Back to blog
Use case·May 25, 2026·7 min read

Claude for PIX risk analysis in Brazil — code, LGPD, and BACEN

Brazilian fintechs using Claude Sonnet 4.6 for real-time PIX risk analysis. Complete code, approximately R$ 0.04 per analysis. LGPD + BACEN Circulars + value-based tiering + Pix/Boleto/international cards + PII pseudonymization + ZDR (only under a direct contract with Anthropic, not through Kunavo).

Brazilian fintechs using Claude for real-time risk analysis of PIX transactions — complete code, cost per transaction, observed latency, and LGPD and BACEN considerations. This is the use case I see most often at Brazilian fintechs in 2026.

Why this works well

Traditional PIX risk analysis uses an ML model trained on fixed features (amount, frequency, time of day). It works, but misses subtle patterns: “This customer usually transfers to their brother, but never amounts like this, and the IP is from another city — probably a SIM swap.” Claude handles this kind of contextual reasoning naturally.

The code

analisar_pix.py
import json
from openai import OpenAI

client = OpenAI(
    api_key="sk-kn-...",
    base_url="https://api.kunavo.com/v1",
)

# No Claude, um response_format json_schema é garantido na resposta; json_object não.
ANALISE = {
    "type": "object",
    "properties": {
        "risco": {"type": "string", "enum": ["baixo", "medio", "alto"]},
        "sinais": {"type": "array", "items": {"type": "string"}},
        "recomendacao": {"type": "string", "enum": ["aprovar", "revisar", "bloquear"]},
        "explicacao_pt_BR": {"type": "string"},
    },
    "required": ["risco", "sinais", "recomendacao", "explicacao_pt_BR"],
    "additionalProperties": False,
}

def analisar_transacao(transacao: dict, historico: list[dict]) -> dict:
    """Detecta sinais de fraude em uma transação PIX usando Claude."""
    historico_txt = "\n".join(
        f"- {t['data']}: R$ {t['valor']:.2f} para {t['destinatario']} ({t['categoria']})"
        for t in historico[-20:]
    )
    resp = client.chat.completions.create(
        model="claude-sonnet-4-6",
        messages=[
            {
                "role": "system",
                "content": [
                    {
                        "type": "text",
                        "text": (
                            "Você é um analista de risco de pagamentos PIX no Brasil. "
                            "Analise a transação atual em relação ao histórico do "
                            "cliente e retorne JSON: "
                            '{"risco": "baixo|medio|alto", '
                            '"sinais": ["..."], '
                            '"recomendacao": "aprovar|revisar|bloquear", '
                            '"explicacao_pt_BR": "..."}'
                        ),
                        "cache_control": {"type": "ephemeral"},
                    },
                ],
            },
            {
                "role": "user",
                "content": (
                    f"## Transação atual\n"
                    f"Data: {transacao['data']}\n"
                    f"Valor: R$ {transacao['valor']:.2f}\n"
                    f"Destinatário: {transacao['destinatario']}\n"
                    f"Origem (IP/dispositivo): {transacao['origem']}\n\n"
                    f"## Histórico recente (últimas 20 transações)\n{historico_txt}"
                ),
            },
        ],
        response_format={"type": "json_schema",
                         "json_schema": {"name": "analise", "schema": ANALISE}},
        max_tokens=400,
    )
    return json.loads(resp.choices[0].message.content)

Cost per analysis: ~$0.008 (about R$ 0.04 at the current exchange rate). At a fintech processing 100,000 PIX transactions per day, that’s ~R$ 4,000/month. For preventing fraud that costs an average of R$ 2,000-5,000 per case, the ROI is extremely positive.

Latency

Claude Sonnet 4.6 via Kunavo from São Paulo (AWS sa-east-1): P50 ~800ms, P99 ~2s. That’s enough for synchronous analysis (blocking before PIX settlement); BACEN allows about 10 seconds before timeout. For very high volumes, consider asynchronous processing: approve first, then analyze and manually review suspicious cases.

What to expect from the output

  • Low risk: Consistent pattern, known recipient, typical time → approve directly
  • Medium risk: 1-2 signals (high amount, new recipient, unusual time) → block and send for manual review or enhanced 2FA
  • High risk: Multiple signals (suspected SIM swap, ghost boleto attempt, money mule pattern) → block and alert the fraud team immediately

LGPD and BACEN — key points

  • Pseudonymize before the LLM: Mask CPF, full name, and bank account before sending. The model sees “[CLIENT_42] transferred R$ X to [DEST_198]”
  • Do not train on the data: Anthropic does not use API requests for training by default. For Enterprise, you can request Zero Data Retention through Kunavo (sales@kunavo.com)
  • Automated decisions: LGPD requires customers to be able to contest an automated decision that affects them. Your UI should offer a “Contest” button, and the explanation_pt_BR returned by the model is a good starting point for the response
  • BACEN resolution on AI: Although there is no specific BACEN regulation on using LLMs for PIX risk yet (2026), the general principles in Circulars 4.018 and 3.978 on governance and risk management apply. Clearly document how the model makes decisions

Tiering by transaction value

You don’t need to run Claude Sonnet on every PIX transaction. Recommended pattern:

  • PIX < R$ 100: pass directly without LLM analysis
  • R$ 100 - R$ 1,000: Claude Haiku 4.5 (10x cheaper), fast analysis
  • R$ 1,000 - R$ 10,000: Claude Sonnet 4.6 (standard analysis)
  • > R$ 10,000: Claude Opus 4.7 (deeper analysis) + parallel human review

Payment and billing

Pay with Pix or an international card. Prices are in USD, and checkout shows the amount converted to Brazilian reais. The 3.5% IOF applies to both payment methods when the payer is in Brazil and the company is foreign. Kunavo does not issue NF-e invoices.

Next steps

  • Create an account with free signup (top up from $10, pay-as-you-go = ~1,250 analyses for a prototype)
  • Configure PII pseudonymization in your backend
  • Run 1,000 real (masked) transactions in shadow mode and compare with your current ML model
  • Iterate on the system prompt using false positives and false negatives as feedback
  • Move to production only with approval from your CRO/compliance team and up-to-date LGPD logs

Full documentation: /docs/quickstart; prompt caching guide to reduce costs by another 70%: prompt caching deep dive.