AI governance & assurance · payment-run release gate · live
Last gate before the wire.
Business email compromise works because one convincing email updates the vendor master and Friday's payment run wires the money in bulk. This demo puts a deterministic release gate between the two. Red-flag rules quarantine suspicious payments before the bank file exists, the language model only assembles the cited anomaly pack and the call-back script, and money moves only after an evidenced call-back plus two named approvals. You get to play the fraudster first. Every decision lands in a hash-chained ledger you can verify, replay and tamper with.
Public dataset: City of Chicago payments · bank details & attacks synthetic
Send the fake bank-change email, then see if your money arrives.
Pick a vendor to impersonate. One click emails AP a new remittance account on plausible letterhead, updates the vendor master, and drops a fresh $48,750.00 invoice into Friday's queue. Exactly how the real thing starts.
Quarantine bay
run the screen firstNothing here yet. Click ② Run Friday's payment screen above. Rules run over all pending payments; anything they flag is held out of the bank file. The model cannot quarantine or release anything.
Anomaly pack & release gate
select a quarantined paymentEach quarantined payment gets an anomaly pack: the rule that caught it, the change-log line that betrayed it, the payment history, the email text, and a drafted call-back script. Every cited value is checked against the record by code before it is shown.
Every payment in the run · days since the vendor's last bank-detail change
appears after screeningrules quarantine → model assembles the cited pack → call-back to the pre-change number → two named approvals → wire, hashed · payments: City of Chicago open data (s4vu-giwb) · bank layer synthetic · deterministic engine, identical results every run · willytai.com