One engine. Three ways in. One record.
The same analysis runs whether an order arrives from a Shopify webhook, a form, or a POST. It takes 15 to 30 seconds, returns the same object, and writes the same row to the log.
What the product actually is
A scoring engine, the surfaces that reach it, and the workspace that owns the result.
- Shopify app
- Scores every new order from the orders/create webhook, renders the assessment on the order page, and writes the band back as a tag. Nothing to build.
- Dashboard
- A form for scoring an order by hand, the verification log, credit balance and history, API keys, team members, and the support desk.
- REST API
- One endpoint that takes an order and returns a decision, authenticated with an organization-scoped key. Everything the dashboard can start, a key can start.
Three things, on every order
A score, 0 to 100
78
High risk
Four fixed bands, so the same score means the same thing on every account and in every rule you write.
Every factor, named
Freight forwarder address
Cardholder name mismatch
Datacenter IP range
Findings from five families, each with its own severity, so you can disagree with a part without discarding the whole.
A row that stays
#1042 · 78
#1041 · 54
#1040 · 24
Kept for the life of the workspace, because the chargeback that makes you want it arrives months later.
Five families of signal, read together
Rules engines score each signal alone, which is why a VPN gets a real customer rejected. Verify AI reads the address against the IP, the card against the customer, and the order against the history behind it.
customer
Customer
Is this a real person who wants the goods?
- Email or phone appearing in fraud databases and scam reports
- Disposable and throwaway email domains
- Phone numbers that are invalid or route to VoIP
- Names that do not resolve to a person
- A day-old account placing a four-figure order
address
Address
Does this address exist, and does it want the parcel?
- Shipping and billing addresses checked for real-world existence
- Freight forwarder and reshipper addresses
- Billing and shipping in different countries
- Postal codes that do not match the city or state
- PO boxes on high-value orders
payment
Payment
Does the card match the person using it?
- Cardholder name against the customer name on the order
- Prepaid and high-risk card brands
- Expiry patterns consistent with card testing
- Payment details that contradict the billing address
technical
Technical
Where is the order coming from?
- IP geolocation against both addresses on the order
- VPN, proxy, Tor, and datacenter ranges
- IP addresses listed in spam and abuse databases
- User agents that read as automation rather than a browser
behavioral
Behavioral
Does this order fit the customer who placed it?
- Cancellation and return rates against total order count
- Order value against the customer average
- First order that is far larger than a first order should be
- Rush shipping on goods that resell easily
- Item combinations that show up in reshipping fraud
And then
They get weighed against each other
A VPN on its own is a low severity note. A VPN, a reshipper address, and a card in someone else’s name is the pattern. The score reflects the combination, and the factor list shows you which parts of it fired.
Severity: low · medium · high · critical
The parts nobody demos
Workspaces, roles, credits, and keys are what decide whether this is usable by a team rather than by one person.
- Organizations
- Every verification, credit balance, API key, store connection, and log row belongs to an organization. Access is checked against it on each request, and members of one cannot read another.
- Members and roles
- Invite by email with a role. Sensitive operations, including connecting a store and managing billing, require owner or admin rather than mere membership.
- Credits
- One balance per organization, spent as verifications run. Seats, stores, API keys, and log retention cost nothing.
- API keys
- Scoped to an organization, individually revocable, with their own rate limit and per-key usage tracking, so a leaked key is visible and containable.
- Sign-in
- Google, GitHub, and passkeys. Sessions are managed by Better Auth, and passkeys can be registered once an account exists.
Pick the surface you would actually use
Order Verification
Risk Signals
Verification Logs
Shopify App
API & webhooks
Pricing
Part of TDCCommerce
Verify AI is built by The Developer Company Inc., which makes the TDCCommerce unified ERP and eCommerce platform. It runs natively for teams on that platform and standalone for everyone else.
Why we built itHow the pieces relate
Is Verify AI a separate product from TDCCommerce?
Do we need a workspace per store?
Can we run the dashboard and the API against the same organization?
What happens when the balance runs out?
Five credits is about twenty orders.
Enough to run the surface you would actually use, against orders whose outcome you already know.
5 credits on signup · no card required