Skip to content

Platform / Prevent

Fraud Protection

Real-time detection of account takeover, payment fraud and bot-driven abuse — scored client-side, without adding a step to your customer's checkout.

<40 ms

decision latency at the edge

What you receive

  • Client-side digital identity and device fingerprinting
  • Behavioural anomaly scoring returned in under 40 ms
  • Chargeback and mule-account reduction reporting
  • Rules you control, not a black box

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    Your dispute ratio is close to the threshold

    Once a card scheme puts an acquirer or a merchant into a monitoring programme, the cost stops being the fraud itself and becomes the fees, the remediation plan and your acquirer's appetite for keeping you. Authorisation is the last point at which a decline is cheaper than a dispute; everything after it is remediation.

  • 02

    Someone else's breach is hitting your login

    Credential stuffing works because people reuse passwords — a list bought elsewhere is replayed against your sign-in until a small fraction succeeds, and the account is drained or resold. That has to be caught at authentication, before any transaction your fraud team can see.

  • 03

    You have just added withdrawals or payouts

    Sign-up incentives, refunds, instant withdrawals and payout paths are farmed within days of launch, usually by automation and by mule accounts opened patiently months in advance. Device and behavioural signals are what separate the farm from the customers you want.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer. We establish what you already run, where the gaps actually are, and whether a module earns its place beside your existing tooling.

  2. 02

    Connect and baseline

    We connect the data sources the module reads and spend the first weeks learning what normal looks like in your estate. Tuning against your traffic is what stops the alerts being noise.

  3. 03

    Go live

    The module starts writing to the adversary graph and escalating to you. Escalation routes, thresholds and who gets woken at 03:00 are agreed in writing beforehand.

  4. 04

    Continuous review

    A standing review of what fired, what did not, and what changed in your estate. A detection set that is not revisited decays — the attacks move even when your systems do not.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • First-party fraud sits outside this — a genuine customer on a genuine device disputing a purchase they made is a dispute problem, not a detection one.

  • We do not grant SCA exemptions or PCI compliance; an exemption is your payment service provider's to claim and its regulator's to supervise, and compliance is your assessor's to validate — see ISO 27001 & PCI DSS.

  • Flaws in the account or payment application itself — broken authentication, insecure object references — belong to Application Security.

Measured against

PSD2 RTS (EU) 2018/389 Art. 18
Allows the transaction risk analysis exemption only while the provider's fraud rate stays below the reference rate for that exemption threshold value; Art. 19 sets how that rate is calculated and Art. 20 when the exemption must be given up.
PCI DSS 4.0.1 Req. 6.4.3
Every script loaded and executed in the consumer's browser on a payment page must be authorised, its integrity assured and an inventory kept with a written justification for each — including any fraud-scoring tag you add.
Regulation (EU) 2024/886 (Instant Payments)
Requires payment providers to check the payee name against the account before a euro credit transfer and to warn the payer on a mismatch.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Can device fingerprinting simply be spoofed?

Yes. Anti-detect browsers, farmed handsets and residential proxies defeat fingerprinting taken on its own — it raises the attacker's cost and catches volume, while behavioural and network signals carry the cases that matter.

Who decides where the block threshold sits?

You do. Every scoring model trades declined fraud against declined customers, and that operating point is a commercial decision — we give you the reasoning behind a score and the ability to change the rules that acted on it.

Does this replace strong customer authentication?

No. Where the RTS mandates SCA, risk scoring only supports an exemption claim — and No. Where the RTS mandates SCA, risk scoring only supports an exemption claim — and the transaction risk analysis exemption has to be given up once your fraud rate exceeds the reference rate for that exemption threshold value over two consecutive quarters..

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.