Risk Signals Solution
Risk signals for fraud detection.
Stop hidden abuse.
Automation, masking and spoofing can make abusive visits look ordinary. ShieldLabs returns named risk signals for each identification, helping you protect signup and account access.
Start Free300+ signals analyzed
Receive ready-made detections across device, browser and network risks.
Protect sensitive actions
Find risky activity around signups, sign-ins and benefit claims.
Reasons behind the score
Keep named signals with the visit’s risk result.
Spot incomplete checks
Get explicit results when identification or network checks cannot finish.
Detected signals
Find the signal.
Understand the reason.
See the named signals available for automation, masking, spoofing, client context and incomplete checks.
VPN
MaskingTraffic routed through a VPN connection.
Proxy
MaskingTraffic routed through a proxy connection.
Private Relay
MaskingConnections using a privacy relay.
Tor Network
MaskingConnections routed through the Tor network.
Check Incomplete
ContextThe identification did not complete every check.
Anti-Detect Browser
AutomationA browser configured to mask or alter its device identity.
Banned IP
ContextA connection from an IP address marked as banned.
Incognito mode
ContextThe browser is using a private or incognito window.
Good bot
ContextA recognized bot that is allowed to browse, such as a search crawler.
Timezone Mismatch
ContextThe browser time zone does not match the location of the IP address.
Bad bot
AutomationAutomated traffic that is not a recognized good bot.
Evidence and account context
Detect browser masking.
Reveal the linked accounts.
Anonymous visitor detection reveals bots, masking and spoofing behind a browser visit. ShieldLabs also detects multi-accounting around registered accounts to protect repeated signup benefits.
Risk signals detected
Anti-Detect BrowserProxyNamed detections
Use named detections with the scored visit to protect signup and access without building a model.
Informational context
Get incognito context, IP mismatch detections and check status with each identification.
Account-level detection
Surface multi-accounting, sharing, takeover and impossible travel without training a fraud model.
The ShieldLabs platform
One signal is a clue.
One platform is the picture.
Combine identification with device and network intelligence, named risk signals, ready-made account abuse detection and traffic quality analytics.
Enterprise-level functionality. Without enterprise pricing.
Analytics dashboard
Find the signal.
Follow the activity.
Find detected risks and their associated visitors, users, devices and IPs. Ready-made results show affected entities and the acquisition sources bringing risky traffic.
How it works
Start protecting your product.
Connect once and start receiving ready-made fraud and abuse detections.
- 01
Add the snippet or SDK
Connect your product and start identifying visitors and users.
- 02
Receive ready-made detections
Get detected fraud and account abuse in the dashboard or through API integrations.
- 03
Prevent fraud and abuse
Protect customer accounts, paid access and signup incentives in your product.
Developers
Integrate in
5 minutes.
A single API to identify, detect and score. Receive risk data through API responses and webhooks. Integrate selected data points into your business logic to prevent fraud and abuse.
Risk Signals Solution
Make risk visible.
Stop abuse of your product.
Start Free FAQ
Understand the result.
Put it to work.
What are risk signals?
Risk signals are named detections of automation, masking, spoofing or other risk around an identification.
How do ShieldLabs risk signals help prevent fraud?
ShieldLabs returns detected risk signals with the identification’s assessment and applicable account abuse events. Use ready-made results to protect your product without building a detection model.
How accurate are ShieldLabs identification and risk signals?
ShieldLabs provides 99.9% identification accuracy and 99.9% risk signal detection accuracy.
Are all 300+ inputs separate flags in the response?
No. ShieldLabs analyzes device, browser, operating-system and network evidence and exposes named detection flags. The collected inputs and the returned flags are different layers.
Does incognito mode automatically mean high risk?
No. Incognito is context, and its detection can carry no score contribution. Risk depends on the complete result and other evidence.
Are high-risk events the same as risk signals?
No. Signals describe evidence around a visit. High-risk events describe account abuse across linked user and device activity and have Medium or high confidence.
Are anonymity signals included in Risk Signals?
Yes. VPN, proxy, Tor and other masking detections are named risk signals. Risk Signals also includes browser automation, anti-detect environments and device or location mismatches.
Can I see the reason behind a score?
Yes. The result includes named signals and detection flags. Signal contributions and the final score should be read together.
Can risk signals protect verification and checkout flows?
Yes. Bot, proxy, anti-detect browser and location detections are available with the identification risk assessment. Add them around browser-based OTP requests, checkout and other sensitive actions.