We look at the person,
not just the destination.
Address screening catches dirty wallets. It's blind to the most expensive fraud there is — a clean address, and a person being coached in real time to send to it. Straja reads the checkout session itself.
Or read how it works first.
idle_gaps_over_60s 4
tab_switches 3
address_entry_method pasted
deposit_escalation [200, 1000, 4800]
destination_first_seen 2d
INTERVENE — coached-session pattern, four signals presentSame checkout. Two completely different sessions.
Address-based screening asks where the money is going. Straja asks what's happening to the person sending it.
Blocklists, sanctions checks, laundering history. Commoditized — every processor already has this layer.
Blind here: the scammer's address is freshly created and perfectly clean.
60-second idle gaps, tab switches mid-checkout, a pasted address, deposits stepping from 200 to 4,800 — the shape of someone following instructions from a live call.
No address blocklist can see any of it.
Fifteen signals in all — see the full set.
Every number below is measured, not modeled.
The stability suite runs live model calls against fifteen labeled scenarios, five times each, and checks the verdict never moves.
Run it in shadow mode before you trust it in production.
Four weeks, one payment corridor. Straja scores every session but never intervenes — then you compare against real fraud outcomes before anything goes live.