Risk Signals Solution

Risk signals for fraud detection.
Stop hidden abuse.

Automation, masking and spoofing can make abusive visits look ordinary. ShieldLabs returns named risk signals for each identification, helping you protect signup and account access.

Start Free
Anti-Detect BrowserDetected
ProxyDetected
Browser AutomationDetected

300+ signals analyzed

Receive ready-made detections across device, browser and network risks.

Protect sensitive actions

Find risky activity around signups, sign-ins and benefit claims.

Reasons behind the score

Keep named signals with the visit’s risk result.

Spot incomplete checks

Get explicit results when identification or network checks cannot finish.

Detected signals

Find the signal.
Understand the reason.

See the named signals available for automation, masking, spoofing, client context and incomplete checks.

VPN

Masking

Traffic routed through a VPN connection.

Proxy

Masking

Traffic routed through a proxy connection.

Private Relay

Masking

Connections using a privacy relay.

Tor Network

Masking

Connections routed through the Tor network.

Check Incomplete

Context

The identification did not complete every check.

Anti-Detect Browser

Automation

A browser configured to mask or alter its device identity.

Banned IP

Context

A connection from an IP address marked as banned.

Incognito mode

Context

The browser is using a private or incognito window.

Good bot

Context

A recognized bot that is allowed to browse, such as a search crawler.

Timezone Mismatch

Context

The browser time zone does not match the location of the IP address.

Bad bot

Automation

Automated traffic that is not a recognized good bot.

Evidence and account context

Detect browser masking.
Reveal the linked accounts.

Anonymous visitor detection reveals bots, masking and spoofing behind a browser visit. ShieldLabs also detects multi-accounting around registered accounts to protect repeated signup benefits.

User[email protected]3 linked user accounts detected
Identification risk score90Dangerous

Risk signals detected

Anti-Detect BrowserProxy
High-risk event detectedMulti-accounting
High confidence

Named detections

Use named detections with the scored visit to protect signup and access without building a model.

Informational context

Get incognito context, IP mismatch detections and check status with each identification.

Account-level detection

Surface multi-accounting, sharing, takeover and impossible travel without training a fraud model.

The ShieldLabs platform

One signal is a clue.
One platform is the picture.

Combine identification with device and network intelligence, named risk signals, ready-made account abuse detection and traffic quality analytics.

Enterprise-level functionality. Without enterprise pricing.

Analytics dashboard

Find the signal.
Follow the activity.

Find detected risks and their associated visitors, users, devices and IPs. Ready-made results show affected entities and the acquisition sources bringing risky traffic.

How it works

Start protecting your product.

Connect once and start receiving ready-made fraud and abuse detections.

  1. 01

    Add the snippet or SDK

    Connect your product and start identifying visitors and users.

  2. 02

    Receive ready-made detections

    Get detected fraud and account abuse in the dashboard or through API integrations.

  3. 03

    Prevent fraud and abuse

    Protect customer accounts, paid access and signup incentives in your product.

Developers

Integrate in
5 minutes.

A single API to identify, detect and score. Receive risk data through API responses and webhooks. Integrate selected data points into your business logic to prevent fraud and abuse.

identification.scored

Risk Signals Solution

Make risk visible.
Stop abuse of your product.

Start Free

FAQ

Understand the result.
Put it to work.

What are risk signals?

Risk signals are named detections of automation, masking, spoofing or other risk around an identification.

How do ShieldLabs risk signals help prevent fraud?

ShieldLabs returns detected risk signals with the identification’s assessment and applicable account abuse events. Use ready-made results to protect your product without building a detection model.

How accurate are ShieldLabs identification and risk signals?

ShieldLabs provides 99.9% identification accuracy and 99.9% risk signal detection accuracy.

Are all 300+ inputs separate flags in the response?

No. ShieldLabs analyzes device, browser, operating-system and network evidence and exposes named detection flags. The collected inputs and the returned flags are different layers.

Does incognito mode automatically mean high risk?

No. Incognito is context, and its detection can carry no score contribution. Risk depends on the complete result and other evidence.

Are high-risk events the same as risk signals?

No. Signals describe evidence around a visit. High-risk events describe account abuse across linked user and device activity and have Medium or high confidence.

Are anonymity signals included in Risk Signals?

Yes. VPN, proxy, Tor and other masking detections are named risk signals. Risk Signals also includes browser automation, anti-detect environments and device or location mismatches.

Can I see the reason behind a score?

Yes. The result includes named signals and detection flags. Signal contributions and the final score should be read together.

Can risk signals protect verification and checkout flows?

Yes. Bot, proxy, anti-detect browser and location detections are available with the identification risk assessment. Add them around browser-based OTP requests, checkout and other sensitive actions.