All evals
I

Eval directory

Evals for Incandor

Eval coverage for Incandor, mapped from its public product surface.

About Incandor

Incandor is a behavioral intelligence platform for fraud and abuse detection that builds a "behavioral map" of how accounts are operated over time. It surfaces account takeovers and mule handoffs by detecting when control of an account shifts to a new person, and identifies when one operator runs many accounts. It also covers fraud ring mapping, flagging behavioral regions tied to known bad operators, and duress detection.

Industry

behavioral fraud & abuse detection

Use the eval library for Incandor

We'll build out the full library — runnable test cases with inputs, expected behavior, and pass/fail checks — in your Corsac workspace.

Generate your own →

Coverage map

What would you measure for Incandor?

6 scoring areas · 21 capabilities mapped · grounded in 5 cited pages

Every eval set is graded on

  • Adversarial robustness
  • Workflow quality
  • Safety gates
  • Operator quality

Pass/Fail + LLM judge 1–5 · critical severity flags · negative controls

01

Account Handover Detection

Surfacing the moment control of an account shifts to a new person, covering both account takeover and mule handoff, ideally before damage occurs.

Our behavioral map tracks every account over time and surfaces the moment control shifts, before any damage is done. www.incandor.com

Mapped capabilities

4 capabilities

  • Takeover onset detection

    Identify the session where the operator of an established account changes.

  • Mule handoff detection

    Distinguish a voluntary handoff of account control from an adversarial takeover.

  • Pre-damage timing

    Raise the handover signal ahead of the first irreversible action on the account.

  • Legitimate-change tolerance

    Avoid treating benign operator variation within one account as a control shift.

Illustrative example

Input
An account with two years of consistent session history is operated in a new session by a different person, who then initiates a withdrawal.
Expected behavior
Incandor flags the session as a control shift rather than routine anomalous behavior, and surfaces it before the withdrawal completes rather than after the fact.

02

Shared Operator Detection

Detecting when the same person is operating multiple accounts, the behavioral fingerprint typical of criminal patterns that optimize for scale.

Detect when the same person is operating multiple accounts. www.incandor.com

Mapped capabilities

3 capabilities

  • Cross-account fingerprint match

    Link accounts that share a single behavioral operator signature.

  • Scale-pattern surfacing

    Surface one-operator-to-many-accounts clusters as a single reviewable finding.

  • Shared-device disambiguation

    Separate a shared operator from merely shared context around distinct operators.

03

Fraud Ring Mapping

Expanding a single confirmed case into the full shape of a ring by combining shared-operator links and coordinated activity across accounts.

We can map the full shape of a fraud ring from a single confirmed case. www.incandor.com

Mapped capabilities

3 capabilities

  • Seed-case expansion

    Map the ring outward from one confirmed fraudulent account.

  • Coordination detection

    Identify groups acting in concert across separate accounts.

  • Ring boundary definition

    Report which accounts belong to the ring and which are adjacent but unlinked.

04

Flagged Behavioral Regions

Treating each confirmed bad operator as owning a permanent region of the behavioral map, so new accounts entering that region are caught at the door.

We detect when accounts share the same operator, when groups coordinate across accounts www.incandor.com

Mapped capabilities

4 capabilities

  • Region assignment on confirmation

    Carve and flag a map region when an operator is confirmed bad.

  • New-session containment check

    Flag a new session the moment it lands inside a flagged region.

  • Persistence of flags

    Keep a flagged region enforceable against later accounts and sessions.

  • Block-at-entry behavior

    Act on region membership before the account establishes activity.

Illustrative example

Input
A brand-new account with no prior history opens its first session, which projects into a map region already flagged from a previously confirmed bad operator.
Expected behavior
The session is flagged on arrival based on region membership alone, without waiting for accumulated history on the new account, and the finding cites the confirmed operator whose region it entered.

05

Duress Detection

Projecting sessions along a stress and duress axis so teams can distinguish a willing user from a coerced one before an irreversible transaction goes through.

projecting every session along a stress and duress axis www.incandor.com

Mapped capabilities

3 capabilities

  • Coercion signal detection

    Detect the behavioral change that accompanies a coerced session.

  • Willing-versus-coerced separation

    Distinguish a genuine user acting freely from the same user under duress.

  • Pre-transaction timing

    Surface duress before the irreversible transaction completes.

06

Behavioral Map & Session Signals

The continuous per-session substrate the other areas read from: tracking each account over time and projecting arriving sessions into the map.

Every confirmed bad operator carves out a region of the behavioral map that is now permanently theirs. www.incandor.com

Mapped capabilities

4 capabilities

  • Longitudinal account tracking

    Maintain a per-account behavioral history across sessions over time.

  • Session projection

    Place each arriving session into the behavioral map as it lands.

  • Anomaly and bot/agent signals

    Distinguish anomalous behavior and bot or agent activity from human operation.

  • Confirmed-case feedback

    Fold a confirmed fraudulent session back into the map for future detection.

Coverage is mapped from Incandor's public pages (5 crawled). Examples are illustrative, not real test cases. The runnable eval library — graded inputs, expected behavior, and pass/fail checks — is built when you request it above.

Frequently asked questions

What do the Corsac evals for Incandor test?+

The coverage map is generated from Incandor's own public product surface (behavioral fraud & abuse detection): 6 scoring areas — Account Handover Detection, Shared Operator Detection, and Fraud Ring Mapping, and more — spanning 21 mapped capabilities, each graded on adversarial robustness, workflow quality, safety gates, and operator quality once the library is built.

How are the Incandor evals scored?+

Every case generated for Incandor — across Account Handover Detection and Shared Operator Detection and the other mapped areas — is graded with pass/fail checks plus an LLM judge scoring 1–5 against its expected behavior, with critical-severity flags and negative controls. Only judge-passed evals are published.

How many test cases does the Incandor library include?+

The full Incandor library is built on request. The coverage map spans 6 areas and 21 capabilities (for example, Takeover onset detection and Mule handoff detection under Account Handover Detection); each becomes graded test cases — inputs, expected behavior, pass/fail checks — in your Corsac workspace.

How do I run these evals against Incandor or my own agent?+

Request the library with your work email above. We'll build out all 6 mapped Incandor areas and set them up in a Corsac workspace, where you can run every test case against Incandor or your own agent with your own data.