Masenu · Security Research Lab
First product Adoor

One fraud report protects the whole network.

Adoor is Masenu's first product — shared fraud intelligence that lets telcos, fintechs and banks trade confirmed fraud signals on hashed identifiers and get a real-time risk decision before money moves. A fraudster gets one shot per network, not one per institution.

Identifiers hashed at your edge — raw data never reaches Adoor

Adoor/Real-time risk
Listening
Partner's identifier01 / 01
+233 55 ••• •221
Inbound payout · GHS 4,100
Consortium signalAwaiting
Signal strength24%
LowCritical
One identifier inlisteningdecision out
How it works

One identifier in. A network-wide decision out.

No raw phone number, account or ID ever leaves a member's systems. Only one-way keyed digests collide across the network.

01/Hash
Hash at the edge

Members normalize and HMAC-hash identifiers inside their own systems. Only keyed digests reach Adoor — never a raw phone number, account or ID.

02/Match
Match across the network

The same real-world identifier produces an identical digest for every member, so confirmed fraud collides mathematically — and a graph engine links related digests into rings.

03/Act
Act in real time

Before onboarding or payout, one API call returns a scored, explainable decision — allow, step-up, review or block — engineered for p95 under 150 ms.

Two-step hashing

One identifier. Two peppers. Zero exposure.

The same real-world identifier deterministically produces the same key across the whole network — so confirmed fraud collides — while nothing stored can be turned back into a phone number, account or ID. It's the sequence the panel above steps through.

01/Your edge · raw
Partner's identifier
+233 55 ••• •221

A raw phone, wallet, account or ID — inside your systems. It never leaves; Adoor never receives it.

02/Consortium pepper
Edge hash · h1
4a89a523de05c7f1b0…

Your SDK normalizes and HMAC-SHA256s the value with the shared consortium pepper. The same identifier makes the same h1 for every member — that's what lets hashes join.

03/Central pepper
Adoor hash · h2
e7c10f9ab2d46583a1…

Adoor applies a second, platform-only pepper server-side. h2 is the stored join key — it never leaves the server, and can't be reversed to raw PII.

Deterministic

Same input, same hash — so the network joins reports without anyone sharing raw data.

One-way

h2 is a keyed digest; no stored value can be turned back into a phone number or account.

Split-key

h1 needs your consortium pepper; h2 needs Adoor's central pepper. Neither side ever holds both.

The thesis

A ring is invisible to one institution — and obvious to the network.

Each member sees only its own fragment of the fraud. Correlated across the consortium, the pattern that no one could see alone becomes a detected ring.

Telco
Fintech
Bank
Three partial views
Correlate
RING/Emergent signal
detected

One coordinated fraud ring — seven identifiers across three sectors — that no member reported in full.

Principles

Neutral by architecture, not by promise.

01
Incapable of betrayal

Adoor never holds raw PII, so it cannot leak, sell, or be compelled to produce it. Contributor identity is reduced to sector + country — reporting never advertises a breach.

02
Explainable, disputable

Every risk score carries human-readable reasons and a versioned ruleset. Anyone flagged can dispute; contested reports stop driving decisions immediately.

03
Tamper-evident by design

Every lookup, report and admin action lands in an append-only, hash-chained audit log. Built SOC 2-ready from the first commit.

Adoor Guardian

Had your identity used by fraudsters before?

Guardian puts a protective marker on your identifiers — extra verification for anyone using them, and a log of who checked. Fraud victims get Shield free.