Invoice Guard

Let us double check that payment,
for you.

That's what we do.

A model reads it. Arithmetic decides it.

A model can be argued with. An invoice carrying instructions aimed at whoever reads it is a real attack, and we test for exactly that. So nothing that decides whether money moves is a judgement call: reading is a language problem, scoring is an arithmetic one, and the two never touch. The same invoice returns the same number every time, and a person can check it by hand.

01

It learns your vendors

Every payment you have already made teaches it what normal looks like for that vendor: the bank details, the usual amount, the usual interval, the tax ID.

02

Eleven checks, all deterministic

Routing change, account change, tax ID change, lookalike name, lookalike sender domain, unknown vendor, amount variance, velocity, duplicate, pressure language, threshold gaming.

03

A check that can't run says so

A blurry scan is not a clean invoice, it is an unexamined one. If anything between the invoice and the payment went unchecked, the verdict is never a pass.

Catching it is half. Proving you checked is the half that pays.

Crime and cyber policies do cover this fraud, right up to the failure to verify clause. Pay without independent verification and the cover is reduced or denied. So every check keeps a timestamped record of what was found, who was told, what they asked, and who released the money anyway. Entries are added. None is ever edited.

26 Aug  09:12
Checked. Scored 25Routing and account both differ from nine prior payments
Hold
26 Aug  09:14
Opened by S. Okafor · #40118Badge identity, recorded with the entry
Viewed
26 Aug  09:31
Verified by phoneReached the AP manager on the number already on file, not the one printed on the invoice
Verified
26 Aug  09:36
Confirmed fraudulent. Not paidThe vendor never sent it. Their mailbox was the compromised one.
$4,088 held

They confirm the account belongs to the vendor. We prove it is the account you have always paid.

When a vendor's email is taken over, the thief opens an account in the vendor's own real name. It does belong to them. Ownership checks pass it. Your payment history does not, because the money still has to arrive somewhere the thief controls, and that is the one thing they cannot keep the same.

The second channel everyone relies on is the one being retired.

The standard control is a phone call to confirm a bank change. Voice cloning from three seconds of audio now costs under twenty dollars, and it is already inside this fraud. So when the verdict is a hold, Invoice Guard hands the caller questions drawn from the vendor's own history: things an attacker cannot know and the real vendor cannot get wrong.

74%

of US organisations were hit by business email compromise in 2025.

AFP Payments Fraud and Control Survey, April 2026
17%

use any form of AI against payments fraud at all.

AFP Payments Fraud and Control Survey, April 2026
$122k

average loss per incident. 86% moves by wire or ACH before anyone notices.

FBI IC3 Annual Report, 2025

Paste one invoice. See what it already knows.

No account numbers are ever stored. Bank details are reduced to a fingerprint before anything is written down, and the invoice itself is never kept.