Risk tags for fintech.

Account takeover, payment fraud on local rails and synthetic identities in one event stream, with a decision you can delegate. Built for neobanks, payment apps and embedded finance.

Fintech attackers don't use one technique, they chain them. A synthetic identity opens an account, a compromised device takes it over, and a mule network moves the funds out before detection. Siloed vendors see pieces of the attack. The whole chain shows up on one user timeline.

The attack surface, broken down.

01

Account takeover

Device, behavioral and graph signals before funds move: device changes, VPN use, session anomalies, credentials reused from breached sets.

device.newlogin.credential_reuselogin.impossible_travel
  • device.new + login.impossible_travel → step_up
  • login.credential_reuse → step_up
02

Payment fraud on local rails

Card testing, UPI collect abuse, geo mismatches and reused instruments, with payment events arriving from your PSP webhook.

card.testing_patternpayment.geo_mismatchpayment.instrument_reused
  • card.testing_pattern → block
  • payment.geo_mismatch (≥ 0.8) → step_up
03

Synthetic identities

Identities assembled from real and fabricated attributes look fine alone and wrong as a cluster: shared devices, shared instruments, shared timing.

cluster.size_5plusemail.no_footprintphone.voip
  • email.no_footprint + phone.voip → step_up
  • cluster.size_5plus → review
04

Who actually needs verification

Onboarding friction costs conversion. Tag the users who need a document check and route them; let the rest through.

kyc.recommendedsignup.velocity_high
  • kyc.recommended → kyc (partner: sumsub)

Three reasons it fits.

01

Local rails, first.

UPI, mobile money, local cards and bank transfers are where the fraud is. Presets and payment integrations reflect that, not just US cards.

02

A timeline, not a snapshot.

Tags accumulate over the user's lifetime, so a chain attack that unfolds over weeks is visible on one screen.

03

Verification only where it counts.

Route to your partner from a tag. Pay for the users who need it, skip the rest, keep the audit trail.

We don't verify identities. We tell you who needs it.

kyc.recommended routes to Sumsub or the partner you choose, at their price, and keeps the audit trail on our side, next to the tags that sent the user there. Everyone else goes straight through.

How KYC routing works

Presets tuned on high-velocity fintech traffic: Stripe, Razorpay, Cashfree, Xendit, Midtrans and PayMongo webhooks, local phone footprint, a data region you choose, and audit exports shaped for regulator reviews.

Your risk team starts here.

$99 a month, 10,000 events, sandbox before you pay, money back in 14 days if it doesn't fit.