The institution's rules
Amounts, merchant categories, countries and time windows your team defines from the console, each amount in its own currency.
Cortex HDC · a technology by UMA Consulting
Cortex is a platform installed in the institution's own data center. Shield scores every card purchase and answers approve, review or decline, with its reasons. Anomalía watches your servers' logs and alerts when something falls outside the normal.
Incoming purchase
Cortex's answer
Review
Fraud prevention
Scores every card authorization in milliseconds and returns the decision with its reasons, for the authorizer and for the analyst.
Discover Shield →Observability
Lightweight agents that learn what a healthy day looks like on each server and alert when something that doesn't fit shows up.
Discover Anomalía →Cortex Shield
The institution's switch sends each purchase to Cortex as JSON, with the ISO 8583 fields it already handles. Cortex scores it and answers with a decision and its reasons. The institution stays in control: Cortex decides, explains and alerts; it does not block cards or touch the core.
The switch sends the authorization. The card number is replaced by a token as soon as it comes in, and the original is discarded.
The institution's rules, usage velocity, that card's habits and a model trained on the bank's own history.
Approve Review Decline with the reasons in plain language. Whatever goes to review reaches the analyst's queue with its case file.
Amounts, merchant categories, countries and time windows your team defines from the console, each amount in its own currency.
Recognizes card testing: many small attempts in a short time, at one merchant or spread across several.
A per-card memory learns with every approved purchase where, how much and how its cardholder buys, without waiting for a retraining.
Trained on the institution's labeled history. It can start in shadow mode: it reports its opinion alongside each decision without changing it.
Signals such as a chip card that comes in by magnetic stripe, or ATM and POS uses that don't fit the cardholder.
Purchases in different countries separated by less time than it takes to travel between them.
When several cards with fraud went through the same merchant, it flags it as a possible origin and lists the exposed cards.
Analyst queue with the case file for each alert. A confirmed chargeback corrects what the card had learned.
Email with validated TLS and webhooks signed under the open Standard Webhooks specification, configurable from the console.
Performance
Shield runs on commodity servers and returns each decision with its reasons. How it performs under your institution's load is not promised from a web page: it is measured on your own hardware.
It answers while the purchase is being authorized. In the lab it does so in a few milliseconds; the time under each institution's load is measured on its server.
Runs on standard x86 processors, in containers on enterprise Linux. Capacity is measured with each institution's hardware and traffic.
Approve, review or decline: every answer carries its written reasons and is recorded, for the analyst and for audit.
It remembers how each cardholder buys and updates with every approved purchase, to tell the usual from the unusual.
How we measure: Today's measurements come from the lab, with simulated purchases, which is why this page publishes no detection or capacity figures. The ones that count are those obtained with each institution's data and hardware, through a procedure that can be repeated.
Cortex Anomalía
A lightweight agent, written in Go, reads each server's logs, learns what they look like on a healthy day and alerts when something that doesn't fit shows up. No regular expressions to write and no indexing everything into a cluster.
Each agent is trained on logs from a normal period and computes its own threshold. There is no fixed limit that is the same for everyone.
It sets aside dates, durations and identifiers that change on every line, and amplifies status codes. Slowness is judged separately, with each service's percentiles: it is detected even when the response is still a 200.
In SLA mode it follows each transaction through its life cycle, measures how long it takes and reconstructs it across the servers it passed through.
If the network goes down, it stores to disk and resends when it is back. Each event arrives at least once and without duplicates.
Each agent generates its own identity and stays pending until an administrator approves it by comparing its fingerprint. The connection is always TLS.
Optionally, it sends HMAC-SHA256 signatures of each line instead of the text. A service can have one or several agents.
Technology
Cortex represents each purchase and each log line as a vector. Comparing two vectors or adding a new one to a memory are simple operations that run on any CPU, with no GPU.
That makes it possible to keep a memory per card and per server that is updated with every event, instead of waiting for the next retraining. In Shield, that memory is one of the layers: the final decision combines rules, velocity, habits and the supervised model, and each one leaves its reason in writing.
Shield does not replace rules or trained models: it combines them with a per-card memory. Each approach covers what the others find hard.
| Criterion | The institution's rules | Model trained on history | Per-card memory |
|---|---|---|---|
| What it needs to start | Someone who knows the fraud and writes the rules | History with the fraud already identified | Each card's first purchases |
| How it keeps up to date | By hand, rule by rule | By retraining every so often | On its own, with every approved purchase |
| What it explains about a decision | Which rule fired | A risk score | Where the purchase departed from that card's habits |
| Where it struggles | Fraud nobody anticipated | Cards with no history and fraud unlike the training data | The cardholder who changes habits, as on a trip |
| In Cortex Shield | Your team defines them from the console | Trained on the institution's history of confirmed fraud | Updated with every approved purchase, with no retraining |
Security
The controls a financial institution asks for, built into the product by design rather than bolted on.
It is installed on the institution's servers. No data leaves it and it does not depend on cloud services.
On arrival it is replaced by an HMAC-SHA256 token with the institution's own key. Expiry date, CVV2, PIN and track data are not stored either: only the result of their verification.
Encryption at rest with the keys in a dedicated vault, designed to rely on the institution's HSM.
The institution builds its own roles from 40 permissions in 16 sections, with least privilege and segregation of duties.
Every change is recorded with who made it, what changed and when.
The institution decides how long each type of data is kept, according to its policy and its regulation.
TLS with certificates issued by the institution's own certificate authority. Console sessions close on their own after inactivity.
If the license expires, Shield keeps scoring purchases and alerting. Nobody is left without detection because of paperwork.
Deployment
Containers that run without administrator privileges on enterprise Linux, with a package that installs without internet access.
An API that receives JSON with the ISO 8583 fields the switch already handles. On the server side, one agent per service.
Because Cortex recommends and the institution decides, it can run alongside the current authorization and be measured with your own data before it influences anything.
Fraud analysts, operations and administrators work in the same web console, each with what their role allows.
Frequently asked questions
No. It returns a recommendation with its reasons and the institution's authorizer decides what to do with it. Cortex does not touch the core or change the status of any card.
No. Everything runs on the institution's servers and the card number is replaced by a token as soon as it arrives.
For Shield, the switch sends each authorization as JSON with the ISO 8583 fields. For Anomalía, install an agent on each server you want to watch and train it on logs from a normal period.
No. It runs on standard processors, with no GPU, on enterprise Linux.
In two ways. Each card has a memory that is updated with every approved purchase. Separately, the supervised model is trained on the institution's own history of confirmed fraud, and can first run in shadow mode.
Yes. Since the final decision belongs to the institution, Cortex can run in parallel with the current authorization and be measured with your own data before its answer is used.
Who is behind it
UMA Consulting is a Peruvian consulting, technology and innovation firm, with more than nine years developing software, artificial intelligence, infrastructure and cybersecurity for banking and financial services, mining and energy, telecommunications, education and the public sector.
About UMA Consulting →Contact
Tell us what your institution needs and we will arrange a demo.