Do I have to write rules myself?
No. Sensible defaults run from day one. You can then tune each threshold from the dashboard, with no code change and no release.
Every order is scored before it reaches the acquirer. Device, velocity and geography signals feed one decision. You set the thresholds. 3-D Secure 2 steps in only when the risk earns it.
Built for EU low-risk sellers: shops, subscription software firms and professional services. Blunt blocking costs good revenue. Tuned rules do not.
Five signal families feed the score. None of them decides alone. Together they separate a card tester from a first-time buyer.
01Device
Each checkout carries a device fingerprint, session age and browser traits. Reused devices across many cards stand out fast.
02Velocity
Count attempts by card, email, IP or device over a window you pick. Card testing shows up as a burst. The burst gets blocked.
03Geography
We compare the card issuing country with the billing and IP country. A mismatch raises the score. It does not block on its own.
04Basket
Ticket size, item count and first-order status all feed the score. A first order at ten times your average is worth a second look.
05History
Past approvals, refunds and disputes on the same payer feed back in. Good repeat buyers get a clear path through checkout.
Scores land beside approval data in real-time analytics, so you can see what a rule change did.
A rule ends in one of four outcomes: allow, step up, review or block. Thresholds are yours to move. Edits apply to the next order, with no release.
The table shows example rules, not defaults you are stuck with. Start with ours. Tune them once you have your own order history.
| Trigger | Outcome | Type |
|---|---|---|
| Velocity — 4+ cards on one device in 10 minutes | Block | card testing |
| Issuing country differs from billing country | Score + | soft signal |
| Order value above your set ceiling | Force 3-D Secure 2 | step-up |
| Payer has a settled dispute on file | Review queue | manual |
| Repeat payer, three clean orders | Allow | trusted list |
Strong customer authentication is a PSD2 duty. It is also a common place to lose sales. Every prompt adds friction. So we ask for one only when the rules say it is worth it.
Low-value and trusted-payer exemptions are requested where the rules allow. When a challenge does fire, liability for that order shifts to the issuer. The result is stored with the payment and reused as dispute evidence.
Cards are one rail among several. Open banking carries bank-side authentication of its own, with no card number in the flow at all.
More on the rails: card & APM processing and open banking.
Screening cuts the volume. It never gets it to zero. So the case flow is built in.
Schemes send early warnings before a case opens. We surface them in the dashboard and by webhook.
Refund early and the case often stops there. Choose to defend and we open a slot for your evidence.
Upload delivery proof, logs and the 3-D Secure 2 result. We format the file for the scheme.
Every stage is stamped in the dashboard. Export the case list as CSV for your finance team.
No. Sensible defaults run from day one. You can then tune each threshold from the dashboard, with no code change and no release.
Scoring runs inline, before the authorisation call. Shoppers see one flow. Only stepped-up orders get an extra bank prompt.
No card number reaches your servers. Vaulting stays gateway-side under our PCI DSS Level 1 scope. Your return stays at SAQ A.
We underwrite low-risk sellers on purpose. A cleaner book means steadier approval rates and fewer scheme penalties for everyone on it.
Replay approvals, declines and challenge flows before a single live order. Keys are self-service. No demo call stands in the way.