Capability · Detect

Fraud moves across events. Follow the pattern.

One account looks ordinary. The connected activity tells a different story. SENTR combines event-scoped rules, customer-specific anomaly detection and linked history to help your team investigate increasingly complex fraud.

  • Mapped context across providers and event types
  • Rules, anomaly and policy as complementary layers
  • Monitor evaluates without influencing score

The payment is not always where the attack begins.

Point scores catch obvious declines. Rings, synthetic journeys and cross-event probes slip between systems that never share policy. Analysts spot the pattern late—after loss, after a partner escalation, or after a queue nobody owns.

The commercial question is not “another model.” It is whether detection, decision, investigation and improvement share the same event and entity context.

Illustrative mechanism
One instrument. Eight accounts. A better question.Eight illustrative accounts link to one payment instrument. Inspect timing, merchant context and prior outcomes to distinguish coordinated attempts from legitimate shared use. The links require the identifiers you supply; they do not assume automatic cross-provider card matching.INSTRUMENT REUSEPaymentpm_4c218 ACCOUNTS · 1 INSTRUMENT
One instrument. Eight accounts. A better question.
Read the diagram

Eight illustrative accounts link to one payment instrument. Inspect timing, merchant context and prior outcomes to distinguish coordinated attempts from legitimate shared use. The links require the identifiers you supply; they do not assume automatic cross-provider card matching.

One instrument. Eight accounts. A better question.

Illustrative mechanism. On smaller screens, scroll across the diagram to inspect the labels.

One instrument. Eight accounts. A better question.Eight illustrative accounts link to one payment instrument. Inspect timing, merchant context and prior outcomes to distinguish coordinated attempts from legitimate shared use. The links require the identifiers you supply; they do not assume automatic cross-provider card matching.INSTRUMENT REUSEPaymentpm_4c218 ACCOUNTS · 1 INSTRUMENT

Eight illustrative accounts link to one payment instrument. Inspect timing, merchant context and prior outcomes to distinguish coordinated attempts from legitimate shared use. The links require the identifiers you supply; they do not assume automatic cross-provider card matching.

Connect the signals. Shape the response.

Rule scores and customer-model anomaly scores stay distinct. Decision policies determine the response; action policies trigger the next workflow.

Layered detection anatomy

  1. Mapped events & history Registration, login, payment, payout and related events you supply—with the fields and history you can join.
  2. Rules & lists Rules can contribute scores or return direct decisions. Lists have customer-set influence scores; a match is not automatically a block.
  3. Anomaly & scoring profiles Customer-specific anomaly detection learns normal activity on a separate score axis. Scoring profiles adjust numeric thresholds inside rules.
  4. Decision & action policy Decision policies set review/block cutoffs; action policies trigger cases, notifications and webhooks. Your integrated system enforces the response.

What this looks like in practice

Linked payout after a quiet account week

A payout event arrives with a clean payment history—but linked devices and beneficiaries reveal recent accounts worth investigating. Rules identify velocity and beneficiary reuse while the customer model assesses abnormal activity on its separate score axis.

  1. Quiet payment week
  2. Payout event
  3. Linked devices / beneficiaries
  4. Review with attribution
Response
Configured policy returns review
Evidence
Rule contribution, customer-model score and linked context available to the reviewer

The reviewer does not rebuild the story from three tools. The decision record already shows contribution and connections.

Configurable detection

Configure rules, scoring profiles, lists and decision policies around the events and fields you map. Detection quality depends on that context. For qualified SENTR.Citadel evaluations, free Shadow Mode lets you compare decisions alongside your existing controls before changing live enforcement.

Connected intelligence

Open the network behind the event.

An event can look ordinary until you see the same device, session or instrument in other activity. Rebuilding those relationships manually slows every investigation.

SENTR resolves five profile families: users/accounts, devices, sessions, IPs and payment methods. Each brings together activity, risk indicators, alerts, open cases and linked profiles from the identifiers you supply.

SENTR Product viewDemo data
SENTR Connection Ring linking a payment-attempt event to a device and payment method, with a selected-node detail panel. Enlarge view
Follow the connection, not another spreadsheet

A payment event and its linked device and instrument in Connection Ring. A connection is an investigation lead, not a verdict.

Inspect the relationship and keep the underlying event in view.

Follow the connection, not another spreadsheet

A payment event and its linked device and instrument in Connection Ring. A connection is an investigation lead, not a verdict. Product demonstration · synthetic data.

Go deeper: Connected intelligence
Move from account to context
Overview, Activities, Linked Profiles, Cases and Connections give analysts a consistent way to explore each entity. Linked profiles expose risk, activity counts and first/last activity.
Follow the Connection Ring
Inspect direct and inferred relationships in an interactive graph. Focus a node, inspect connections, rearrange and zoom to trace related accounts, devices and instruments.
Start from the report, not only the alert
Create a case directly from a profile when a customer reports takeover or another concern. You do not need to wait for a new flagged payment to begin investigating.

Turn a suspicious connection into an investigation with context. Shared identifiers are leads—not proof of collusion or guilt.

Make the pattern visible before the next decision.

Show us the fraud pattern you need to understand. We will map the signals, controls and investigation workflow that could help.

Or Book a Session

Your privacy choices

Choose how you use SENTR. Your enquiry, chat and booking do not depend on accepting analytics.

Essential functionality Always active

Delivers and secures the site, remembers this choice and supports the chat or booking you request.

Measures page visits, feature use and enquiry journeys, including recognised campaign sources. Uses analytics cookies. Form answers and chat messages are not sent to Google Analytics.

Advertising trackers are disabled. The same choices apply to UK and EU visitors.

We remember this choice on this browser for up to six months. Changing an active analytics choice reloads the page to stop tracking scripts. Save any unfinished enquiry first.

Website data information