Skip to content
How Sieve works

One record, from sign‑up to report.

Fraud moves from a SIM swap to a payout in minutes. Sieve puts six tools on one customer record, behind one API.

01 · Real-time decisions

Decide before the money moves.

Send an event, from sign-up to payout. Get allow, review or block back at once, with the reasons.

One set of rules covers M-Pesa, Airtel Money, cards, bank transfers and crypto withdrawals.

  • Typically answers in under 50 ms
  • Safe to retry; test and live kept apart
  • Watch first, enforce when ready
  • Signed webhooks for blocks, cases and sanctions matches
POST /v1/events200 OK · 16 ms
payout.requestedKES 48,000 → M-Pesa · cus_1001
Block
score96
  1. Phone number and payout account changed 16 minutes after signupdetails_changed_after_signup
    +35
  2. Payout account added 5 minutes agopayout_to_new_destination
    +25
  3. Withdrawing 99% of the balanceaccount_drain
    +21
Pattern · New-account cash-out139 pts · alert 75 · block 100
02 · Rules & patterns

Rules you can read. Numbers you can change.

Sieve ships thirty-one plain-English rules, plus your own. They combine into seven fraud patterns, each with an alert line and a block line.

  • Off, Watch or Enforce: test any rule on live traffic without blocking anyone
  • Replay the last 30 days before you save a change
  • Hit rate and precision for each rule, from your verdicts
  • Every change versioned and logged, with who made it
Rules & patternssample ruleset
Flag any payout to an account added less than 24 hours ago.
  • Recent SIM swap

    Flag money leaving within 72 hours of the SIM card being swapped.

    Enforce
  • Money in, straight back out

    Flag when 80% of money received in the last 24 hours leaves again.

    Enforce
  • Amounts kept under the threshold

    Flag 3 or more transactions within 7 days between 80% and 100% of the reporting threshold.

    Watch
03 · Threat memory

Fraudsters come back. Sieve remembers them.

Confirm a case and Sieve remembers its devices, payout accounts and identities. It flags them on any new account. Memories fade over time and weaken after a false alarm.

  • Rule weights tuned by your verdicts, never silently
  • Threat radar shows when any pattern surges above normal
  • Optional fraud network: share hashed signals with other members
Threat memory · recallsample data
Linked to confirmed fraudnew account · day 1
Payout account used in confirmed fraud 12 days agoNew-account cash-out · case_7Qm2… · confidence 0.92
Threat radarSIM-swap drain alerts up 4.2× this week against the 28-day baseline
04 · Sanctions & PEP

Screened at sign-up. Rescreened when lists change.

Sieve matches names as they are written in Kenya and Nigeria. It handles word order, accents and spellings like Mohamed and Muhammad. Date of birth and nationality can only lower a match score.

  • OFAC and UN lists direct; Kenya FRC, Nigeria Sanctions List, EU and PEP data via licensed feeds
  • Lists checked hourly; any change rescreens every customer
  • Full rescreens by risk tier: daily, weekly or monthly
  • A match needs a second reviewer; dismissed ones stay muted until the entry changes
Screening · name matchsample data
CustomerAbdirahman J. Kassim
ListedCabdiraxmaan Juma Kassim
transliteration · word order · DOB year0%
Date of birth1985-03-02 · list: 1985
Result93% · awaiting second reviewer
05 · AI investigator

The case file, written before you open it.

The Sieve Agent gathers the evidence, cites each event and weighs the innocent explanation. It recommends an outcome and drafts suspicious transaction reports.

  • Runs on Claude or a model you host; never sees names, phone numbers or emails
  • Ignores instructions hidden in customer records
  • Recommends only: it cannot close cases, change rules or move money
  • Spots event sequences your rules miss; its proposals are backtested and start in Watch
Sieve Agent · case summarysample case

New-account cash-out using a borrowed identity

Recommendation onlyAn analyst closes the case
06 · Code Guard

Find the hole before a fraudster does.

Much fintech fraud starts in the fintech’s own code. Code Guard scans your repositories for twenty classes of flaw that fraudsters exploit.

  • Callback verification for M-Pesa, Paystack, Flutterwave and Stripe
  • Double-spend races, idempotency, IDOR and mass assignment
  • Payout 2FA, OTP strength and throttling, leaked secrets
  • Each fix comes as a prompt for your coding agent
Code Guard · src/routes/mpesa.tsCritical
router.post('/mpesa/callback', async (req, res) => {
const { Body } = req.body
const cb = Body.stkCallback
const amount = cb.CallbackMetadata.Item[0].Value
await wallets.credit(cb.AccountReference, amount)
res.json({ ResultCode: 0 })
})
Critical · the callback credits wallets without checking who sent it

Anyone with the callback URL can fake a “payment received” and withdraw money that never arrived.

Integration

Start with one call before each payout.

That alone protects your payouts. Add sign-ups, logins and detail changes to switch on every rule. Use our Node.js SDK, or JSON over HTTPS from any language.

  • payout.requested
  • customer.created
  • customer.updated
  • login
  • transaction
payouts.js
// npm install @sievefraud/node
import { Sieve } from '@sievefraud/node'

const sieve = new Sieve('sv_live_…')

// Before you release a payout, ask Sieve.
const d = await sieve.events.create({
  type: 'payout.requested',
  customer_id: user.id,
  amount: 48000,
  destination: { type: 'mpesa', account: payout.phone },
})

if (d.decision === 'block') return res.status(403).json({ error: 'Payout held for review' })
if (d.decision === 'review') await holdPayout(payout.id, d.reasons)
Book a demo

See Sieve catch fraud in your business.

Book a demo and get a private workspace set up for how your customers pay.