Licensing · banks, telecoms, insurers, payment firms
Your controls stop unauthorised payments.
This is about the authorised ones.
Nothing in your stack fires when a customer, having been worked on for five weeks, initiates a payment themselves and means it. The last control in that chain is a person’s judgement. HeartOSINT trains it, and — this is the part nobody else does — measures it.
No demo wall. Everything a licensee’s people will do is on this site right now, unmetered and without an account.
Since October 2024 this stopped being a training budget and became a liability line.
A UK payment firm must now reimburse an APP scam victim up to £85,000, within five business days, and the cost is split equally between the sending and the receiving institution. Awareness training protects you from an incident you might have had. This sits against money you are already paying out.
- UK APP losses, 2025
- £576.4mUp 19% in a year, across 248,070 cases.
- Average investment-fraud case
- £14,873The highest-value category, up 40% in a year — and one of the four this product is built for.
- Your half of one of them
- £7,436Which is the number the arithmetic below runs on.
Divide whatever we quote you by £7,436, and that is how many prevented investment-fraud cases the licence has to be worth.
There were 14,893 of them nationally last year, so for most institutions the answer is a number in single figures. We are not going to tell you what share of yours this prevents — nobody honestly can before a pilot, which is exactly what a pilot is for. We are giving you the arithmetic so you can decide whether it is plausible before you spend an hour on us.
Figures: UK Finance Annual Fraud Report 2026 and the PSR reimbursement policy statement. The regime works at population scale: the PSR’s independent evaluation in July 2026 found APP losses over Faster Payments fell about 21%, roughly £73m a year. That is the whole regime, not this product — we quote it because it shows the category moves, not because we are claiming it.
The Netherlands, Germany, the rest of the EU
In 2027 you will be required to run this.
In 2026 you can still have a baseline.
PSD3 and the Payment Services Regulation reached political agreement in November 2025 and are expected to enter into force in 2027. Two provisions are ours: impersonation fraud becomes reimbursable, which brings the UK liability across the Channel — and payment service providers are obliged to run customer fraud-awareness programmes and structured staff fraud training, and to invest in public education on recognising fraud.
Running a programme is straightforward. Evidencing that it worked is not, and that is what a supervisor asks for. A firm that starts in 2027 has one measurement and nothing to compare it against. A firm that starts now has a year of movement to show, which is the only honest reason to do this sooner rather than later.
One decision:
whose recognition are you measuring?
Your staff, or your customers. That choice is the licence. Everything below it is an addition to whichever you pick, and each one says what state it is genuinely in — because a pilot that discovers the difference in week three is a pilot that ends badly for both of us.
Workforce licence
Security awareness, financial crime training
A join code per department. Your people use the site they can already see, and you get a report showing which techniques got past which cohort. Nobody creates an account, and you never receive a list of who did what.
Working now
Awareness licence
Customer protection, retail marketing
The same product in front of your customers, linked from online banking or from the warning they see before confirming a payment. You get aggregate figures on what your customer base does not recognise. Your own hostname and logo is about a week of work and is not built yet.
Working now · co-branding in build
Casework pack · built to order
Your own anonymised cases written into scenarios, with your procedures spliced in. Packs of six, quoted separately, because it is our time rather than software.
Benchmark · not yet possible
Annual, across licensees, on what gets past staff versus customers. With two licensees the sample would identify them both, so it comes later or not at all.
How a pilot runs
Ninety days, one cohort, and one email from you.
- Week 0Us
We set it up
We create your organisation and issue join codes, one per department if you want the departments compared. Takes an afternoon and needs nothing from you but a name.
- Weeks 1–2You
Your cohort joins
You send one email with a link and a code. Your people enter the code once. Nobody creates an account, nobody downloads anything, and nobody gives us a name.
- Weeks 3–11Them
They use it
In their own time, at their own pace. Nothing is timed, nothing is chased, and leaving a conversation early counts as a correct outcome rather than a failure.
- Week 12Us
You get the measurement
Which techniques got past which cohort, against the national baseline. It looks like this, and it is yours to keep whatever you decide next.
Specimen · invented figures
Example Bank · retail
Quarter to 30 June · 412 people
Still working, worst first
You / national
- Manufactured urgency74% / 58%
- Borrowed authority61% / 55%
- The withdrawal that works52% / 49%
- Investment pitch38% / 47%
- Request for secrecy22% / 41%
A specimen with invented figures, not a real organisation. The real one arrives as a printable page and a spreadsheet, names no individual, and compares each technique with everybody who has used the free service.
What it costs your IT team
Nothing to install, nothing to integrate, no SSO, no network change, no software inside your perimeter. It is a website your people already have access to.
What it costs your people
Between twenty minutes and an hour, whenever suits them. There is no course to complete and no certificate to chase.
What you are left holding
The report, in both formats, whether or not you go ahead. The fee comes off the first year in full if you do.
It is priced below the threshold that triggers a full procurement exercise at most institutions, because the first conversation should not be about an annual contract. The licence itself is an annual figure banded by your size. Tell us roughly how many people or customers are in scope and you will have it the same day.
And what you do with it
You already measure losses.
Nothing you have moves before one.
Every fraud figure on your board pack counts the times you were too late, and none of them tells you where the next one comes from. A phishing click-rate does not either: the frauds producing these losses take five weeks, involve no link, and end with the victim doing something entirely deliberate.
Recognition is measurable before the money moves and it responds to what you do. So the report is not a training record. It is a list, in order, of which techniques currently work on the people you are responsible for. Three things follow.
- 01
Re-word the warning they push past
If manufactured urgency gets past two thirds of your customers and impersonated authority does not, the warning before confirming a payment should name urgency rather than warn in general. That is the shortest path from this report to your losses: it changes a control you already operate, on the screen where the money leaves.
- 02
Send the next campaign to the cohort that needs it
The figures come back by cohort, so the branch that has not started and the department that keeps missing the same thing are both visible. You stop sending one message to everybody.
- 03
Show a supervisor movement, not attendance
From 2027 you must run customer fraud-awareness programmes and evidence them. Every other method produces a completion rate; this produces the same measurement twelve months apart.
None of it requires you to take our figure over yours. Your own fraud data already names the techniques in the cases you paid out on. Where the two agree you have a priority; where they disagree you have a question worth asking.
Ask about a pilotWhat this does not do
It is not a detection product
It does not sit in your payment flow or stop anything in real time. It changes the person, which is the part your existing tools cannot reach.
It does not publish an accuracy figure yet
The labelled set is built, 317 messages, and has not been run. When there is a number it will appear with its method beside it, or not at all.
It will not tell you who failed
Not as a setting, not on request, not for a regulator. A report naming individuals turns training into surveillance, and the first employee to work that out tells everybody else.