E-commerce & Retail
Card-not-present fraud, inventory scraping, loyalty abuse and counterfeit storefronts impersonating your brand.
What you receive
- Checkout fraud scoring without added friction
- Counterfeit storefront takedown
- Bot and scraping mitigation
- PCI DSS support
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
Your acquirer has flagged your fraud ratio
Transaction risk analysis exempts a payment from strong customer authentication only while the payment service provider's fraud rate stays under the reference rate, so a threshold you do not control decides how much friction your checkout carries. When the exemption stops being granted, the conversion loss arrives without anything having changed on your side.
Peak trading week starts in three weeks
Card-testing bots do not care about your conversion rate; they care that your authorisation endpoint is cheap to hit and that you are too busy to look. Rate limits and scoring rules set in January are usually the wrong ones for the week that pays for the year.
Your checkout loads scripts you do not own
Tag managers, analytics and personalisation scripts execute in the same page as the card field, so a compromise anywhere in that chain reads the form directly. A web application firewall inspects requests to your server, and a skimmer that runs in the browser and posts card data to a third party may never produce one — which is why the control is script inventory and integrity checking rather than another server-side filter.
How it runs
Where you actually are
A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.
What the obligation really requires
We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.
A scoped programme
The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.
Evidence, not a gap report
The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
Chargeback representment is not filed for you; we supply the evidence and the pattern analysis, and your payment operations team submits it.
Nothing here replaces a QSA assessment — we prepare the technical evidence and the scope argument, and someone else signs the report on compliance.
Vetting third-party sellers on your marketplace is outside scope — we address impersonation of your brand, not policing who trades on it.
- PCI DSS 4.0.1 Req. 6.4.3
- Every script loaded in the payment page must be inventoried, authorised and checked for integrity — third-party tags included.
- PCI DSS 4.0.1 Req. 11.6.1
- Must detect and alert on unauthorised change to payment-page headers and content, run every seven days or at a targeted-risk-analysis frequency.
- PSD2 RTS (EU) 2018/389
- The obligation to apply strong customer authentication is in Article 97 of PSD2; Commission Delegated Regulation (EU) 2018/389 sets the exemptions, and the transaction risk analysis exemption rests on the payment service provider's fraud rate, not the merchant's.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Will fraud scoring hurt our conversion rate?
Any layer that can decline will sometimes decline wrongly, so the honest answer is that it moves both numbers and you choose the balance. The rules stay yours to read and tune, which matters more than the model, because the acceptable false-positive rate is a commercial decision.
Can you stop scraping entirely?
No — a determined competitor with residential proxies and a headless browser will get your prices eventually, and what changes is the cost, the delay and the resolution of what they collect. The realistic goal is making bulk collection expensive and slow.
How quickly do counterfeit storefronts come down?
That depends on the registrar and the host, and some jurisdictions simply do not act. Reputable registrars respond to a documented trademark complaint; bulletproof hosting does not, and there the useful lever is browser and payment-processor blocklisting.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.