Your stores are staffed around the clock. Your numbers aren't. Being in the store and reviewing the data are two different jobs, and on almost every shift nobody is doing the second one — so theft and error drain the business quietly, and never show up as a line on any report you run today. Keystone compares every register on every shift, ranks what actually looks wrong, and tells you exactly what to check.
It runs every day and stops loss before it happens. It's built to catch skimming and sweethearting — the things no other system can see — and to explain the loss you already know about but can only guess at.
Your stores are covered. Two partners on the floor, an assistant manager when the manager is off — that part works. But running a store and reviewing its data are different jobs, and the second one isn't on anybody's shift.
Nobody standing behind the counter is comparing tonight's basket size to the same shift last month, or this cashier's coffee count against everyone else who works mornings. That comparison happens at corporate — by hand, weeks later, for a fraction of the stores, by the one or two people experienced enough to know what to look for.
And presence isn't a control. The partner working next to you isn't auditing you. Sweethearting and under-ringing look like a normal shift to everyone in the building — which is the whole reason they work.
Most exception reporting flags line voids and no-sales above a threshold — and the people taking money know it. Everything that actually drains a store lives somewhere else, in patterns that only exist across weeks.
Ring the sale, wait for the customer to leave, void the record, keep the cash. The drawer still balances perfectly.
Free coffee for a friend. It never rings as anything at all — it just shows up as quietly lower sales whenever one person is on.
One $1.50 wobble is noise. The same wobble on 40 straight shifts is a pattern — and it stays under every threshold ever set.
All-cash channels with round-number tells: activation-to-settlement gaps, expired-but-live ticket redemption, drive-offs landing on exact dollars.
A refund with no parent sale — the single highest-yield tell in the category, and one almost nobody reports on.
If the report only surfaces someone above a fixed cut, the person just below it never appears — no matter how long the behavior runs.
Your audit finds what didn't match the books — we're short $500. Keystone catches the pattern before it reaches the books — and for the shortages you've already found, it connects the data you're sitting on to the reason they happened.
Today a corporate auditor digs backward and reasons it out: bad audits started around six months ago, a new hire started then, so it's probably her. That's an educated guess about a real person, built from memory. Keystone replaces it with a named, dated pointer — and the comparison that produced it.
“Something's wrong at Shop 14. We're short $500 and we don't know where it's going.”
Somebody now reviews a whole shift of footage, or several, and hopes.
“Cashier Smith, Tuesday evening shift, markdown pattern on FTG items, $47 cumulative — watch 07:42–07:45 on the DVR.”
Your guy watches thirty seconds instead of a whole shift. Same evidence, two orders of magnitude less labor.
Every cashier against their shift peers and against their own history. Every shift, product, and store against its own norm, its district, and the chain. The comparison a great auditor does by hand — run for every store, every day.
A clean exception report doesn't mean a clean fingerprint. Coffee running a third under everyone else on the same morning shift, week after week, is a tell no threshold will ever catch. That's the first thing Keystone puts in front of you — with the comparison that produced it, the dollar exposure, and the exact DVR window to pull.
Illustrative interface with demonstration data. Every row carries the comparison behind it, the dollar rail it belongs to, and what to check — never a conclusion about a person.
Transactions per shift: normal. Voids: normal. Traffic: normal. Items per basket, average ticket, and coffee per shift: well under every peer working the same daypart, consistently, on weekday mornings. That's a pattern worth thirty seconds of footage — and the screen says so in those words.
Demonstration data. The panel reads: “This is a data pattern to check, not a conclusion.” That sentence is enforced by the software, not left to whoever writes the report.
We don't wait for your count to be wrong. We watch the rate things are happening — and a rate moves weeks before a variance does.
An audit is a post-mortem: it tells you what already walked out, three weeks or three months after it started. Keystone is looking for the patterns that precede loss, which is why the intervention lands while the number is still small. Say something at $5 and it usually stops. Wait, and it compounds for six months.
Flagged now — before the shrink shows up on a single count. Nothing is missing yet. That's the point.
Caught the week it starts, not after it's been running a month. And a manager on the void report is a root-cause tell in itself.
Low-level signals never break a threshold on their own. Keystone ties multiple pieces of data together across weeks and finds it early anyway.
Loss surfaces long before it would reach an audit or an exception report — which is the entire difference between preventing it and accounting for it.
The drifting store identified three weeks early, and hit before the number grows. The same visit, at a fifth of the loss.
Roughly three-quarters of loss isn't theft. Early beats severe: coaching the careless 75% costs a conversation, not a case.
A tool that only accuses gets rejected — especially in a company where everyone knows everyone. Keystone spends as much effort exonerating as detecting: the slow cashier who's genuinely fine, the shift that looked off and reconciles, the high void count fully explained by store context.
Roughly three-quarters of retail loss is carelessness, not theft. The valuable, friendlier outcome is coaching that 75% early — and closing the other cases in seconds instead of carrying weeks of quiet suspicion about someone who did nothing wrong.
Detection was never the hard part. Getting anyone to act on it was. Managers get the report and don't follow up — so Keystone makes the first response automatic, and independent of whether anyone feels like doing it.
The fix that works is the early conversation: say something at $5 and it usually stops. Wait, and it compounds for six months. Keystone has that conversation at machine speed — then escalates on a clock if nobody responds, carrying the cost of the delay with it.
A fair, private, coaching-toned heads-up at the first pattern. Never an accusation, never a verdict.
The item, the comparison behind it, the dollar exposure, and the exact camera window to verify.
Ignored items climb automatically. A "managers not following up" report is itself a root-cause signal.
With the cost of inaction attached — and named on the desk of whoever sat on it.
Your auditors hand-count every item at dawn, then reconcile on a calculator across eight handwritten pages. Keystone turns that into a phone that already knows every price and does the case math — and writes the paperwork itself.
A typical audit cycle runs every few weeks per store, which means a pattern starting today may not surface for months. Automating the counting is what frees the auditor to have the conversation that actually prevents the loss.
Every scan resolves price, key, and case math instantly. The count stays human; the data entry disappears.
Close the count and the audit packet generates — variance against theoretical, before she leaves the cooler.
The counter commits their number before any expected value is revealed. Append-only and attributed, with automatic recount requests — so nobody counts to the number.
Demonstration data. Case math, retail value, and running category totals resolve as she scans.
Twenty-five detection signals across the register, the cash, the count, and the all-cash channels — every one carrying an honest confidence label and the comparison that produced it.
Ask any monitoring vendor one question: when your system flags someone and it's wrong, what exactly did it put in writing about that employee — and who's on the hook for it?
Keystone's answer is structural. The system reports data; humans conclude. There are no verdicts, no characterizations, and no accusatory language anywhere in its output — enforced at a single chokepoint in the code that every alert, document, and API response passes through. It's the reason these reports are safe to put in front of HR.
No person is named in any output until a monitoring notice is both delivered and acknowledged. New York Civil Rights Law §52-c is satisfied by the architecture, not by a binder — and the same gate exceeds Connecticut's §31-48d posting standard and Delaware's acknowledgment path. In states with no statute, you're ahead of the law instead of behind a lawsuit. Per-store jurisdiction rules ship in the product.
Every flag carries a conclusion-free dossier, an action ladder, and a permanent trail: event ids, the comparisons behind it, DVR windows, and notice status. Append-only counts, attributed actions, immutable dispositions — evidence built to survive a dispute.
Managers never see across shops — not in rows, and not in composed text either. Cash-pattern, operational, and count-variance dollars stay in three separate books, so a real skim can't hide inside operational noise and no single inflated number ever gets reported.
Built to exceed the applicable standards; multi-state entries are counsel-reviewed per jurisdiction at onboarding. Keystone does not provide legal advice.
Keystone isn't a POS and doesn't compete with one. It reads the journals your systems already produce and sits on top of the registers, cameras, and back office you own. The rollout is a login, not a hardware project.
Journal presets for major convenience POS platforms today; a new export format is a parser, not a project. Part of onboarding is a POS hardening checklist — which controls to turn on in your system, then verification from the journal that they're actually being enforced.
Keystone is DVR-brand-agnostic. Every flag ships exact pull windows — timestamp, register, what to look for — so a 40-hour tape review becomes a targeted two-hour one on the cameras you already own.
Single-tenant deployment per chain: your instance, your database, nothing commingled. You own 100% of your data, with full export and certified deletion terms written into the agreement.
Conservatively, a single convenience store bleeds $100–200 a week in product cost to theft and error — and closer to double that once you count the margin you never earned on it. Across a chain, that's a multi-million-dollar line that never appears as a line.
Recovered, it isn't revenue with costs attached. It's margin already paid for — which is why the return case doesn't depend on catching everything, or even most of it.
Illustrative industry ranges for a chain of this size, not a forecast. The pilot measures yours from your own history.
The credibility is the product. Here's where the boundaries are, before you ask.
Keystone doesn't sell cameras or store footage. It tells your existing DVR exactly where and when to look. Direct click-to-clip against a specific DVR brand is scoped as a pilot deliverable.
No AI watching the checkout. When you add vision or self-checkout, those events become one more input Keystone correlates against the journal and the drawer count.
It doesn't replace perpetual inventory or the back office. It's the layer that audits their honesty — which counts to distrust, and where variance clusters.
Statistical detection against self, peer, and seasonal baselines, with an honest confidence label on every signal, plus early warning matched against your own case history. Every flag can show its work.
No vendor can promise zero false positives, and anyone who does is selling you something. What Keystone claims is that it reviews everything — every transaction, every register, every day — and reports its own gaps when it doesn't.
Most loss is carelessness. The default posture is coaching early and clearing the innocent quickly; the investigation path exists, but it isn't the point.
Keystone runs on one district's actual numbers, calibrates to your baselines, and reports back exactly two things: the hours returned, and the loss your current reports missed.
Small enough to approve in one conversation. You see the return on paper before anything scales — including a dated accounting of loss that already happened, pulled from your own history.
Wire the district's data. Comparison engine and weekly packs running on real baselines. Parsers validated against your actual journal exports.
Alerts and the accountability loop go live. First items surfaced and verified on camera. Notice-delivery flow executed on your HR rails.
Before and after: the hours returned, the exposure surfaced, the retro autopsy, and the number as it scales chain-wide.
The fastest walkthrough there is: we map every column of your existing report to the Keystone signal that covers it — and then show you a class of loss it structurally cannot represent.