LynxPay

The UPI PIN proves it's you. It doesn't prove it's your idea.

The missing layer

Every control today checks that a transaction was authorized. None checks that the authorization was genuine. LynxPay adds a pre-authorization intent layer on top of the existing fraud rails. It doesn't replace them. It sees what they can't, and it feeds what it learns back to the ecosystem.

Where LynxPay sits

Layer 1
Device & account trust
Handset/app risk, account legitimacy
Is the device/account compromised?
Layer 2
Transaction & beneficiary rails
NPCI / bank FRM, velocity, blocklists
Does the pattern or payee look risky?
Layer 3
Intent layer (LynxPay)
Pre-authorization intent verification
Does this payment still match the user's genuine intent?

What the intent layer adds

Conventional fraud controls+ LynxPay intent layer
The question askedIs the device / account / payee suspicious?Does the payment still match the user's intent?
Social-engineering contextNot visible to the railsReads the message / call / QR that drove the payment
LanguagesMostly English rules8 languages live, incl. Hinglish, Tanglish, Bengali, Marathi, Telugu
Who decidesRules / scoresAI understands; transparent policy + human decide
Mandate termsNot checked against the messageClaimed vs actual AutoPay terms, diffed; execution drift blocked
CounterfactualsNot reproducible from a model verdictLive what-if: flip a factor, the engine re-decides identically
Proof of decisionA log entryEd25519-signed intent record, publicly verifiable
Warning overridesClick-through and hopeThe Second Question reads the user's own justification
ExplainabilityVariesEvidence-backed, auditable, overridable
Data residencyVariesSelf-hostable, in-region (DPDP / RBI)
EcosystemPer-institutionFeeds shared intelligence (e.g. a DPIP-style network)

What we add

A different question

Existing controls ask "is this suspicious?" We ask "does this payment match the user's intent?", checking what the user thinks they're paying for against where the money is really going. That's the layer nobody else has.

The AI never decides

The model understands language. A transparent weighted score plus hard safety rules make every decision, with human override and a full audit trail. It's something a regulator can actually sign off on.

India-first language

Real scams are code-mixed and regional. We read Hindi, Hinglish, Tanglish, Bengali, Marathi and Telugu live, the way scams actually reach people.

Graduated friction, not blunt blocking

A nudge, a timed pause with a pointed question, a trusted-contact check, or a hard block, matched to the risk. Legitimate urgent payments don't get punished.

Sovereign-ready

Runs on a self-hosted, in-region model, so payment data never has to leave India. That's a real privacy and compliance edge.

Feeds the network

One corroborated report raises that beneficiary's risk for everyone. It's a citizen-side complement to shared fraud intelligence, not a competitor.

How we answer the judging criteria

Innovation & Credibility
Intent-to-transaction consistency, signed intent records, mandate diffing, the Second Question: fraud the device/account/rail checks can't see.
Live Demonstrability
Interactive consumer app, analyst console, and a live red-team box judges can try (and try to jailbreak).
Relevance
UPI scams, AutoPay mandate abuse, shop-counter QR fraud and collect requests, in 8 Indian languages.
Scalability & Deployment
Docker, stateless API, swappable/self-hosted model, pre-auth SDK, graph network effect.
Technology Excellence
Deterministic explainable engines, live counterfactuals, 100+ tests, low latency, an open adversarial benchmark.
Responsible AI & Ethics
AI never decides; signed records; audit; masking; no chain-of-thought stored; in-region model; DPDP-aligned.

Synthetic demonstration environment. No real UPI, bank, telecom or device integration. Metrics are measured on our own adversarial synthetic benchmark (which we intend to open-source). Risk indicators show elevated risk but do not by themselves prove fraud.