Products Fraud Management
Product 03 · Risk & fraudFraud Management.
Multi-layer detection calibrated to high-risk categories — card testing, friendly fraud, trial abuse and subscription disputes. Score every transaction in real time and block the fraud without suppressing legitimate approvals.
The structural problem
Why generic fraud rules fall short.
Fraud in high-risk categories doesn't look like fraud in standard e-commerce. Rules built for the average store miss the patterns that target gaming, dating, nutra and subscription merchants — and threaten the acquiring relationship itself.
Category-specific fraud patterns
Gaming faces card testing — small bets validating stolen cards at scale. Dating faces friendly fraud. Nutra faces trial abuse. Each pattern is distinct, and generic e-commerce rules don't recognize any of them.
Rules calibrated to your category
Category-specific rule templates start from the fraud patterns that actually target your vertical — card testing, friendly fraud, trial abuse — then tune against your observed traffic.
Fraud escalates chargeback ratios
High-risk merchants run close to network thresholds — Visa's VDMP at 0.9%, Mastercard's ECM at 1.5%. Fraud that converts to chargebacks pushes ratios toward monitoring programs, fines and account suspension.
Stops fraud before it disputes
Blocking fraudulent authorizations is the upstream intervention — it prevents the chargebacks that would otherwise escalate your ratio and put the acquiring relationship at risk.
Aggressive rules kill approvals
Rules tuned too hard produce false positives — legitimate buyers declined for matching category fraud signals. For merchants already managing lower approval rates, that compounds the loss.
Thresholds tuned per category
Friction is proportional to risk: low-risk transactions clear, the uncertain middle gets a 3DS2 step-up, and only genuine risk is blocked — so approval rate is protected, not sacrificed.
Fraud management capabilities
Detection built for your category.
Six layers run on every transaction — specialist scoring, device and behavioral signals, velocity controls, authentication and a rule engine you can change without a deployment.
Multi-layer detection via specialists
Signals evaluated through Sift, Kount and Forter — each with distinct strengths in risk scoring, device intelligence and friendly-fraud identification. Combined scores inform the decision, without you holding direct vendor contracts.
Device & behavioral signals
Device fingerprinting tracks identity across sessions and accounts. Behavioral signals — typing, mouse movement, navigation path — separate human customers from automated fraud scripts, alongside IP geolocation and proxy/VPN detection.
Velocity controls & pattern recognition
Velocity rules monitor frequency against thresholds — transactions per device per hour, failed attempts per BIN, account creation per IP. Particularly relevant for gaming card testing and nutra trial abuse, and configurable by category.
3DS2 authentication & liability shift
3DS2 authenticates the cardholder with their issuing bank — on success, fraud-chargeback liability shifts to the issuer. Deploy it strategically on high-risk-scored transactions for protection without friction on every checkout.
Custom rule engine
Combine transaction fields, device signals, velocity metrics and external checks into IF/THEN rules with configurable actions — approve, decline, 3DS2 challenge or manual review. Changes take effect without a code deployment.
Real-time decisions under 100ms
Evaluation completes in under 100ms — a risk score and action returned before the authorization is sent to the acquiring bank. Sub-threshold transactions approve immediately; friction is applied only where the score warrants it.
Real-time risk scoring
Every transaction gets a score.
A 0–100 risk score in under 100ms decides the path. The action at each band is configured to your category — friction proportional to risk, not applied to everyone.
Approve directly
No additional authentication. The transaction clears straight through to authorization — legitimate buyers see no friction at all.
Clears to the acquirer3DS2 challenge
Step-up authentication with the issuing bank. On a successful challenge, liability for a fraud chargeback shifts from you to the card issuer.
Liability shift on passBlock or review
Declined outright, or held in a manual-review queue — set per rule configuration for the category and its tolerance for false positives.
Held before authorizationThe detection stack
What the engine evaluates.
Pure transaction data doesn't catch category fraud. MIDs layers device, behavioral and network signals — scored through three specialist partners reached via one integration.
Signals on every transaction
Each transaction is screened across these signals before a score is returned. Weighting is configured per merchant category, so the checks that matter for your fraud patterns carry the most influence.
Calibration, not just blocking
More than a fraud filter.
A single-vendor filter built for standard checkout blocks broadly and declines your real customers. MIDs calibrates to the category and ties detection to the acquiring relationship it protects.
Works with the stack
Products that run alongside.
Fraud management is one of five integrated layers. These work directly with it — the dispute defense beneath it, the routing it feeds, and the data that drives rule tuning.
Chargeback Protection
Pre-dispute alerts and representment — fraud that still converts to a chargeback is managed at both ends.
See chargeback protectionOrchestration
Risk scores feed routing — high-risk transactions trigger 3DS2 or an alternate acquirer path automatically.
See orchestrationAnalytics
Fraud rate, false-positive rate and decline-reason reporting — the data that drives rule optimization.
See analyticsFAQ
Common fraud questions.
Each high-risk category has characteristic patterns. Gaming merchants face card testing — using small transactions to validate stolen card numbers at scale. Adult and dating merchants face friendly fraud — cardholders disputing legitimate charges by claiming an unrecognized or unauthorized transaction. Nutra merchants face trial abuse — using stolen or synthetic identities to claim free-trial offers. Subscription merchants face account sharing and credential stuffing. Effective rules need to be calibrated to the specific category's patterns rather than applying generic e-commerce fraud logic.
Fraud that converts to chargebacks directly increases the merchant's chargeback ratio — the metric card networks use to determine monitoring-program placement and merchant-account standing. For high-risk merchants already operating with elevated chargeback exposure, a cluster of fraud-driven chargebacks can push ratios toward Visa VDMP (0.9%) or the Mastercard threshold. Fraud management that prevents fraudulent transactions from occurring is the upstream intervention — it prevents chargebacks before they happen rather than disputing them after.
3DS2 is a cardholder-authentication protocol that verifies identity with the issuing bank at the point of transaction. On a successful 3DS2 authentication, fraud-chargeback liability shifts from the merchant to the card issuer. EU and UK merchants are required to apply 3DS2 (Strong Customer Authentication) for most card-not-present transactions under PSD2. Outside SCA regions, strategic deployment — applied to transactions above a risk-score threshold rather than all transactions — provides liability-shift protection on higher-risk transactions without adding checkout friction for every customer.
The rule engine configures IF/THEN logic using transaction fields, device signals, velocity metrics and external data checks. A rule might be: IF transaction amount is over a set value AND the device fingerprint has not been seen before AND the IP country doesn't match the billing country, THEN apply a 3DS2 challenge. Rules can be combined and prioritized, and changes take effect without a code deployment. Starting templates are provided for common high-risk fraud patterns — gaming card testing, subscription friendly fraud, nutra trial abuse — which are then adjusted against observed fraud and false-positive rates.
False positives — legitimate transactions declined by fraud rules — are a direct cost for high-risk merchants already managing lower approval rates. Rule calibration is the key: rules should be specific to the merchant's actual fraud patterns (category, geography, transaction profile) rather than generic signals that apply to fraud broadly. The custom rule engine allows threshold adjustment — if a rule produces false positives on specific card countries or amounts, that threshold can be modified without affecting rules that are performing correctly. Monitoring false-positive rates alongside fraud rates is part of ongoing optimization.
Want rules built for your category? Talk through your fraud profile
Fraud rules built for your category.
Tell us your merchant category, current fraud patterns and chargeback profile. We'll advise on the detection configuration and rule setup that blocks the fraud without taking your legitimate approvals down with it.