity servers

Runs on standard x86 processors, in containers on enterprise Linux. Capacity is measured with each institution's hardware and traffic.

Reasons In every decision

Approve, review or decline: every answer carries its written reasons and is recorded, for the analyst and for audit.

Habits A memory per card

It remembers how each cardholder buys and updates with every approved purchase, to tell the usual from the unusual.

How we measure: Today's measurements come from the lab, with simulated purchases, which is why this page publishes no detection or capacity figures. The ones that count are those obtained with each institution's data and hardware, through a procedure that can be repeated.

Cortex Anomalía

Observability that learns what normal looks like

A lightweight agent, written in Go, reads each server's logs, learns what they look like on a healthy day and alerts when something that doesn't fit shows up. No regular expressions to write and no indexing everything into a cluster.

  • Learns the healthy state

    Each agent is trained on logs from a normal period and computes its own threshold. There is no fixed limit that is the same for everyone.

  • Ignores the noise, highlights what matters

    It sets aside dates, durations and identifiers that change on every line, and amplifies status codes. Slowness is judged separately, with each service's percentiles: it is detected even when the response is still a 200.

  • End-to-end transactions

    In SLA mode it follows each transaction through its life cycle, measures how long it takes and reconstructs it across the servers it passed through.

  • Doesn't lose what it detects

    If the network goes down, it stores to disk and resends when it is back. Each event arrives at least once and without duplicates.

  • Enrollment with approval

    Each agent generates its own identity and stays pending until an administrator approves it by comparing its fingerprint. The connection is always TLS.

  • Private logs

    Optionally, it sends HMAC-SHA256 signatures of each line instead of the text. A service can have one or several agents.

Technology

Hyperdimensional computing, on standard processors

Cortex represents each purchase and each log line as a vector. Comparing two vectors or adding a new one to a memory are simple operations that run on any CPU, with no GPU.

That makes it possible to keep a memory per card and per server that is updated with every event, instead of waiting for the next retraining. In Shield, that memory is one of the layers: the final decision combines rules, velocity, habits and the supervised model, and each one leaves its reason in writing.

  • Continuous learning, purchase by purchase
  • No graphics accelerators or cloud services
  • Every decision arrives with the reasons that support it

Three approaches that complement each other

Shield does not replace rules or trained models: it combines them with a per-card memory. Each approach covers what the others find hard.

Criterion The institution's rules Model trained on history Per-card memory
What it needs to start Someone who knows the fraud and writes the rules History with the fraud already identified Each card's first purchases
How it keeps up to date By hand, rule by rule By retraining every so often On its own, with every approved purchase
What it explains about a decision Which rule fired A risk score Where the purchase departed from that card's habits
Where it struggles Fraud nobody anticipated Cards with no history and fraud unlike the training data The cardholder who changes habits, as on a trip
In Cortex Shield Your team defines them from the console Trained on the institution's history of confirmed fraud Updated with every approved purchase, with no retraining

Security

Designed to pass the security team's review

The controls a financial institution asks for, built into the product by design rather than bolted on.

Everything inside your perimeter

It is installed on the institution's servers. No data leaves it and it does not depend on cloud services.

The card number is not stored

On arrival it is replaced by an HMAC-SHA256 token with the institution's own key. Expiry date, CVV2, PIN and track data are not stored either: only the result of their verification.

Keys under custody

Encryption at rest with the keys in a dedicated vault, designed to rely on the institution's HSM.

Tailored roles

The institution builds its own roles from 40 permissions in 16 sections, with least privilege and segregation of duties.

Audit log

Every change is recorded with who made it, what changed and when.

Configurable retention

The institution decides how long each type of data is kept, according to its policy and its regulation.

Encrypted communication

TLS with certificates issued by the institution's own certificate authority. Console sessions close on their own after inactivity.

Protection doesn't stop on a date

If the license expires, Shield keeps scoring purchases and alerting. Nobody is left without detection because of paperwork.

Deployment

Installed where your data lives

In your data center

Containers that run without administrator privileges on enterprise Linux, with a package that installs without internet access.

Direct integration

An API that receives JSON with the ISO 8583 fields the switch already handles. On the server side, one agent per service.

Start in parallel

Because Cortex recommends and the institution decides, it can run alongside the current authorization and be measured with your own data before it influences anything.

One console for everything

Fraud analysts, operations and administrators work in the same web console, each with what their role allows.

Who it is for

  • Banks and card issuers
  • Processors and transaction switches
  • Credit unions and finance companies
  • Any organization with critical servers to watch

Frequently asked questions

What people usually ask

Does Cortex block cards?

No. It returns a recommendation with its reasons and the institution's authorizer decides what to do with it. Cortex does not touch the core or change the status of any card.

Does data leave the institution?

No. Everything runs on the institution's servers and the card number is replaced by a token as soon as it arrives.

What does it take to connect it?

For Shield, the switch sends each authorization as JSON with the ISO 8583 fields. For Anomalía, install an agent on each server you want to watch and train it on logs from a normal period.

Does it need special hardware?

No. It runs on standard processors, with no GPU, on enterprise Linux.

How does it learn?

In two ways. Each card has a memory that is updated with every approved purchase. Separately, the supervised model is trained on the institution's own history of confirmed fraud, and can first run in shadow mode.

Can it be tried without risk?

Yes. Since the final decision belongs to the institution, Cortex can run in parallel with the current authorization and be measured with your own data before its answer is used.

Who is behind it

Cortex is a technology by UMA Consulting

UMA Consulting is a Peruvian consulting, technology and innovation firm, with more than nine years developing software, artificial intelligence, infrastructure and cybersecurity for banking and financial services, mining and energy, telecommunications, education and the public sector.

About UMA Consulting →

Contact

Let's talk about your case

Tell us what your institution needs and we will arrange a demo.

You are interested in

We use this information only to reply to your request.