POST /loginVerifyRight password, unfamiliar device and network
- New device for this account
- Network never seen for this user
- Real browser, human input
Comparison
LexisNexis ThreatMetrix is a risk decision engine that scores logins, account openings and payments using device, location, identity and behavior signals from its shared Digital Identity Network. Kavra assesses every request from what it observes directly, keeps each customer's data isolated, and returns a plain-language finding with a recommended action.
POST /loginVerifyRight password, unfamiliar device and network
ThreatMetrix is part of LexisNexis Risk Solutions. LexisNexis describes it as a risk decision engine that brings several risk technologies into one place for new account opening, logins and account management, account takeover and payments. It analyzes device, geolocation, IP address, email address, phone, behavioral patterns and transaction details, and looks at distance anomalies, age, history, velocity and previous risk associations.
The center of the product is the Digital Identity Network. According to LexisNexis, it spans 200+ countries and territories, processes about 3 billion transactions a month, and holds a tokenized identifier for about 1.4 billion recognized users. Its intelligence is crowdsourced from participating organizations and covers web and mobile device identification, true location and behavior analysis, identity and link analysis, and bot and malware threat intelligence. LexID Digital is the network's identifier; LexisNexis says it merges offline and online data to give confidence and trust scores for a digital identity.
Around that sit BehavioSec behavioral biometrics (typing rhythm, mouse and touch patterns), machine learning models configured in a no-code environment, and the Dynamic Decision Platform for forensics, case management, reporting and workflow orchestration.
ThreatMetrix leans on what a large shared network already knows about an identity. Kavra relies on what it can observe and prove about the request in front of it, and never shares one customer's data with another. Every assessment comes back with a plain-language headline, the findings behind it, risk by domain (automation, impersonation, network, tampering, abuse), network context and a recommendation: allow, verify or block. Your backend decides.
Kavra analyzes 3,000+ data points on every visit and looks for contradictions between layers, because a disguise that fools one layer rarely fools all of them. For account takeover, it compares each login with the account's own history: new device, new network, impossible travel, known-bad device. Trusted devices are kept per account, and devices can be revoked through the API.
Both products are built to score risk in real time and leave the outcome to your systems. They differ in where the evidence comes from and how much platform comes with it.
| Kavra | LexisNexis ThreatMetrix | |
|---|---|---|
| Main evidence | What Kavra observes on each request across layers | Device, location, identity and behavior, enriched by the Digital Identity Network |
| Cross-customer data | None; strict tenant isolation | Crowdsourced consortium intelligence, tokenized |
| Offline identity data | Not used | LexID Digital merges offline and online data |
| Output | Headline, findings, domain risk, recommended action | Confidence and trust scores, with workflow orchestration |
| Bot detection | Across network, device, browser integrity and behavior | Bot and malware threat intelligence in the network |
| Proxy intelligence | Own measurement of commercial proxy exit IPs plus 30+ feeds | IP and true location analysis; proxy methods not publicly detailed |
| Behavioral biometrics | Behavior is one of Kavra's analysis layers | BehavioSec, a dedicated behavioral biometrics product |
| Case management | Investigate view with evidence per assessment | Forensics, case management and orchestration in the Dynamic Decision Platform |
| Integration | One script plus one API call, first results the same day | Delivered through the Dynamic Decision Platform; deployment timeline not publicly documented |
| Data you must send | No names, emails or phone numbers; technical signals only (see privacy policy) | Email, phone and identity signals among inputs, tokenized per LexisNexis |
ThreatMetrix suits large identity and risk programs, and some needs point clearly to it or to a platform like it.
The two can also coexist. A bank can keep an enterprise identity platform for onboarding and payments, and add Kavra in front of login, signup and high-value API endpoints to catch bots and spoofed devices with a readable reason. See how this works in fintech.
Login or signup is usually best: high volume, clear outcomes and a known fraud rate.
Add the script and API call next to your current setup. Nothing is blocked.
Look at where the two disagree. Read Kavra's findings for each request and check them against confirmed fraud.
Start with cautious, balanced or strict, map allow, verify and block to your flow, and label outcomes back through the API.
LexisNexis and ThreatMetrix are trademarks of their respective owners. This comparison is based on public information as of September 2026 and may change. Kavra Lab is not affiliated with LexisNexis Risk Solutions.
How Kavra helps
Evidence you can read, from data that stays yours.
Headline, findings, domain risk and a recommended action on every assessment.
Strict tenant isolation, opaque visitor IDs, no names or emails required.
Kavra's own edge network sees how a visitor actually connects.
New device, new network, impossible travel and trusted devices per account.
First results the same day. Kavra recommends; your backend decides.
FAQ
Something else? Talk to our team.
ThreatMetrix is a risk decision engine from LexisNexis Risk Solutions. It scores account openings, logins and payments using device, location, identity and behavior signals, enriched by the Digital Identity Network, a crowdsourced and tokenized pool of transaction intelligence from participating organizations. It comes with forensics, case management and workflow tools through the Dynamic Decision Platform.
A consortium pools intelligence from many organizations so a device or identity seen elsewhere carries its history with it. Kavra keeps each customer's data isolated and instead proves what it can about each request: the real device, the real connection, proxy exits, automation and rotation. Both approaches are valid; they suit different privacy and data-sharing policies.
For bot detection, spoofed devices, multi-accounting and login risk, often yes. Kavra does not offer offline identity data, consortium lookups or dedicated behavioral biometrics, so if your program depends on those, keep them and add Kavra where automated and disguised traffic is the main threat.
Kavra compares the login with the account's own history: known or new device, usual or new network, impossible travel, and devices already marked bad. It also checks for automation and tampering. When evidence is mixed, it recommends verify, and your backend chooses the step-up, such as a one-time code or a trusted-device prompt.
No. Kavra assesses requests from technical and network signals, not from identity data. Those signals, such as the IP address, can still be personal data under GDPR, so Kavra applies the legal basis per visitor region, respects your consent manager and documents the processing in its privacy policy. Visitor IDs are pseudonymous and each customer's data stays isolated.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.