One signal is noise. Four is a pattern.
Verify AI runs five families of check on every order and reads them against each other. That is the difference between rejecting a customer for using a VPN and catching the order where the VPN was the smallest problem.
Every rule you write rejects someone real.
Block VPNs and you lose the privacy-conscious. Block freight forwarders and you lose genuine international buyers. Block first orders over a threshold and you lose the customer who finally decided to buy the expensive one.
The signals are not wrong. Reading them one at a time is. A datacenter IP on an order that is otherwise unremarkable is a note; the same IP alongside a reshipper address and a mismatched cardholder is the whole case.
So the analysis reports each finding separately, with its own severity, and scores the combination. You see both the parts and the conclusion, which is what lets you disagree with either one.
Five questions asked of every order
Categories match the category field on every risk factor the API returns, so a finding a merchant reads in the Shopify admin belongs to a family named on this page.
customer
Customer
Is this a real person who wants the goods?
- Email or phone appearing in fraud databases and scam reports
- Disposable and throwaway email domains
- Phone numbers that are invalid or route to VoIP
- Names that do not resolve to a person
- A day-old account placing a four-figure order
address
Address
Does this address exist, and does it want the parcel?
- Shipping and billing addresses checked for real-world existence
- Freight forwarder and reshipper addresses
- Billing and shipping in different countries
- Postal codes that do not match the city or state
- PO boxes on high-value orders
payment
Payment
Does the card match the person using it?
- Cardholder name against the customer name on the order
- Prepaid and high-risk card brands
- Expiry patterns consistent with card testing
- Payment details that contradict the billing address
technical
Technical
Where is the order coming from?
- IP geolocation against both addresses on the order
- VPN, proxy, Tor, and datacenter ranges
- IP addresses listed in spam and abuse databases
- User agents that read as automation rather than a browser
behavioral
Behavioral
Does this order fit the customer who placed it?
- Cancellation and return rates against total order count
- Order value against the customer average
- First order that is far larger than a first order should be
- Rush shipping on goods that resell easily
- Item combinations that show up in reshipping fraud
And then
They get weighed against each other
A VPN on its own is a low severity note. A VPN, a reshipper address, and a card in someone else’s name is the pattern. The score reflects the combination, and the factor list shows you which parts of it fired.
Severity: low · medium · high · critical
The same signal, two orders
Both of these orders came from an IP the customer did not sit behind at home. Only one of them is a problem.
Order #1038
18Third order from a two-year-old account. Home address, card in the same name, ships to the billing address.
- IP resolves to a consumer VPNlowtechnical
The customer uses a commercial VPN, which millions of people do. On its own it moves the score by a few points.
Order #1042
78First order at nine times the category average, shipping to a consolidation facility, paid with a card in a third party name.
- IP resolves to a datacenter rangemediumtechnical
The same family of signal as the VPN above, and here it is corroborated by three other findings rather than standing alone.
- Shipping address is a freight forwarderhighaddress
- Cardholder name does not match customerhighpayment
A rules engine that blocks non-residential IP addresses rejects both. Verify AI ships the first one and holds the second, and tells you which three findings made the difference.
Where the findings come from
Live sources rather than a rules table that was current when it shipped.
- Live web research
- Fraud databases, scam report sites, and reputation records are read at the moment the job runs. A phone number reported last week is found this week.
- Address validation
- Shipping and billing addresses are checked for real-world existence, and against the known freight forwarder and reshipper facilities that consumer address validation does not flag.
- IP intelligence
- Geolocation, hosting and datacenter ranges, proxy and VPN detection, and spam and abuse listings. Cached, so a repeated IP does not cost a second lookup.
- Email validation
- Disposable and throwaway domains, plus deliverability signals that catch an address created for one order.
- The order itself
- Amount against history, item combinations, shipping speed, timestamp, and the internal consistency of the addresses, payment, and customer on the payload.
Four levels, and what each one is for
Note it
Low
Worth a look
Medium
Act on it
High
Stop
Critical
Severity is per factor. The band on the order is the conclusion drawn from all of them, so an order can carry a high severity finding and still score in the medium band when everything else about it checks out.
What it can and cannot see
Where does the fraud data come from?
How current is it?
Do you check the same things for every order?
Can we turn a family off?
Does a single critical factor mean a critical score?
One score, four surfaces
Send an order you already know was fraud.
The fastest way to judge the signal families is to run them on a chargeback you have already paid for.
5 credits on signup · no card required