Data Cleanroom · Use case
Telco–Bank Fraud Prevention
Most account takeovers and scam-driven payments start on the phone network long before money moves. The Data Cleanroom lets a bank check a customer against its telco partner’s live risk signals at the moment of a login or transfer — and get back only a verdict, never the telco’s data.
The Problem
Telcos see critical signals that banks miss
A fraudster who wants into a bank account usually needs the victim’s phone first. They swap the SIM to receive one-time passwords, turn on call forwarding to hijack verification calls, or move the number to a new handset. In scams, the victim is often on a call with the fraudster while they approve the transfer.
All of this is visible to the telco. None of it is visible to the bank — which sees a correct password, a valid OTP and a transfer that looks legitimate. By the time the fraud is reported, the money is gone.
The obvious fix — sharing data — is exactly what neither side can do. Subscriber data is regulated and commercially sensitive, customer lists can’t be exposed to a partner, and copying data between organizations creates new privacy and security risk.
The Signals
Signals the telco sees
Each of these can be checked for a single customer, at the moment of a risky action, without the bank ever seeing the underlying records.
Recent SIM swap
The number moved to a new SIM shortly before a login or payment — the classic setup for OTP interception.
Call forwarding turned on
Calls to the customer are being diverted, so verification calls reach the fraudster instead.
Device change
The SIM is now in a different handset than the one the customer normally uses.
Active call during a transfer
The customer is on a call while approving a payment — a common sign of a live scam.
Number tenure
A brand-new or recently recycled number carries more risk than one held for years.
Location mismatch
The phone is somewhere inconsistent with the transaction or the customer’s usual pattern.
How It Works
How the Data Cleanroom closes the gap
Connect in place
The bank and the telco each connect their own data to the cleanroom. Nothing is copied to the other side or to a central store.
Match privately
When a risky login or transfer happens, the bank submits an encrypted phone number. It’s matched against the telco’s records without either side learning the other’s customer list.
Compute the risk
The agreed rules or model combine the telco’s signals with the bank’s transaction context, using multi-party computation on encrypted inputs.
Release only the verdict
The bank receives a risk score or clear flags — such as “SIM changed in the last 48 hours” — and decides to allow, step up verification, or hold the payment.
The Outcome
What this changes
Who It's For
Who it’s for
Banks & fintechs
Add telco risk signals to login, payment and onboarding checks in real time.
Payment providers & wallets
Screen transfers and account changes for signs of SIM-based takeover.
Telecom operators
Offer fraud intelligence to financial partners without ever handing over subscriber data.
Privacy
Private by design
No customer lists exchanged
Neither party learns who the other’s customers are.
Data stays at its source
Telco records never leave the telco; bank data never leaves the bank.
Only the agreed output
The result released is limited to the score or flags both sides agreed on.
Auditable
Every query is logged, so each check can be reviewed and justified.