Fraud insights · device & behavioural signals

Every session leaves a fingerprint.

A new signup at 21:41. Before the form is submitted, the SDK has read the device, the browser and the network and resolved one identifier that survives a cleared cookie.

Sessionsignup · 21:41 · Singapore
0 / 6
  • Device attributes
  • Browser & render
  • Time zone & locale
  • Network posture
  • Private mode & Tor
  • Interaction pattern
Profile identifier
Resolving
Decisioning · linked accounts

One fingerprint, forty-one accounts.

The identity changed. The device did not.

The same device had opened forty-one accounts in thirty-six hours, across three IPs, claiming the welcome bonus on every one. Each account cleared KYC on its own.

Velocity, not volumeScored, not stacked
Accounts created · 36 hoursDifferent names, different emails
1/ 42 accounts linked
One profile identifier09dd5f3fb80cc1ac
3 IP addresses39 bonuses claimed36 hours
Fraud alert · case opened

The alert lands before the payout does.

Your rule holds the account, opens a case, and attaches the fingerprint and every account linked to it. Elena V. sees which signal fired and what it was scored against, then decides. The reasoning stays on the file.

  • $2.4m in bonus payouts held
  • One case, forty-one accounts, one decision
Illustrative scenario
CASE-4417 · Bonus abuseDevice velocity rule fired
High risk · 87
Profile identifier09dd5f3f · 41 accounts
IP geolocationProxy · claimed another market
Session originEmulator detected
Vyra assessment

Forty-one accounts share one device fingerprint and one proxy range. Bonus claimed on thirty-nine. Recommend hold on all linked accounts and a single STR if funds moved out.

Decision · Elena V. · Fraud analystHeld · 41 accounts

Trusted by top financial institutions and fintech leaders across the EMEA region

Live check

Your browser is already telling a story.

These are the signals your session revealed when this page loaded read live, not pre-recorded. Your IP address and network type come from a lookup; blocklist checks resolve server-side.

Welcome back.

Reading

Profile identifier
Reading
Risk scoreReading
IP addressReading
VPN or proxy
Location
Time zone
Browser
Device
Visit count
Private mode
IP blocklist

Device and browser signals are read by the Youverify Behavioral SDK when this page loads. Your IP address, network operator and approximate location come from the same session, resolved server-side.

Capabilities

Six signals, one profile.

One unusual signal may mean nothing. Several signals moving together tell a story.

  • 01

    Profile Identifier & Fingerprinting

    Device and browser signals resolve into a persistent profile identifier, so related sessions and accounts surface together.

  • 02

    Device & Account Velocity

    See when one device begins creating or accessing accounts faster than expected.

  • 03

    Privacy & Anti-Detect Signals

    Detect private browsing, Tor, anti-detect browsers and attempts to obscure the environment.

  • 04

    Behavioral Intelligence

    Compare navigation, interaction and behavioural patterns against previous activity.

  • 05

    Network & Location Anomalies

    Surface mismatches between network location, time zone, locale and claimed geography.

  • 06

    Emulator & Remote Access Detection

    Detect virtual devices, emulators and remote-control environments before they become trusted sessions.

From signal to decision · rules

You write the rule. You keep the reasoning.

Signals become decisions in a rule engine your fraud team edits, not a model you have to take on faith. Every rule carries a version, an author and a dry run against the last thirty days of traffic before it goes live.

Explore API documentationWeb, iOS and Android SDKs
Rule · bonus abusev4 · live
  1. WHENprofile identifier seen on ≥ 5 accounts
  2. ANDwelcome bonus claimed on ≥ 3 of them
  3. WITHINa rolling 24 hours
  4. THENhold payouts, open one case, notify fraud desk
Illustrative dry run · last 30 days312 sessions caught · 4 false positives
From signal to decision · case

The signal does not stop at the alert.

A rule can hold the activity, open the case and bring every linked account with it. Your workflow determines which of those happens, and an analyst can open a case by hand from any session. However it starts, it is the same case object an onboarding review uses.

See the onboarding side of the same case
CASE-4417 · Bonus abuse

Device velocity rule fired

Open · fraud desk
Opened by
Vyra workflow · rule v4
Scope
All linked accounts · 1 funded
  1. +0sRule matched · case opened by workflow
  2. +1sPayouts held on every linked account
  3. +24mAssigned to Elena V. · fraud desk
  4. +58mDecision recorded · STR drafted
Same case object as an onboarding reviewOne entity record
From signal to decision · investigation

Vyra investigates. Your workflow decides.

Vyra AI groups the linked activity, explains the shared signals, reconstructs the sequence and drafts the investigation narrative. The evidence stays attached to the case, and the decision stays with a named officer under your workflow.

VyraCASE-4417Workflow · investigate
Elena V.

What else has this device touched in the last week?

Six more sessions, all on the same proxy range: two failed card top-ups, three abandoned signups, one password reset on an account opened in March. That account has withdrawn $840,000 since Tuesday.

  • 7 linked sessions
  • 1 funded account
  • Draft STR ready
Every claim above links back to the session it came from, and the workflow step that asked for it.
By industry

The same signals, a different fraud.

Illustrative scenarios
Scenario · account takeover

Right credentials, wrong device.

A corporate login arrives with the correct password and a device the profile has never used, from a proxy claiming Panama, minutes after a password reset. Step-up is triggered before the transfer screen loads.

  • New device on known profileFlagged
  • Time zone vs claimed IPMismatch
  • ActionStep-up + hold
In production

What the fraud desk actually says.

We used to find the ring in the monthly reconciliation. Now the fourth account on a device never opens.

Head of Fraud · consumer betting platform

The part our examiner cared about was the audit trail: which signal fired, what it scored, who decided. It was all on the case.

Chief Compliance Officer · tier-2 bank
FAQs

Frequently asked questions.

  • The SDK reads device, browser and behavioural signals on the session itself and resolves them into a persistent profile identifier. Your rules score that profile as it moves rapid account creation, a shared fingerprint, a spoofed location, an emulator and fire before the money leaves.

  • Device and browser attributes, rendering characteristics, time zone and locale, network posture, and interaction patterns. No document contents and no biometric data. The profile identifier survives cleared cookies and reinstalled apps because it is derived from the device, not stored on it.

  • Signals are scored, not stacked. A shared device in a household is not the same as one fingerprint on forty accounts in thirty-six hours, and your rules can say so. Every rule can be dry-run against the last thirty days of traffic before you turn it on.

  • Yes a web SDK and native iOS and Android SDKs return the same profile identifier and the same signal set, so a rule written once applies across every channel a customer reaches you on.

  • It runs on the same entity record. A device signal raised at signup sits beside the identity and screening evidence, and the case a fraud rule opens is the same case an analyst works in Cowork.

  • Signals are collected under legitimate interest for fraud prevention, retained for the period you configure, and processed in regions with adequate data protection regulation. Youverify holds SOC 2 Type II and ISO 27001 and is registered with the data protection authorities in the markets it serves.

  • One script tag or one SDK install, then rules. Most teams see signals in a sandbox the same day and run their first production rule inside a week.

See the fraud already hiding in your traffic.

Bring us a sample of your traffic. We will show you the devices already connected, the patterns already forming, and the rules that could have caught them.

Compliance certifications

Youverify holds SOC 2 Type II, ISO 27001, ISO 27018 and ISO 42001 certifications, and is registered with the data protection authorities in Nigeria, Kenya, South Africa, Côte d’Ivoire and the United Kingdom.

Certifications & attestations
  • SOC 2 Type II
  • ISO/IEC 27001:2022 certified
  • ISO/IEC 27018:2019 attested
  • ISO/IEC 42001:2023 certified
Privacy and data protection
  • EU GDPR compliant
  • CCPA, California
  • Nigeria Data Protection Commission
  • Office of the Data Protection Commissioner, Kenya
  • Information Regulator, South Africa
  • ARTCI, Côte d’Ivoire
  • ICO, United Kingdom