Mobile risk intelligence for commerce

Score the risk. Authenticate when needed.

Shastra evaluates mobile transaction risk on-device before authentication begins. Kavaach handles native 3DS when authentication is required. Mitra shows what happened across both and gives you the controls to tune policy over time.

One illustrative transaction sample values

Device resultShastra
Device recognized
18

Low riskRisk score 18 / 100. Higher means higher risk.

RECOGNIZED_DEVICECONSISTENT_HISTORY
Native challengeKavaach
Your brandSecure checkout

Verify your purchase

We sent a one-time code to the mobile number ending 5329.

MerchantNorthwind
Amount$500.00
Transaction viewMitra
Risk score18 / 100 · Low
Merchant policyStandard 3DS
IssuerChallenge · 2 rounds
3DS outcomecompleted
End to end5.2s
MitraDecision + outcome

Illustrative values for one example transaction where a challenge was required. Shastra and Kavaach can be adopted independently; Mitra works with either. Merchant policy decides whether to invoke 3DS. If 3DS is invoked, the issuer controls the authentication outcome and challenge decision.

The problem

The numbers behind the checkout.

Mobile is where the volume is. Card-not-present is where the fraud is. The gap between the two is where revenue disappears.

60%

of global ecommerce sales happen on mobile

Industry reports, 2026

81%

of all fraud cases globally are card-not-present

Chargebacks911

$443B

lost annually to false declines — 13× actual fraud

Aite-Novarica / Javelin

85.65%

mobile cart abandonment rate

Baymard Institute, 2026

18 pp

authorization-rate gap between card-present and CNP

Visa

One system. Clear control.

Shastra evaluates transaction risk. Merchant-owned policy decides what to do with it. Kavaach handles native 3DS when authentication is needed. Mitra gives teams the visibility and controls to tune that policy over time.

Learn + tune · around every transaction

Mitra

Visibility & policy control · optional add-on

  • Observe transaction outcomes
  • Configure risk thresholds
  • Define merchant-owned rules
  • Tune policy over time
Threshold & rule controls in development Explore Mitra
01 · Understand

Shastra

Risk context, on-device

Scores mobile transaction risk on-device and returns a score with reason codes before authentication begins.

Explore Shastra
02 · Decide

Merchant policy

Thresholds and rules you own

Shastra supplies the risk context. Your thresholds and rules determine whether the transaction continues normally or invokes 3DS.

Configurable in Mitra · controls in development
03 · Authenticate

Kavaach

Native 3DS, when needed

Handles native 3DS inside the app when authentication is required, with the 3DS Server you already operate.

Explore Kavaach

Risk context and authentication outcomes return to Mitra, so teams can see why each decision happened and tune the thresholds and rules that shape the next one.

Merchant policy decides whether to invoke 3DS. Shastra supplies the risk context; Kavaach handles native authentication when required; Mitra provides visibility and policy control across both. Issuer authentication decisions remain issuer-controlled.

Shastra

Recognize the device before you decide how to authenticate.

A device that has been on your platform for a year is not the same proposition as one you have never seen — and a device you know can still be running somewhere it should not be. Shastra answers both questions on the device, before 3DS is invoked.

On-device result · before 3DS Sample data
Device recognized
18

Low riskRisk score 18 / 100. Higher means higher risk.

RECOGNIZED_DEVICECONSISTENT_HISTORY

The sample device has consistent history and a familiar network. Recognition is context for your policy, not proof of the cardholder's identity.

Risk score: 0–100. Higher means higher risk. Scores and bands shown are illustrative; merchant-configured thresholds may differ.

Kavaach

Keep the authentication step inside your app.

When merchant policy invokes 3DS, Kavaach handles native authentication with your existing 3DS Server. If the issuer requires a challenge, Kavaach renders it inside the app with supported brand customization.

  • Android available for evaluation
  • iOS in development
  • EMVCo certification in progress
Explore Kavaach
MerchantAndroid app
KavaachNative 3DS SDK
ExistingYour 3DS Serverunchanged
The SDK follows the EMVCo interface your server already speaks. Nothing in the 3DS protocol message flow is modified.

Mitra · Visibility & policy control

See what happened. Tune what happens next.

Mitra is the operating surface for Vyuha. Inspect transaction-level risk and authentication outcomes, understand why decisions happened, and configure the thresholds and rules that shape future transactions.

The current demo shows transaction visibility; merchant-managed policy controls are in development.

Mitra partner: acme-payments Illustrative · sample data

Policy controls

In development
Scope
Portfolio (selected)MerchantApp
Risk thresholds
0–30Low risk
31–70Medium risk
71–100High risk
Merchant rules
  1. IF integrity_failed THEN require_3ds
  2. IF risk_score > 75 THEN require_3ds
  3. IF known_device AND risk_score < 25 THEN follow_low_risk_policy

Transaction view

7c3e…d18
56

Medium riskShastra risk score 56 / 100. Higher means higher risk.

UNSEEN_DEVICENEW_NETWORK
Merchant policy31–70 band → require_3ds
3DSInvoked · Kavaach
Challenge01 Text · 2 rounds
Outcomecompleted
Decision + outcome in one transaction view. Policy controls are in development. Scores and thresholds are illustrative; merchant-configured thresholds may differ. Explore sample Mitra

What it takes to adopt.

Integration fit

Android is available for evaluation today. iOS is in development. Kavaach works with the 3DS Server you already operate; Shastra can also be adopted independently.

See the integration

Operational ownership

Vyuha maintains the SDK, including specification and OS updates. Your team keeps control of server orchestration and merchant policy.

Current status

EMVCo functional certification for Kavaach is in progress; early partners can integrate and test now. Shastra scores independently of the 3DS flow and does not wait on it.

Start with the problem you need to solve now.

Evaluate Shastra for mobile risk intelligence, or Kavaach for native 3DS. Each works independently; Mitra adds visibility and policy control across either one.