Advisory · Bank owns the action · Free public triage

Stop hunting mules in screenshots

Check a scam receipt on the phone — NRIC, phone, and email stripped on-device; only scrubbed indicators leave (aliases follow partner policy). Partner banks get structured mule clues as advisory tips. Not in-session behavioral biometrics — destination account from the victim artifact. We never freeze accounts.

The cost of digital fraud in Malaysia is accelerating

Malaysia lost RM2.97 billion to online fraud in 2025 (Home Ministry), with 66,204 cases reported (PDRM) — nearly double the prior year. The current response is fragmented and manual — victims report hours after the scam, mule accounts are drained within minutes, and raw evidence sharing across banks risks PDPA violations.

Today
0 min
Victim transfers
to mule account
5–30 min
Funds layered &
cashed out abroad
2+ hrs
Victim finally
calls NSRC
Too Late
Money is gone
Waspada
on-device
Receipt parsed
on the phone
scrubbed
Mule indicators
extracted & scrubbed
partner
Advisory tip reaches
the bank fraud team
Advisory
Bank decides · ~2s durable path

Intelligence starts on the device

The Waspada SDK runs inside the host banking app or the public triage sandbox. No receipt or screenshot ever uploads to our servers. All extraction happens on-device before transmission.

1. Receipt Parsing

Handles major Malaysian banking receipts, screenshots, and multi-page PDFs — including encrypted files. Extraction is CI-gated on clean and noisy labeled corpora; we publish characterized misses, not vanity 100%s.

2. On-Device Intelligence

Three-tier extraction identifies mule accounts, BIC codes, scammer aliases, and malicious URLs. Runs natively on Apple and Android devices.

3. Privacy Scrub & Sign

NRIC, phone numbers, and emails stripped before anything leaves your device. Payload cryptographically signed for tamper-proof delivery. Works offline after models are cached on first load.

Privacy by design: NRIC / phone / email stripped on-device; only scrubbed indicators transmitted. Alias handling configurable per partner. Absolute “zero PII egress” is not claimed.
NRIC: 900101-14-5555
PII REMOVED
SIGNED
On-Device Analysis
Account match✓ PASS
Alias & URL✓ PASS
Draft assistSTANDBY
RECEIPT SCAN
receipt.pdf

How a receipt becomes an advisory tip

Public sandbox triage stays on the phone (draft report, no auto bank feed). Partner-integrated apps can send scrubbed indicators to the fraud team — advisory only, bank decides. WhatsApp is not a live public ingest door.

Step 1 of 6

Citizen opens the public sandbox

A community responder or victim opens the free triage sandbox in their browser. Evidence is processed on-device — nothing is uploaded through chat, and public triage does not write into the bank FMS path.

Public channel
Sandbox
Browser triage · no bank feed
Opened
On-device
On the phone
Waspada SDK
On-device receipt analysis
Inactive
Indicators
Secure gateway
Waspada Gateway
Verification & enrichment
Inactive
Partner only
Your bank
Fraud team / FMS
Advisory tip · bank decides
Inactive
Privacy: receipt stays on device; NRIC / phone / email stripped; aliases follow partner policy Public sandbox: on-device triage only — does not auto-feed bank FMS (WhatsApp ingest closed) Partner path: signed indicators → advisory alert when integrated

What your fraud team gets

Privacy compliance, extraction accuracy, and zero-friction integration with existing bank infrastructure — by design, not afterthought.

01

Victim Identifiers Stay On-Device

NRIC, phone, and email are stripped on-device and re-verified at the gateway. Receipt images are not uploaded for cloud inference. Only scrubbed indicators leave the device; scammer aliases egress only under partner policy.

02

Built for Malaysian Banking Receipts

Measured on labeled Malay receipt corpora — clean CI gate plus a noisy soft gate with published failure modes (including wrong-account vs miss). Parsing stays on-device; alerts stay advisory so banks own any freeze.

03

Tamper-Proof Delivery

Every alert is cryptographically signed with per-partner key isolation. Replay attacks and payload tampering are structurally prevented. Image authenticity is not assumed from a single receipt — corroboration belongs with the bank.

04

Real-Time Analyst Feeds

Live streaming alerts to bank fraud dashboards on the partner path. Memory fast path under a second; durable delivery ~2 seconds p99 — measured topologies, not a single blended claim.

05

Scam Domain Intelligence

Malicious URLs from scam messages enriched with domain registration data for attribution and takedown support.

06

STIX 2.1 Formatting

Gateway formats advisory alerts as STIX 2.1 for analyst export / offline use. Live bank delivery is the signed FMS JSON webhook — not an automated SIEM push. Patterned indicators are suppressed while disposition is advisory.

Regulatory alignment

RMiT Aligned
Paragraph-cited mapping across 10 BNM domains.
Alignment, not certification.
PDPA Aligned
PII stripped on-device before transmission.
Full DPIA pending.
STIX 2.1
OASIS-standard formatter for analyst
export / offline samples — not a live SIEM push.

Integration Surface

Four endpoints. Partner-authenticated ingestion, real-time alert streaming, and health monitoring. Full API docs in the developer portal.

GET
/health
Gateway health check and uptime status
POST
/api/v1/telemetry/ingest
Ingest anonymized fraud telemetry (JWT required)
POST
/api/v1/alerts/stream-ticket
Exchange API key for SSE stream ticket
GET
/api/v1/alerts/stream
Real-time threat alert feed (ticket required)

Ready for a supervised pilot?

For bank fraud, mobile, and FMS teams evaluating an advisory evidence layer — start with contracts you can verify, then a staged integration week.