Home/news/How Sentinela tracks the fraud trail that MED 2.0 now requires
news
How Sentinela tracks the fraud trail that MED 2.0 now requires
Payments High Risk
24 Jul 2026 · 2 min read
MED 2.0 changed the job from “find the suspicious transaction” to “follow the money across the entire account chain, in real time, and prove what you saw.” For PSPs, that is not a manual review problem; it is a system design problem.
Sentinela, the compliance and antifraud engine from Connect PSP, does this through its Advanced Transaction Tracking Module. The module is built to respond to the new MED 2.0 mechanism by reconstructing the flow of value across a chain of accounts, not by looking at isolated transactions one by one.
The core of the tracking layer is a transaction graph. Each account is modeled as a node and each Pix as an edge, so the system can map the network of connections rather than a single payment. When a root transaction is disputed, the engine traverses that graph to rebuild the path the money took through the chain — the same view MED 2.0 now requires for recovery from any link in the chain.
Sentinela also assigns each transaction a real-time risk score based on behavioral signals: transfer speed, value dispersion, newly opened accounts, and patterns typical of laranjas (strawman accounts). A high score triggers verification before the money moves further, turning a Notificação de Infração that would arrive days later into a decision made at the moment of the transaction.
The third pillar is an immutable audit trail. Every decision is logged: the score assigned, the path traced, the notification answered, and the balance blocked. That is the evidence regulators and banking partners now expect — not “trust us,” but a record of exactly what was seen, when, and why.
The point is that these are not three separate tools. The graph feeds the score, the score triggers the block, and the block feeds the audit trail, all within the same payment infrastructure that already processes the transactions. In practice, that means MED 2.0 response is not bolted on after the fact; it is part of the operation’s architecture before the first notification lands.
For high-risk PSPs, the useful takeaway is simple: when the rule requires real-time chain tracing with proof, the anti-fraud stack has to behave like infrastructure, not like a queue of manual exceptions. MED 2.0 is asking for architecture, and architecture does not get improvised under deadline.