> ## Documentation Index
> Fetch the complete documentation index at: https://support.wepayments.com.br/llms.txt
> Use this file to discover all available pages before exploring further.

# Anti-Fraud and MED Notifications

This guide covers WEpayments' anti-fraud procedures for credit card transactions, MED (Special Return Mechanism) notifications from the Central Bank of Brazil, and the processes for preventive analysis and value recovery for suspected Payout fraud.

## **Preventive Anti-Fraud Analysis**

As a Payment Institution regulated by the Central Bank of Brazil, WEpayments operates under strict regulatory guidelines for risk management and fraud prevention. To ensure the integrity of the financial ecosystem and protect our partners' operations, we maintain continuous monitoring and analysis routines for suspicious transactions.

### **Why are transactions preventively held?**

Occasionally, certain transactions may be preventively held for additional verification before final decision. This occurs for:

| **Reason**                | **Description**                                   |
| :------------------------ | :------------------------------------------------ |
| **Ecosystem protection**  | Ensuring financial integrity                      |
| **Regulatory compliance** | Meeting Central Bank requirements                 |
| **Fraud prevention**      | Identifying suspicious patterns before completion |
| **Partner security**      | Protecting our merchants' operations              |

### **Confidentiality of anti-fraud rules**

In accordance with current regulatory standards and best practices in the financial market, the guidelines, parameters, and anti-fraud rule engines adopted by WEpayments are **strictly confidential**.

> 💡 This policy ensures the effectiveness of the anti-fraud system, preventing malicious actors from circumventing security mechanisms.

## **SLA for Preventive Analysis**

Transactions held for preventive analysis follow this service level agreement:

| **Period**                         | **SLA for analysis completion**        |
| :--------------------------------- | :------------------------------------- |
| **Business days (business hours)** | Up to **3 hours**                      |
| **Weekends and holidays**          | Completed on the **next business day** |

> 💡 Transactions held during weekends or holidays will be analyzed as soon as regular business hours resume.

## **Treatment and Notification of Rejected Transactions**

Transactions that do not comply with security policies or exceed operational risk limits will be duly rejected.

### **How WEpayments notifies rejections**

To ensure transparency and ongoing risk management support, we operate as follows:

| **Channel**                   | **What is displayed**                                                                                                          |
| :---------------------------- | :----------------------------------------------------------------------------------------------------------------------------- |
| **Merchant Dashboard**        | Standard status: **"Rejected by Preventive Analysis"**                                                                         |
| **Webhook**                   | Same status sent via notification                                                                                              |
| **Orientative notifications** | In specific cases (e.g., transactions with fraud history), our team may actively notify the merchant with guidance and context |
| **Active support**            | If you identify a rejection and need additional direction, our team is available through official support channels             |

> 💡 Active support respects institutional confidentiality limits, providing guidance without compromising the confidentiality of anti-fraud rules.

## **Credit Card Anti-Fraud Procedure**

The anti-fraud system is provided by our card processing partner and applies exclusively to **Credit Card** transactions.

### **How the anti-fraud system works**

| **Component**               | **Description**                                                      |
| :-------------------------- | :------------------------------------------------------------------- |
| **Neural network**          | Interconnects multiple databases with dynamic indexing rules         |
| **Machine learning engine** | Feeds risk analysis rule trees with behavioral pattern data          |
| **Rule trees**              | Map scenario-specific behavioral patterns to prevent false positives |

> 💡 The system is designed to ensure that false positives do not contaminate the analyses.

### **Critical field: Email address**

The **email address** is one of the most important fields for fraud checking. Incorrect email addresses can trigger false fraud alerts.

| **Best practice**                 | **Why**                                 |
| :-------------------------------- | :-------------------------------------- |
| Always fill email correctly       | Prevents unnecessary fraud flags        |
| Use business emails when possible | More reliable than free email providers |
| Verify email format               | Simple typos cause false positives      |

### **Free and block lists**

You can create custom lists to improve approval rates without compromising security:

| **List type**  | **Effect**                                             |
| :------------- | :----------------------------------------------------- |
| **Free list**  | Releases buyers according to their consumption profile |
| **Block list** | Blocks buyers based on risk profile                    |

> 💡 These lists help increase purchase approval rates for legitimate customers while maintaining security.

## **What is MED (Special Return Mechanism)?**

The **Special Return Mechanism (MED)** is a Central Bank of Brazil process that allows banks to return funds from suspected fraudulent transactions. It is part of the PIX system's security framework.

### **When MED is triggered**

| **Scenario**         | **Description**                                   |
| :------------------- | :------------------------------------------------ |
| **Fraud complaint**  | A customer reports an unauthorized transaction    |
| **Bank suspicion**   | A bank identifies potentially fraudulent activity |
| **System detection** | Automated fraud detection flags a transaction     |

## **How WEpayments handles MED notifications**

### **Step-by-step process**

| **Step**                      | **Description**                                                                                                |
| :---------------------------- | :------------------------------------------------------------------------------------------------------------- |
| **1. Notification received**  | WEpayments receives a MED notification from the Central Bank or a partner bank                                 |
| **2. Transaction identified** | The suspected transaction is located and frozen (if funds are still available)                                 |
| **3. Account review**         | Your account may be temporarily restricted during the investigation                                            |
| **4. Evidence requested**     | You may be asked to provide documentation supporting the legitimacy of the transaction                         |
| **5. Final decision**         | Funds are either returned to the originator (if fraud is confirmed) or released (if transaction is legitimate) |

### **Your responsibilities when a MED notification occurs**

| **Responsibility**   | **Action required**                                        |
| :------------------- | :--------------------------------------------------------- |
| **Respond promptly** | Answer compliance requests as quickly as possible          |
| **Provide evidence** | Submit proof of service delivery or product shipment       |
| **Maintain records** | Keep customer communications and transaction history       |
| **Cooperate fully**  | Work with our compliance team throughout the investigation |

## **Value Recovery Request (Payout)**

If you identify **Payout** transactions from your WE account with suspected fraud, you may request **Value Recovery** under the mechanism established by the Central Bank.

### **When to contact WEpayments**

Upon identifying a suspected fraudulent transaction, contact WEpayments **immediately** through one of our official channels:

| **Channel**  | **Contact**                                         |
| :----------- | :-------------------------------------------------- |
| **Email**    | [cs@wepayments.com.br](mailto:cs@wepayments.com.br) |
| **WhatsApp** | +55 41 92667191                                     |

> 💡 These channels will automatically trigger ticket opening with our **24/7** support team.

### **How to report fraud**

To ensure your request is identified and prioritized:

| **Item**                  | **Instruction**                                                                                     |
| :------------------------ | :-------------------------------------------------------------------------------------------------- |
| **Required phrase**       | Include in your ticket: **"Value Recovery Request – Fraud Reason"**                                 |
| **Required information**  | End-to-end or invoice of the Payout transaction + brief description of the suspected fraud          |
| **Multiple transactions** | If there are more than 10 transactions, send the list in a **spreadsheet** to facilitate processing |

### **What happens after ticket opening**

After receiving your request:

| **Step**                    | **Description**                                                                                                               |
| :-------------------------- | :---------------------------------------------------------------------------------------------------------------------------- |
| **1. Immediate activation** | WEpayments duty team will be activated immediately                                                                            |
| **2. DICT registration**    | The Value Recovery request will be registered in DICT, the Central Bank system responsible for the PIX value return mechanism |

### **Important**

> ⚠️ **WEpayments does not analyze the reported fraud and does not decide on the return of funds.** The analysis and final decision are made by the banks involved in the transactions, according to Central Bank rules.

### **How the analysis process works**

After the request is opened:

| **Step**             | **Description**                                                           |
| :------------------- | :------------------------------------------------------------------------ |
| **1. Notifications** | DICT sends notifications to the receiving banks                           |
| **2. Analysis**      | The involved banks analyze the fraud suspicion                            |
| **3. Return**        | If funds are available, total or partial return may occur                 |
| **4. Updates**       | You will receive updates through the same channel used to open the ticket |

#### **Regulatory deadline**

> 📅 The estimated regulatory deadline for analysis and conclusion is **up to 12 days**.

### **Possible outcomes**

| **Outcome**              | **Description**                                                                                                    |
| :----------------------- | :----------------------------------------------------------------------------------------------------------------- |
| **Value returned**       | If the involved banks confirm fraud and funds are available, recovered amounts will be credited to your WE account |
| **Request not approved** | If banks conclude no fraud occurred or no funds are available, the request will be closed without return           |

### **Deadline to request recovery**

> 📅 Value Recovery requests can be made up to **80 calendar days** from the transaction date. After this period, the mechanism can no longer be used.

## **Fraud and MED Prevention**

### **Best practices for merchants**

| **Practice**                      | **Why it helps**                                   |
| :-------------------------------- | :------------------------------------------------- |
| **Verify customer identity**      | Reduces unauthorized transactions                  |
| **Keep delivery proofs**          | Evidence if challenged                             |
| **Monitor unusual patterns**      | Detect potential fraud early                       |
| **Use anti-fraud tools**          | WEpayments' fraud system helps screen transactions |
| **Respond quickly to compliance** | Prevents escalation                                |

### **For PIX transactions**

| **Prevention measure**           | **Description**                           |
| :------------------------------- | :---------------------------------------- |
| **Validate PIX keys**            | Ensure keys are correct before processing |
| **Confirm beneficiary identity** | Verify you are paying the correct person  |
| **Keep transaction records**     | Maintain evidence of legitimate payments  |

## **Next steps**

* **Report fraud:** Contact immediately via [cs@wepayments.com.br](mailto:cs@wepayments.com.br) or WhatsApp +55 41 92667191
* **Track Analysis:** You can contact [antifraude@wepayments.com.br](mailto:antifraude@wepayments.com.br) to ask for updates on the process.
* **Prevent fraud:** Maintain complete records and respond quickly to compliance requests
