Order Verification

A score you can argue with.

Every order comes back with a number from 0 to 100, the findings that produced it, the reasoning in plain language, and the action to take. In 15 to 30 seconds.

The problem with a level

“Medium risk” has never stopped a chargeback.

Every platform ships a risk indicator. It gives you a word, no reasoning, and no way to tell the difference between an order that looks odd and an order that is fraud.

So the word gets ignored, or it gets over-trusted and real customers get rejected. Either way the team ends up googling addresses by hand on anything over a few hundred dollars.

The useful output is not a stronger word. It is the finding underneath it: this address is a reshipper, this card is in a different name, this IP is a datacenter. Those are things a person can check, dispute, and act on.

What you get back

A number nobody can question is a number nobody acts on.

Most fraud tools return a level and leave your team to argue about it. Verify AI returns the finding behind every point of the score, so the person deciding whether to ship has something to read rather than something to trust.

  1. The score, and the band it falls in

    0 to 100, mapped to low, medium, high, or critical. The band is what your rules key off; the number is what tells you how far into it you are.

  2. Each factor, named and rated

    Not a category weighting. The actual finding, its severity, and which of the five families it came from.

  3. The reasoning that produced it

    Written in the language you would use to explain the hold to the customer, because that is usually the next thing that happens.

  4. A recommendation you can act on

    Ship, review, verify the customer, or reject. Verify AI never cancels or refunds anything itself, so the decision stays on your audit trail.

The full response, field by field

Verification record

Order #1042

ver_8k2p
78High risk

61 to 85 is the high band. Multiple fraud indicators, and the order should not ship without a check.

3 risk factors

  • Shipping address is a freight forwarderhighaddress

    The Miami address is a known package consolidation and reshipping facility, not a residence.

  • Cardholder name does not match customerhighpayment

    The card is in a different name from the account placing the order, with no company on the order to explain it.

  • IP resolves to a datacenter rangemediumtechnical

    The order came from a hosting provider range rather than a consumer connection.

Analysis

A first order at nine times the category average, shipping to a consolidation facility, paid with a card in a third party name. Any one of these appears on legitimate orders. Together they are the reshipping pattern, and the datacenter IP removes the innocent explanation for the address.

Recommendation

Verify identity before fulfilment

Hold
The bands

Four bands, fixed thresholds

The same score means the same thing on every account, so a rule you write today still means what you meant next year.

Low risk0 to 30Minimal red flagsShip it
Medium risk31 to 60Some suspicious indicatorsSend to review
High risk61 to 85Multiple fraud indicatorsVerify the customer first
Critical risk86 to 100Definitive fraud signalsReject

The action column is the recommendation, not an automation. Verify AI does not hold, cancel, or refund anything on your behalf.

Underneath the number

Where the points come from

Five families of check, read against each other rather than scored in isolation.

customer

Customer

Is this a real person who wants the goods?

  • Email or phone appearing in fraud databases and scam reports
  • Disposable and throwaway email domains
  • Phone numbers that are invalid or route to VoIP
  • Names that do not resolve to a person
  • A day-old account placing a four-figure order

address

Address

Does this address exist, and does it want the parcel?

  • Shipping and billing addresses checked for real-world existence
  • Freight forwarder and reshipper addresses
  • Billing and shipping in different countries
  • Postal codes that do not match the city or state
  • PO boxes on high-value orders

payment

Payment

Does the card match the person using it?

  • Cardholder name against the customer name on the order
  • Prepaid and high-risk card brands
  • Expiry patterns consistent with card testing
  • Payment details that contradict the billing address

technical

Technical

Where is the order coming from?

  • IP geolocation against both addresses on the order
  • VPN, proxy, Tor, and datacenter ranges
  • IP addresses listed in spam and abuse databases
  • User agents that read as automation rather than a browser

behavioral

Behavioral

Does this order fit the customer who placed it?

  • Cancellation and return rates against total order count
  • Order value against the customer average
  • First order that is far larger than a first order should be
  • Rush shipping on goods that resell easily
  • Item combinations that show up in reshipping fraud

And then

They get weighed against each other

A VPN on its own is a low severity note. A VPN, a reshipper address, and a card in someone else’s name is the pattern. The score reflects the combination, and the factor list shows you which parts of it fired.

Severity: low · medium · high · critical

How it runs

Four steps, and one of them is yours

  1. STEP 1

    Send the order

    From the Shopify app automatically, from the dashboard form by hand, or from your checkout over the API. Same analysis, same response.

  2. STEP 2

    The checks run live

    Addresses, identifiers, IP reputation, and fraud reports are read at the moment the job runs rather than looked up in a stale table.

  3. STEP 3

    A score comes back

    0 to 100, a band, every factor with a severity and a category, the reasoning, and the action to take.

  4. STEP 4

    You decide

    Verify AI never holds, cancels, or refunds anything. It reports; your rules and your team act, which keeps the decision on your audit trail.

What to send

More input, better score

Two fields decide most of the accuracy: the IP address and the customer history. Both are optional, and both are the difference between a guess and a comparison.

Required
Order amount and currency, customer name and email, whether this is a first order, and the full shipping and billing addresses.
Strongly recommended
IP address and user agent. Without them the technical family has nothing to read, and a datacenter IP is one of the highest-value signals available.
Payment
Card brand, last four digits, expiry, and cardholder name. The cardholder name against the customer name is what catches a third party card.
Customer history
Total orders, cancellations, returns, fulfilments, and average order value. This is what turns the behavioral family from a guess into a comparison.
Company
Company name and address, for B2B orders. Both are checked for real-world existence rather than accepted as typed.
Line items
Name, quantity, price, and SKU. Item combinations are read for the patterns that show up in reshipping.
What comes back

One response shape, everywhere

The dashboard, the Shopify block, and the API all render the same object. Nothing is summarised away for one surface and not another.

POST/api/{org}/order-verification
{
  "success": true,
  "data": {
    "riskScore": 78,
    "riskLevel": "high",
    "riskFactors": [
      {
        "factor": "Shipping address is a freight forwarder",
        "severity": "high",
        "category": "address",
        "description": "8400 NW 25th St is a package consolidation
          and reshipping facility, not a residence."
      }
    ],
    "reasoning": "A first order at nine times the category average…",
    "recommendations": [
      "Verify identity before fulfilment",
      "Request a card in the customer's own name"
    ]
  }
}

riskScore and riskLevel

The number and its band. Both are returned, so you never have to re-derive one from the other.

riskFactors[]

Each finding with a severity of low, medium, high, or critical, and a category naming the family it came from.

reasoning and recommendations[]

Written for a person, because the next step is usually a conversation with the customer.
Scoring

How the number behaves

What does the score actually mean?
It is the analysis’s confidence that the order is fraudulent, expressed on a 0 to 100 scale and mapped to four bands. Treat the band as the thing your rules key off and the number as how far into that band the order sits, because a 62 and an 84 are both high and are not the same conversation.
Can we change the thresholds?
The bands are fixed at 30, 60, and 85, so the same score means the same thing on every account and in the API. What you choose is the level at which your own rules act: plenty of stores auto-approve low, review medium and high, and reject nothing automatically.
Will the same order always get the same score?
Not exactly. The checks read live sources, so an address that gets reported to a fraud database between two runs will move the score. Re-verifying writes a new row to the verification log beside the old one, which is how you see that movement.
What can it not detect?
Stolen card validity, account takeover, friendly fraud, and real-time card authorisation all sit outside what an order payload can show. Run this alongside your processor’s fraud tools, 3D Secure, and address verification rather than instead of them.
What happens if the order is missing fields?
Required fields are rejected with a validation error. Optional fields that are absent reduce what the analysis can check, and the reasoning says so rather than scoring around the gap silently.
How much does one verification cost?
A fraction of a credit, and a credit is one dollar. Consumption is metered on the model tokens, address validations, and web searches the analysis uses, so an order with full history and technical data costs more than a bare one. Around four orders per credit is the figure to plan with.

Run it on last week’s orders.

The free credits cover enough real orders to tell you whether the score agrees with what you already know happened.

5 credits on signup · no card required