Identity-first fraud detection

One identity.
One verdict.
Every visit.

Authentiq resolves a single durable identity across sessions, devices, and supply — then scores what they're doing using one of the most sophisticated methodologies on the market. Built for any platform where bad actors and money meet.

Request access →
Private beta · Q3 2026 SDK · Hosted screening EU · US
01 The shape of the problem

The fraud is identity-driven. Most tooling isn't.

Four archetypes, twelve verticals

Automation at scale

Playwright, Puppeteer, anti-detect browsers — scripted farms completing surveys, claiming bonuses, and signing up at volume behind residential proxies.

Surfaces Rewards · Panels · Ad-tech · Sign-ups

Identity recycling

The same actor across incognito tabs, devices, accounts, and supply lines. Invisible without cross-session linkage and a durable identity model.

Surfaces Rewards · Gaming · Panels · Crypto

Synthetic & stolen

Fabricated KYC, card-testing rings, SIM-swap, account takeover. Identity-shaped attacks that pass surface checks but fail under cross-signal correlation.

Surfaces Fintech · Payments · Telecom

Coordinated real-device farms

Real fingers, fake intent. Sweatshop panels, scalper coalitions, click farms — detected through cadence, geography, and supply-side correlation.

Surfaces Ticketing · Ad-tech · Marketplaces · Social
02 Two layers, pick what fits

Sit silently underneath, or run the screen for us.

One identity model, two integration shapes

Identity & threat scoring SDK

Drop our SDK into login, registration, checkout — any surface. We sit silently underneath and tell your backend who you're really talking to. Provided Trust Score gives easy decision to take, Block on untrusted, verify more on suspicious, approve the trusted

BROWSER customer page SDK COLLECTS multiple layered signals browser · network · behavior · time passively, in the background identify() AUTHENTIQ API resolve identity match against prior visits cross-device link via shared anchors score 12 factors client integrity · network · velocity cross-visit anomalies · engagement multiplicative · explainable · auditable → trust verdict · 0.00 to 1.00 retrieve SERVER your backend DECIDE approve step-up block trusted suspicious fraudulent server-to-server · idempotency-keyed · no PII on the wire
retrievalidempotent · replay-safe
wireno PII transit
integration1 SDK · 1 webhook

Hosted screening

Redirect the user through a screening environment we run end-to-end — consent gate, adaptive browser challenge, multi-location IP probes, browser extension checks. Profiling questions are optional: run an identity-only screen for silent verification, or layer in postal-code lookup, email-risk grading and open-end AI-based analysis when you need them.

YOUR APP your app MINT INTENT tier (low/med/high) group_id return URL metadata redirect AUTHENTIQ SCREEN end-to-end on our infrastructure consent gate capture & timestamp full SDK analysis every identity & threat signal profiling (optional) postal · email · open-end behavioral & AI deep screening · attention checks → HMAC-signed callback token callback YOUR APP your app VERIFY & ACT check HMAC signature retrieve full verdict replay-safe forgery-proof identity-only screens skip profiling · verdict shape identical to SDK
callbackHMAC-signed
surfacefully owned by us
flowredirect · consume · return
03 The receipts

Twelve factors. Five groups.
One verdict, every one auditable.

Multiplicative · explainable · defendable

Client integrity

Is the browser real, and untouched?
01

Automation

We watch for the tells that a script is driving the browser instead of a person — automation frameworks, control-protocol traces, headless modes. The cleaner the runtime, the higher the trust.

02

Tampering

A browser's claims about itself should match how it actually behaves. We catch mismatches between what the page reports and what we observe — spoofed identity strings, canvas blockers, anti-detect browsers.

03

Browser challenge

We ask the browser to do a small amount of invisible work on every visit. Real users solve it in milliseconds; high-volume scripts pay a steep cost on every account, every claim, every signup.

04

Browser score

Browser add-ons betray purpose. We probe for the tooling fraud farms rely on — anti-detection plugins, automation helpers, fingerprint scramblers — without listing or storing the extensions a user has chosen privately.

Network

Where is the connection actually coming from?
05

IP risk

Hosting providers and known-abusive networks are not where your real customers come from. We rate the network the visit is arriving on and weight it against the rest of the picture.

06

VPN & Proxy

Tor exits, commercial VPNs, and proxy networks are signals on their own. We detect them — and where the user is hiding a different real location underneath, that's a stronger signal still.

07

IP Spoofing

Some connections look clean on the surface but mask a different true location underneath. We combine deep packet inspection with network-path analysis to expose the connection's real origin — flagging when the address a browser presents doesn't match where its traffic actually comes from.

Cross-visit anomalies

Does the identity move like a real person over time?
08

Impossible travel

Real people don't move between continents in minutes. We compare each visit against the identity's recent history and flag jumps that physics doesn't allow.

09

Burst velocity

Scripted attacks come in waves — the same account, the same address, or the same person hitting your endpoints faster than a human would. We track activity across short and long windows and surface the bursts.

10

Location churn

One person should not appear from a dozen different networks in a single week. We count how varied the source addresses are over time — diversity beyond normal use is suspicious.

Engagement

Does the interaction look human?
11

Human behavior

Real interaction has shape — pauses, typing rhythm, mouse paths, the timing between actions. We compare each visit's behavior against what a real human typically does on your surface.

Account quality

Is the account itself trustworthy?
12

Email risk

The email address itself is a signal. Disposable domains, role accounts, breach exposure, and abuse history all factor in — when a customer supplies an email, we score it.

04 Access

Get on the private beta.

Onboarding a small group of partners through summer. Early partners help shape the integration and get founding pricing locked in.

Request access →