Risk Signals

One signal is noise. Four is a pattern.

Verify AI runs five families of check on every order and reads them against each other. That is the difference between rejecting a customer for using a VPN and catching the order where the VPN was the smallest problem.

Why rules engines fail

Every rule you write rejects someone real.

Block VPNs and you lose the privacy-conscious. Block freight forwarders and you lose genuine international buyers. Block first orders over a threshold and you lose the customer who finally decided to buy the expensive one.

The signals are not wrong. Reading them one at a time is. A datacenter IP on an order that is otherwise unremarkable is a note; the same IP alongside a reshipper address and a mismatched cardholder is the whole case.

So the analysis reports each finding separately, with its own severity, and scores the combination. You see both the parts and the conclusion, which is what lets you disagree with either one.

The families

Five questions asked of every order

Categories match the category field on every risk factor the API returns, so a finding a merchant reads in the Shopify admin belongs to a family named on this page.

customer

Customer

Is this a real person who wants the goods?

  • Email or phone appearing in fraud databases and scam reports
  • Disposable and throwaway email domains
  • Phone numbers that are invalid or route to VoIP
  • Names that do not resolve to a person
  • A day-old account placing a four-figure order

address

Address

Does this address exist, and does it want the parcel?

  • Shipping and billing addresses checked for real-world existence
  • Freight forwarder and reshipper addresses
  • Billing and shipping in different countries
  • Postal codes that do not match the city or state
  • PO boxes on high-value orders

payment

Payment

Does the card match the person using it?

  • Cardholder name against the customer name on the order
  • Prepaid and high-risk card brands
  • Expiry patterns consistent with card testing
  • Payment details that contradict the billing address

technical

Technical

Where is the order coming from?

  • IP geolocation against both addresses on the order
  • VPN, proxy, Tor, and datacenter ranges
  • IP addresses listed in spam and abuse databases
  • User agents that read as automation rather than a browser

behavioral

Behavioral

Does this order fit the customer who placed it?

  • Cancellation and return rates against total order count
  • Order value against the customer average
  • First order that is far larger than a first order should be
  • Rush shipping on goods that resell easily
  • Item combinations that show up in reshipping fraud

And then

They get weighed against each other

A VPN on its own is a low severity note. A VPN, a reshipper address, and a card in someone else’s name is the pattern. The score reflects the combination, and the factor list shows you which parts of it fired.

Severity: low · medium · high · critical

In practice

The same signal, two orders

Both of these orders came from an IP the customer did not sit behind at home. Only one of them is a problem.

Order #1038

18

Third order from a two-year-old account. Home address, card in the same name, ships to the billing address.

  • IP resolves to a consumer VPNlowtechnical

    The customer uses a commercial VPN, which millions of people do. On its own it moves the score by a few points.

Order #1042

78

First order at nine times the category average, shipping to a consolidation facility, paid with a card in a third party name.

  • IP resolves to a datacenter rangemediumtechnical

    The same family of signal as the VPN above, and here it is corroborated by three other findings rather than standing alone.

  • Shipping address is a freight forwarderhighaddress
  • Cardholder name does not match customerhighpayment

A rules engine that blocks non-residential IP addresses rejects both. Verify AI ships the first one and holds the second, and tells you which three findings made the difference.

What it reads

Where the findings come from

Live sources rather than a rules table that was current when it shipped.

Live web research
Fraud databases, scam report sites, and reputation records are read at the moment the job runs. A phone number reported last week is found this week.
Address validation
Shipping and billing addresses are checked for real-world existence, and against the known freight forwarder and reshipper facilities that consumer address validation does not flag.
IP intelligence
Geolocation, hosting and datacenter ranges, proxy and VPN detection, and spam and abuse listings. Cached, so a repeated IP does not cost a second lookup.
Email validation
Disposable and throwaway domains, plus deliverability signals that catch an address created for one order.
The order itself
Amount against history, item combinations, shipping speed, timestamp, and the internal consistency of the addresses, payment, and customer on the payload.
Severity

Four levels, and what each one is for

Note it

Low

A minor inconsistency. Present on plenty of legitimate orders, and worth nothing on its own.

Worth a look

Medium

A suspicious indicator. Two or three of these together are what move an order into the review queue.

Act on it

High

A strong fraud signal. Something specific was found, and the order should not ship without a check.

Stop

Critical

A definitive fraud indicator. On its own it is enough to put the order in the top band.

Severity is per factor. The band on the order is the conclusion drawn from all of them, so an order can carry a high severity finding and still score in the medium band when everything else about it checks out.

Signals

What it can and cannot see

Where does the fraud data come from?
Public sources: fraud and scam report sites, reputation records, address and IP intelligence, and the manufacturer of the signal itself where one exists. Verify AI does not operate a consortium database of your customers, and it does not contribute your orders to one.
How current is it?
It is read when the job runs. That is why a verification takes 15 to 30 seconds rather than 200 ms, and it is the reason a newly reported address is caught rather than missed until the next data refresh.
Do you check the same things for every order?
The families are the same. What can be checked depends on what you send: no IP address means no technical family, and no customer history means the behavioral family has nothing to compare against. The reasoning says when a gap limited the analysis.
Can we turn a family off?
Not today. Every family runs and every finding is returned, which is what keeps the score comparable between orders. If a family is noise for your business, ignore that category in your own rules rather than suppressing it at the source, so the evidence is still on the record.
Does a single critical factor mean a critical score?
Usually, but not mechanically. A critical severity finding is a definitive fraud indicator and will push the score into the top band on its own. The number still reflects the whole picture, which is why the factor list is returned beside it.

Send an order you already know was fraud.

The fastest way to judge the signal families is to run them on a chargeback you have already paid for.

5 credits on signup · no card required