Sense
Sign inBook a demo
INDUSTRIESCAPITAL MARKETS

An order arrives. You cannot ask who sent it.

Milliseconds, an app on someone else's phone, credentials that were correct. In broking, the question is never whether the order was valid — it is whether the client placed it.

1 in 3
retail trades in India are placed from a mobile app rather than a terminal
T+0
settlement leaves no overnight window in which to reverse a bad order
CSCRF
SEBI's cyber framework applies to brokers, RTAs, AMCs and their apps
6 h
to report a cyber incident to CERT-In once it is detected
Sources: exchange retail participation data · SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) · CERT-In incident reporting directions.
Read the counter-moveDownload the broking brief
01 — THE CASE

One session, one screen share, a full portfolio.

Correct credentials, a valid TOTP, orders inside every risk limit. The client watches it happen and cannot stop it.

14:06
The client answers a call about a margin shortfallThe caller has the client's name, UCC and last trade. He asks the client to install a support app so the shortfall can be shown on screen.SOCIAL ENGINEERING · PRETEXT CALL
14:11
A remote-control session opens on the handsetA screen-sharing tool is granted accessibility permissions. Everything the client sees, the caller sees; everything the caller types, the app receives as the client.REMOTE ACCESS · SESSION HIJACK
14:14
Login and second factor pass cleanlyThe client enters the credentials and reads the TOTP aloud. Nothing in the authentication is wrong — the person authenticating is not the person deciding.VALID CREDENTIALS · VALID SECOND FACTOR
14:22
The portfolio is sold and the proceeds rotatedHoldings are liquidated and the cash is worked into illiquid small-cap and far out-of-the-money option positions bought from counterparties the ring controls.UNAUTHORISED TRADING · VALUE TRANSFER
14:31
A mule demat account absorbs the other sideThe buying accounts were opened months earlier with farmed devices and rented identities, each dormant until it was needed for one session.MULE ACCOUNTS · DEVICE FARM
16:40
The complaint arrives after settlementThe client reports the loss the same evening. On T+0 settlement there is nothing left to reverse, and every order carries a clean audit trail.T+0 · IRREVERSIBLE
WITH SENSE
The order never reaches the exchange.At 14:22 a remote-control tool is live in the session, the handset is not one this client has ever traded from, and the order pace is not human. The order is held for out-of-band confirmation before it is routed — no unauthorised trade to unwind, no client complaint to arbitrate.

A risk engine can only judge the order it is given. It cannot see whose hand is on the phone.

WHY CREDENTIALS AND LIMITS RUN OUT
02 — THE MAP

Four surfaces in a broking business. What you see, and what they use.

Pick a surface to read the exposure in the terms your risk and compliance committee uses.

WHAT THE BROKER SEESOrders from an authenticated client on a mobile device inside every risk and margin limit the OMS enforces.
WHAT THE FRAUD NETWORK USESRemote-control and screen-share tools to drive the session, emulators and cloned instances to run accounts at scale, root and hooking to move client-side limit checks, and repackaged builds for whatever the real app refuses.
remote_access_activeemulatordevice_reuse_x27frida_hookrepackaged_build
03 — THE COUNTER-MOVE

Evidence from the device, the session and the order — before it is routed.

Sense does not price risk. It tells your OMS and risk stack whether the order in front of it came from your client, on a device they own, in a session nobody else was driving.

POSITION 01On the deviceThe SDK runs inside your trading app and reports what an order message cannot: remote-control and screen-share sessions in progress, emulator and cloned instances, device reuse across UCCs, root and hooking, and whether the build placing the order is the one you shipped.RASPIN-THREADCode ObfuscationBUILD-TIMEApp AuthATTESTATION
POSITION 02At the sessionThe client's number is proven live on the handset instead of by a code anyone holding the SIM can read out, and the web terminal is separated into clients and scripts — so credential stuffing, token replay and a hijacked session are visible before an order is routed.Silent Mobile VerificationIDENTITYAccount TakeoverSESSIONBot DetectionWEB & API
POSITION 03Around the orderAdvisory and support assistants are inspected in flight — prompt, retrieved document, tool call, response — and every model in the surveillance and recommendation path is scanned, signed and inventoried before it can act on client positions.AI Runtime SecurityIN-PATHModel Security & TrustPRE-SHIP
04 — THE EXPOSURE INDEX

Nine ways a broking business absorbs fraud as operational loss.

Open a line to read the mechanism and the control that answers it. Most of these arrive as client complaints, arbitration and regulatory correspondence rather than as a fraud number.

A client is talked into installing a support tool and the session is driven by someone else. Credentials, second factor and every risk limit are satisfied.Remote-control, screen-share and overlay activity is reported from inside the app, and the order is held for out-of-band confirmation before routing.
Mechanisms drawn from published exchange and SEBI advisories on unauthorised trading, account takeover in trading apps, mule demat accounts and market-data abuse.
05 — THE FIRST NINETY DAYS

No change to your risk limits. One release per surface.

01DAYS 1–30The trading app, in report-onlySDK into your existing app. Nothing is held. Your risk team sees the remote-control, emulator, device-reuse and tampering rate in its own order flow for the first time.
02DAYS 31–60Hold at the order, not at the complaintDevice and session evidence enters the pre-trade check. Driven sessions and unrecognised devices are held for confirmation; genuine clients notice nothing.
03DAYS 61–90Web, API and the model pathTerminal and API clients covered, market-data endpoints defended, and advisory or surveillance models scanned and inventoried with records the exchange audit can read.
WHAT THE EXCHANGE AUDITOR AND YOUR CISO RECEIVE
A signed device and session record per orderApp build inventory — yours and every vendor build in the chainUnauthorised-trading evidence separated from market riskModel and adapter inventory for the advisory pathIncident timelines assembled inside the CERT-In reporting window
MAPPED TO
SEBI CSCRFExchange system auditCERT-In · 6 h reportingTwo-factor for trading accountsDPDP ActSEBI advisories on unauthorised tradingOWASP MASVSISO 27001 / SOC 2

SEBI's CSCRF holds the regulated entity answerable for the security of every client-facing app and API it operates, its own and its vendors'. When the exchange audit arrives, the device and session evidence is already assembled, per order, per release.

NEXT STEP

Send us a month of order flow. We'll show you which devices placed it.

A device-and-session assessment across your trading app, web terminal and API clients — remote-control sessions, device reuse across UCCs, tampered builds, emulator clusters, credential-stuffing pressure on login and scraper load on market-data endpoints.

Run the assessmentTalk to our capital-markets teamReport-only on your own flow first — you see the exposure before anything is held.