Mules activate after approval
The account opens clean, stays quiet, then turns into a pass-through for stolen funds weeks later.

ScreenX decided who came in. Cortex watches who they become — continuous device, behavioural and network monitoring across every active account, surfacing mule formation, account takeover and behavioural drift before the first transfer.




























Most controls make one decision at signup and never revisit it. A genuine account at signup can still be compromised later. Onboarding judged them right; Cortex watches in case they change.
The account opens clean, stays quiet, then turns into a pass-through for stolen funds weeks later.

A genuine login, the real password, a session driven by someone who isn't the customer.

Each account looks normal on its own. The pattern only surfaces when you watch the links between them.

By the time a transaction rule fires, the first transfer has usually already cleared.

Fraud rarely arrives in one move. It assembles over hours, days, weeks. The signal is there long before the money leaves.
ScreenX reads every one of them
Cortex runs continuously on every active account, not only at moments of friction, every customer, every session, across the entire lifecycle. It works in three layers.

Device, behavioural, and network signals are read on every session and matched against the account's own baseline, the profile of how this user actually behaves.

A dynamic risk-scoring engine with 60+ rules surfaces the assembly as it happens: a mule ring forming, an account takeover in progress, a synthetic identity warming up, a behavioural drift away from the norm.

Risk-based adaptive authentication responds in proportion: low risk passes frictionless, medium risk steps up, high risk is blocked, with the full signal history attached to every flag.
Three signal layers, read continuously and scored together, the same sensing modalities that power onboarding, now running for the life of the account. Account takeovers break the pattern within seconds; mules drift from it over time.
Onboarding asks one question once. Cortex asks it on every session, against a baseline that belongs to the individual account, not a global threshold that treats every customer the same. Each account's signals are resolved on Sign3's unified customer graph and scored by a dynamic engine of 60+ rules, and the score carries the reason with it.



One continuous score, and the full context behind it — structured for your systems to act on in real time.
A risk score per account, updated each session, rising and falling as behaviour changes.
Mule formation, account takeover, behavioural drift and fraud-ring membership — each surfaced before the first transfer.
Frictionless, step-up or block — mapped to the score on your thresholds, so genuine customers feel nothing.
The accounts, devices and numbers connected to a flagged account, ready for investigation.
Every session and signal behind a flag, logged and attached, so any action is reproducible later.
Cortex is the monitoring layer for everything that goes wrong after approval. The same continuous score answers four questions across the life of the account.

Surface accounts that open clean and turn into pass-throughs — and the rings they belong to — before funds start moving.

Catch the genuine credentials driven by the wrong hands — a session that breaks the customer's behavioural pattern within seconds.

Map the links between accounts, devices and numbers to expose coordinated abuse invisible at the single-account level.

Detect the slow change — a synthetic identity warming up, an account being groomed — long before a transaction rule would fire.
Findings from a live fraud-ring analysis across a personal-loan onboarding journey, and from monitoring deployments across BFSI.
6.01%in organised fraud rings
Of users found to belong to organised fraud rings in a single week of live traffic (NBFC analysis).
40%of rings on a single device
A clear, high-ROI rule for device-based monitoring.
70%+of fraud in the top 4% of devices
The highest-value targets to watch.
503distinct fraud rings surfaced
From 69,646 numbers in one analysis window, patterns invisible account by account.
60+rules in the scoring engine
Driving low / step-up / block decisions automatically.
<200msp95 decisioning latency
So monitoring never adds friction for genuine customers.




























Most controls make one decision at signup and never revisit it. A genuine account at signup can still be compromised later. Onboarding judged them right; Cortex watches in case they change.
The account opens clean, stays quiet, then turns into a pass-through for stolen funds weeks later.

A genuine login, the real password, a session driven by someone who isn't the customer.

Each account looks normal on its own. The pattern only surfaces when you watch the links between them.

By the time a transaction rule fires, the first transfer has usually already cleared.

Fraud rarely arrives in one move. It assembles over hours, days, weeks. The signal is there long before the money leaves.
ScreenX reads every one of them
Cortex runs continuously on every active account, not only at moments of friction, every customer, every session, across the entire lifecycle. It works in three layers.
Book a demo
Device, behavioural, and network signals are read on every session and matched against the account's own baseline, the profile of how this user actually behaves.

A dynamic risk-scoring engine with 60+ rules surfaces the assembly as it happens: a mule ring forming, an account takeover in progress, a synthetic identity warming up, a behavioural drift away from the norm.

Risk-based adaptive authentication responds in proportion: low risk passes frictionless, medium risk steps up, high risk is blocked, with the full signal history attached to every flag.
Three signal layers, read continuously and scored together, the same sensing modalities that power onboarding, now running for the life of the account. Account takeovers break the pattern within seconds; mules drift from it over time.
Onboarding asks one question once. Cortex asks it on every session, against a baseline that belongs to the individual account, not a global threshold that treats every customer the same. Each account's signals are resolved on Sign3's unified customer graph and scored by a dynamic engine of 60+ rules, and the score carries the reason with it.



One continuous score, and the full context behind it — structured for your systems to act on in real time.
A risk score per account, updated each session, rising and falling as behaviour changes.
Mule formation, account takeover, behavioural drift and fraud-ring membership — each surfaced before the first transfer.
Frictionless, step-up or block — mapped to the score on your thresholds, so genuine customers feel nothing.
The accounts, devices and numbers connected to a flagged account, ready for investigation.
Every session and signal behind a flag, logged and attached, so any action is reproducible later.
Cortex is the monitoring layer for everything that goes wrong after approval. The same continuous score answers four questions across the life of the account.

Surface accounts that open clean and turn into pass-throughs — and the rings they belong to — before funds start moving.

Catch the genuine credentials driven by the wrong hands — a session that breaks the customer's behavioural pattern within seconds.

Map the links between accounts, devices and numbers to expose coordinated abuse invisible at the single-account level.

Detect the slow change — a synthetic identity warming up, an account being groomed — long before a transaction rule would fire.
Findings from a live fraud-ring analysis across a personal-loan onboarding journey, and from monitoring deployments across BFSI.
6.01%in organised fraud rings
Of users found to belong to organised fraud rings in a single week of live traffic (NBFC analysis).
40%of rings on a single device
A clear, high-ROI rule for device-based monitoring.
70%+of fraud in the top 4% of devices
The highest-value targets to watch.
503distinct fraud rings surfaced
From 69,646 numbers in one analysis window, patterns invisible account by account.
60+rules in the scoring engine
Driving low / step-up / block decisions automatically.
<200msp95 decisioning latency
So monitoring never adds friction for genuine customers.
We'll score it, surface the fraud patterns your current stack missed, and walk you through what we found. Your data, our scoring. No commitment, no integration, no decision required until you've seen the result.