Shastra
Risk context, on-device
Scores mobile transaction risk on-device and returns a score with reason codes before authentication begins.
Explore ShastraMobile risk intelligence for commerce
Shastra evaluates mobile transaction risk on-device before authentication begins. Kavaach handles native 3DS when authentication is required. Mitra shows what happened across both and gives you the controls to tune policy over time.
One illustrative transaction sample values
Low riskRisk score 18 / 100. Higher means higher risk.
We sent a one-time code to the mobile number ending 5329.
Illustrative values for one example transaction where a challenge was required. Shastra and Kavaach can be adopted independently; Mitra works with either. Merchant policy decides whether to invoke 3DS. If 3DS is invoked, the issuer controls the authentication outcome and challenge decision.
The problem
Mobile is where the volume is. Card-not-present is where the fraud is. The gap between the two is where revenue disappears.
of global ecommerce sales happen on mobile
Industry reports, 2026
of all fraud cases globally are card-not-present
Chargebacks911
lost annually to false declines — 13× actual fraud
Aite-Novarica / Javelin
mobile cart abandonment rate
Baymard Institute, 2026
authorization-rate gap between card-present and CNP
Visa
Shastra evaluates transaction risk. Merchant-owned policy decides what to do with it. Kavaach handles native 3DS when authentication is needed. Mitra gives teams the visibility and controls to tune that policy over time.
Visibility & policy control · optional add-on
Risk context, on-device
Scores mobile transaction risk on-device and returns a score with reason codes before authentication begins.
Explore ShastraThresholds and rules you own
Shastra supplies the risk context. Your thresholds and rules determine whether the transaction continues normally or invokes 3DS.
Configurable in Mitra · controls in developmentNative 3DS, when needed
Handles native 3DS inside the app when authentication is required, with the 3DS Server you already operate.
Explore KavaachRisk context and authentication outcomes return to Mitra, so teams can see why each decision happened and tune the thresholds and rules that shape the next one.
Merchant policy decides whether to invoke 3DS. Shastra supplies the risk context; Kavaach handles native authentication when required; Mitra provides visibility and policy control across both. Issuer authentication decisions remain issuer-controlled.
Shastra
A device that has been on your platform for a year is not the same proposition as one you have never seen — and a device you know can still be running somewhere it should not be. Shastra answers both questions on the device, before 3DS is invoked.
Low riskRisk score 18 / 100. Higher means higher risk.
The sample device has consistent history and a familiar network. Recognition is context for your policy, not proof of the cardholder's identity.
Risk score: 0–100. Higher means higher risk. Scores and bands shown are illustrative; merchant-configured thresholds may differ.
Kavaach
When merchant policy invokes 3DS, Kavaach handles native authentication with your existing 3DS Server. If the issuer requires a challenge, Kavaach renders it inside the app with supported brand customization.
Explore KavaachWe sent a one-time code to the mobile number ending 5329.
Mitra · Visibility & policy control
Mitra is the operating surface for Vyuha. Inspect transaction-level risk and authentication outcomes, understand why decisions happened, and configure the thresholds and rules that shape future transactions.
The current demo shows transaction visibility; merchant-managed policy controls are in development.
Medium riskShastra risk score 56 / 100. Higher means higher risk.
Android is available for evaluation today. iOS is in development. Kavaach works with the 3DS Server you already operate; Shastra can also be adopted independently.
See the integrationVyuha maintains the SDK, including specification and OS updates. Your team keeps control of server orchestration and merchant policy.
EMVCo functional certification for Kavaach is in progress; early partners can integrate and test now. Shastra scores independently of the 3DS flow and does not wait on it.
Evaluate Shastra for mobile risk intelligence, or Kavaach for native 3DS. Each works independently; Mitra adds visibility and policy control across either one.