New · MCP endpoint live

Fraud detection,
inside the AI you already use.

RILLA Shield exposes its Australian fraud-detection engine over the Model Context Protocol. Connect once from Claude, ChatGPT, Copilot or Cursor — your assistant can then check invoices, ABNs, BSBs, cousin domains and suspicious emails without you leaving the chat.

MCP server URL
https://rillashield.app/mcp

Public endpoint · rate-limited per IP (5/hr anonymous, 100/hr with partner API key) · optionalX-MCP-API-Key header for white-label / referral partners. Streamable HTTP transport.

Connect in 30 seconds

Claude Desktop / Claude.ai

  1. 1Settings → Connectors → Add custom connector
  2. 2Name: RILLA Shield
  3. 3Paste the URL above
  4. 4Save. New tools appear in the tool tray.

ChatGPT (Pro / Team / Enterprise)

  1. 1Settings → Connectors → Add
  2. 2Choose 'Custom MCP server'
  3. 3Paste the URL, allow tool discovery
  4. 4Ask ChatGPT to 'check this invoice for fraud'.

Cursor

  1. 1Cursor Settings → MCP → Add new server
  2. 2Type: streamable-http
  3. 3URL: the address above
  4. 4Save. Tools show in the composer.

Any MCP-compatible AI

  1. 1Add a new MCP server
  2. 2Transport: streamable HTTP
  3. 3URL: https://rillashield.app/mcp
  4. 45 tools discovered automatically.

What your AI can do

Five tools, one engine. Same detection logic that powers the RILLA Shield web app — every response is evidence and risk score, never a payment verdict.

check_invoice

Full 15-layer fraud engine on any invoice or payment email.

Input
Raw invoice/email text (ABN, BSB, sender, body).
Returns
Risk score 0–100, red flags with severity, evidence, recommended action.
check_email

Business Email Compromise, phishing and bank-change screening.

Input
Email text with From / Reply-To / Subject / body (raw .eml fine).
Returns
Risk score, flagged signals (lookalike sender, urgency, mid-thread bank change).
check_abn

Validates any ABN via the ATO mod-89 checksum.

Input
An ABN — spaces, hyphens, formatting all accepted.
Returns
Valid / invalid, formatted ABN, plain-English reason.
check_bsb

Identifies the bank + flags fraud-prone BSB prefixes.

Input
6-digit BSB (062-000, 062000, etc.).
Returns
Institution, risk level, notes on discontinued or elevated-risk banks.
check_domain

Cousin/lookalike domain detector for BEC attacks.

Input
Suspicious domain + one or more known-legitimate reference domains.
Returns
Lookalike score, edit distance, specific tricks detected (rn↔m, wrong TLD, hyphen).

Try it now

After connecting, paste this into your assistant. It'll pick the right RILLA Shield tool automatically.

Sample prompt
I just received this invoice from a supplier. Can you use RILLA Shield to check if it's genuine?

From: accounts@bunnnings-trade.co
Subject: Updated banking details — please pay latest invoice to new account
Body: Hi mate, we've changed banks. Please pay invoice #4471 ($12,480 inc GST) into:

BSB 802-985
Account 12345678
Account name: Bunnings Trade Supplies

ABN 12 345 678 901

Urgent — needs to be paid today so we can release the timber order.

Evidence, not verdicts.

RILLA Shield returns risk scores and forensic evidence — it never says "safe to pay" or "approved". Final approval decisions rest with the human payer. Tools are rate-limited, stateless, and do not retain the content submitted through the public MCP endpoint.

Streamable HTTPMCP 2025-06-18Made in Australia