WoWyrd
Observe-only PoC · On-premise

Pre-transaction risk control for financial and high-velocity platforms.

Observe-first, on-premise. See weak fraud signals earlier — before onboarding, payment, or payout workflows create irreversible exposure.

Why earlier matters

Most controls decide after the request already cost you something.

Onboarding, payment, and payout logic typically screens for risk after a request has already entered application logic, triggered external checks, or reached a workflow that's expensive or irreversible to unwind. That's a poor fit for instant and account-to-account rails, where money — once sent — is gone. Cloud-hosted fraud vendors add a second problem: they need your sensitive data to leave your environment.

Earlier in the path

WoWyrd sits after your trusted edge/TLS termination but before expensive processing — so a risk signal can inform a decision while it's still cheap to act on.

Inside your environment

Runs on-premise / in the operator environment. Raw operational data can stay local — nothing has to leave to get a risk read.

Complementary, not a replacement

Sits alongside KYC, AML, sanctions screening, and existing fraud tooling — a signal layer that helps route what deserves deeper review, not a substitute for any of it.

How it works

Three planes: Signal, Risk, Control.

Deterministic and explainable by design — every plane produces something a human can read and check.

1

Signal Plane

Ingests what you already trust — no need to see raw client packets behind Cloudflare or an ALB.

  • Edge headers & logs (Cloudflare, WAF, ALB)
  • Application & payment callback events
  • Out-of-box threat-intel feeds
  • Optional eBPF/runtime agent, later
2

Risk Plane

Normalizes events, resolves entities, and correlates weak signals into an evidence timeline.

  • Trust model per header source
  • Velocity counters per entity & combination
  • Deterministic, explainable rule pack
  • Correlates independent weak signals (automation/bot labels, threat-intel, account-lifecycle) into one explainable compound reason
  • Evidence timeline + human-readable reasons
3

Control Plane

Starts at observe and report. Anything stronger is a deliberate, reviewed step — never the default.

  • Observe → evidence report
  • Manual review / step-up / hold routing
  • Controlled enforcement, only after evidence review
  • Optional later: eBPF enforcement (patent application pending)
Why now

The regulatory and payment-rail backdrop is shifting underneath this problem.

Discovery context, not a compliance claim — WoWyrd doesn't make you compliant with any of the below.

Nacha credit-push fraud monitoring (2026) New monitoring obligations for credit-push payments on the ACH network.
UK APP reimbursement rules Receiver-side liability for authorised-push-payment fraud changes who has to catch it, and when.
PSD3 / PSR & Verification of Payee EU payment-services rules pushing risk checks earlier in the payment path.
DORA operational resilience Third-party risk and operational-resilience expectations for EU financial entities.
The PoC

Narrow, observe-only, and reviewed together.

The first useful deployment is deliberately small: one stream, one owner, one measurable risk question. Framed as shadow-mode / champion-challenger validation — language your model-risk team already uses.

Pick one stream

Merchant onboarding, payout/withdrawal, payment initiation, account-opening/KYC step, beneficiary creation/change, instant-payment initiation, or a suspicious login→payment sequence.

Deploy observe-only, inside your environment

2–4 weeks. Mirror/observe mode — no inline decision on day one. Data-boundary agreed up front: what stays local, what (if anything, hashed or aggregated) leaves.

Review evidence weekly, together

Which early signals appeared before business-impacting events, which were useful vs. noisy, and measured — not claimed — latency and resource impact.

Get a decision report

Not a dashboard promise — a report a non-engineer can read: top triggered rules, evidence timeline, false-positive candidates, suggested calibration, and an enforcement-readiness recommendation: no-go, continue observe-only, or controlled-enforcement candidate.

What WoWyrd is not.

Not a replacement for KYC, AML, sanctions screening, payment-fraud tooling, bot products, or case management. A pre-transaction signal layer that helps decide what deserves deeper review, routing, throttling, or — later, deliberately — controlled enforcement.

Use cases

Anywhere a request precedes an irreversible transaction.

Merchant onboarding & underwriting Payout / withdrawal Payment initiation Account opening / KYC step Beneficiary creation or change Instant / account-to-account payments Embedded finance

Target operators: payment processors & orchestrators, ACH third-party senders, embedded-finance platforms, merchant-onboarding & payout providers, crypto-fiat on/off-ramps, and bank/FI fraud-risk innovation teams (narrow PoC only).

Talk to us about one stream, one owner, one question.

No deck required first — tell us the stream you're worried about and who owns the decision, and we'll scope a narrow, observe-only PoC around it.