Sense
Sign inBook a demo
INDUSTRIESINSURANCE

You insure a life you never see and pay a claim you never visit.

A proposal filled on someone else's phone, photographs chosen by the claimant, documents that render perfectly. Insurance fraud is no longer a document problem — it is an evidence problem.

10%
of claim outgo is widely estimated to be fraudulent or inflated
Self-serve
claim intake means the only witness to the loss is the claimant's camera
POSP
and intermediary apps sit outside your build pipeline but inside your liability
6 h
to report a cyber incident to CERT-In once it is detected
Sources: industry estimates of fraudulent and inflated claim outgo · IRDAI Information and Cyber Security Guidelines · CERT-In incident reporting directions.
Read the counter-moveDownload the insurance brief
01 — THE CASE

One accident, four insurers, no accident.

Every photograph is sharp. Every bill is itemised. Every policy is in force. The vehicle in the images was damaged eighteen months ago, in another state.

DAY 0
A policy is bought for a loss that already happenedA motor policy is issued online at 22:40 with a backdated risk-start request, on a vehicle photographed months earlier in a different state.PRE-EXISTING LOSS · ANTEDATED COVER
DAY 2
The claim is filed from a self-serve journeyNo assessor visit is needed for a claim of this size. Intake is a form, four photographs and a repair estimate, all supplied by the claimant.SELF-SERVE INTAKE · NO INDEPENDENT WITNESS
DAY 2
The camera never saw the damageImages are fed into the app through a virtual camera and a hooked media pipeline. Metadata is consistent, resolution is native, and the file was never taken by that phone.INJECTED MEDIA · VIRTUAL CAMERA
DAY 3
The paperwork is issuer-accurateThe repair estimate and the FIR copy come from a template service — correct fonts, correct seals, a garage that answers the phone and confirms the job.DOCUMENT TEMPLATE FARM · COLLUSIVE VENDOR
DAY 4
One handset is filing for eleven claimantsThe device behind the claim has submitted eleven claims across four insurers this quarter, each under a different name and policy.DEVICE REUSE · ORGANISED RING
DAY 9
Settled, and counted as loss ratioThe claim clears within the turnaround the regulator expects. It appears in the book as claims cost, not as fraud, and the ring files the next one.SETTLED · NEVER CLASSIFIED AS FRAUD
WITH SENSE
The claim never reaches the assessor.At the moment of capture the app is running in an emulated environment with a virtual camera in the media path, on a handset already seen across eleven claims. The claim is held before an assessor is dispatched — no survey cost, no settlement, no recovery action a year later.

A claims model can only judge the evidence it is handed. It never sees the vehicle, the ward, or the room.

WHY DOCUMENT CHECKS AND IMAGE FORENSICS RUN OUT
02 — THE MAP

Four surfaces in an insurance business. What you see, and what they use.

Pick a surface to read the exposure in the terms your claims and risk committee uses.

WHAT THE INSURER SEESA proposal or a claim submitted from a mobile device, with captures that pass image checks and documents that render correctly.
WHAT THE FRAUD NETWORK USESVirtual cameras and hooked media pipelines to supply photographs and liveness frames, emulators and cloned instances to run claimants at scale, root and hooking to move client-side validation, and repackaged builds for whatever the real app refuses.
virtual_cameraemulatordevice_reuse_x11frida_hookrepackaged_build
03 — THE COUNTER-MOVE

Evidence from the device, the capture and the claim — before the settlement leaves.

Sense does not adjudicate claims. It tells your underwriting and claims stack whether the proposal or the claim in front of it came from a real customer on a real device, with media that came from a camera rather than a file.

POSITION 01On the deviceThe SDK runs inside your app and reports what a photograph cannot: whether the capture came from the phone's sensor or from a virtual camera, whether the app is emulated or cloned, how often that device has appeared across claims and proposals, and whether the build is the one you shipped.RASPIN-THREADCode ObfuscationBUILD-TIMEApp AuthATTESTATION
POSITION 02At the proposal and the claimThe customer's number is proven live on the handset instead of by a code anyone holding the SIM can answer, and the web journey is separated into customers and scripts — so farmed proposals, quote harvesting and organised claim rings are visible before an assessor is dispatched.Silent Mobile VerificationIDENTITYBot DetectionWEB & APIAccount TakeoverSESSION
POSITION 03Around the settlementClaims and service assistants are inspected in flight — prompt, retrieved document, tool call, response — and every model, adapter and tokenizer in the triage and settlement path is scanned, signed and inventoried before it can approve a payout.AI Runtime SecurityIN-PATHModel Security & TrustPRE-SHIP
04 — THE EXPOSURE INDEX

Nine ways an insurance book absorbs fraud as claims cost.

Open a line to read the mechanism and the control that answers it. Most of these arrive in your MIS as loss ratio, not as fraud.

Damage photographs and liveness frames are fed through a virtual camera or a hooked media pipeline. The image is native quality and the metadata is consistent.Virtual-camera, screen-replay and instrumentation indicators are reported from inside the app, attached to the capture your model scored.
Mechanisms drawn from published insurance-fraud research and regulator advisories: staged and inflated motor and health claims, injected-media attacks on self-serve capture, intermediary-side policy fraud and identity reuse at proposal.
05 — THE FIRST NINETY DAYS

No change to your underwriting policy. One release per surface.

01DAYS 1–30The app, in report-onlySDK into your existing customer app. Nothing is held. Your claims and risk teams see the virtual-camera, device-reuse and tampering rate in their own intake for the first time.
02DAYS 31–60Hold at intake, not at recoveryDevice and capture evidence enters triage before an assessor is dispatched. Injected media and ring devices are held; genuine claimants notice nothing.
03DAYS 61–90Intermediaries, web and the model pathPOSP and white-label builds attested, quote and payment endpoints defended, and the triage models scanned and inventoried with records a reinsurer can audit.
WHAT THE REINSURER AND THE AUDITOR RECEIVE
A signed device and capture record per claimApp build inventory — yours and every intermediary build in the chainFraud-rate reporting separated from loss-ratio reportingModel and adapter inventory for the claims pathIncident timelines assembled inside the CERT-In reporting window
MAPPED TO
IRDAI cyber security guidelinesFraud monitoring frameworkCERT-In · 6 h reportingIntermediary due diligenceDPDP ActClaim turnaround normsOWASP MASVSISO 27001 / SOC 2

IRDAI holds the insurer answerable for the security of the distribution chain it operates, its own apps and its intermediaries'. When a claim is contested or a reinsurer asks how a loss was verified, the device and capture evidence is already assembled, per claim, per release.

NEXT STEP

Send us a month of claims. We'll show you which cameras never saw them.

A device-and-capture assessment across your customer app, claims journey and intermediary builds — virtual-camera and injected-media indicators, device reuse across claims and proposals, emulator clusters, tampered builds and number-not-on-handset proposals.

Run the assessmentTalk to our insurance teamReport-only on your own book first — you see the exposure before anything is held.