Wayo is an enterprise-grade financial fraud detection and investigation system. It combines real-time machine learning (XGBoost/LightGBM) for anomaly scoring with an LLM-powered reasoning engine (RAG) that automatically generates human-readable explanations on why specific transactions were flagged as high-risk.
The system follows an event-driven microservices architecture:
- Ingestion & In-Flight Scoring: Transactions stream via Apache Kafka into the ML Scoring Service, which evaluates risk metrics using XGBoost and historical features from the Feature Store.
-
LLM Investigation Engine: High-risk flags (
$>80%$ probability) trigger the LLM Explanation Service. Using RAG over historical user behavior stored in MongoDB, the engine generates actionable explanations (e.g., "Amount is $7\times$ higher than average"). -
Clients:
- Next.js Web Dashboard: Used by fraud analysts to review automated investigation reports and action accounts.
- React Native Mobile App: Provides push notifications and quick action verification for end-users and admins.
wayo/
โโโ clients/
โ โโโ web/ # Next.js Dashboard (Fraud Investigator UI)
โ โโโ mobile/ # React Native / Expo App
โโโ api-gateway/ # Nginx API Gateway & Reverse Proxy
โโโ identity-provider/ # Keycloak Configurations
โโโ service-registry/ # HashiCorp Consul
โโโ service-coordination/ # Apache ZooKeeper
โโโ message-broker/ # Apache Kafka Pipeline
โโโ databases/
โ โโโ database-a/ # PostgreSQL (Transactions & Profiles)
โ โโโ database-b/ # MongoDB (Investigation Audit Logs & LLM Reports)
โโโ microservices/ # FastAPI Backend Microservices
โโโ fraud-detection/
โ โโโ ml-scoring-service/ # XGBoost / LightGBM Scoring Engine
โ โโโ feature-store/ # Real-Time Behavioral Feature Pipeline
โโโ llm-investigator/
โโโ explanation-service/ # LLM Reasoning Engine ("Why Flagged?")
โโโ rag-pipeline/ # RAG Pipeline over Historical User Behavior
| Layer | Component | Technology |
|---|---|---|
| Frontend | Web Dashboard | Next.js, React, TailwindCSS |
| Mobile App | React Native (Expo) | |
| Backend | Microservices Engine | Python 3.11+, FastAPI, Uvicorn |
| Machine Learning | Risk Scoring | XGBoost, LightGBM, Scikit-Learn |
| AI / LLM | Explainability & RAG | OpenAI / Local LLM, LangChain / LlamaIndex |
| Databases | Relational DB | PostgreSQL |
| Document Store | MongoDB | |
| Streaming | Message Broker | Apache Kafka |
| Infrastructure | API Gateway | Nginx |
| Identity Provider | Keycloak | |
| Coordination | Apache ZooKeeper |
- Docker & Docker Compose installed
- Node.js (v18+) for local web development
- Python 3.11+ for local service development
-
Clone the repository:
git clone https://github.com/your-org/wayo.git cd wayo -
Create an
.envfile in the root directory:OPENAI_API_KEY=your_openai_api_key_here POSTGRES_USER=postgres POSTGRES_PASSWORD=password POSTGRES_DB=wayo_db MONGO_INITDB_DATABASE=wayo_investigations
Start the complete microservices stack:
docker-compose up --build -dCheck the running containers:
docker-compose ps| Service | Endpoint / Port | Description |
|---|---|---|
| API Gateway | http://localhost:80 |
Nginx reverse proxy |
| Web Dashboard | http://localhost:3000 |
Next.js Investigator Portal |
| Identity Provider | http://localhost:8080 |
Keycloak Auth Server |
| Consul Registry | http://localhost:8500 |
Service Discovery UI |
| ML Scoring API | http://localhost:8000/docs |
FastAPI Swagger Docs |
| PostgreSQL | localhost:5432 |
Main Database |
| MongoDB | localhost:27017 |
Audit Logs & AI Reports |
You can send a test transaction payload to the ML Scoring Endpoint:
curl -X POST "http://localhost/api/v1/score" \
-H "Content-Type: application/json" \
-d '{
"user_id": "usr_98123",
"amount": 4200.00,
"merchant": "Unrecognized Tech Vendor",
"location": "Lagos, NG",
"device_id": "dev_new_882"
}'Sample Output:
{
"transaction_id": "tx_001928",
"fraud_probability": 0.94,
"flagged": true,
"llm_investigation": {
"summary": "High risk transaction flagged.",
"reasons": [
"Transaction amount is 7x higher than user's normal average ($600.00).",
"Login location changed suddenly from Accra, GH to Lagos, NG.",
"New device detected (dev_new_882).",
"Multiple transactions attempted within 2 minutes."
]
}
}Distributed under the MIT License. See LICENSE for details.