How a risk score is built
No single signal proves fraud. A VPN can be a privacy-minded customer. A new device can be a new phone. A fast form fill can be a password manager. A risk score exists to weigh many of these weak signals together and turn them into one decision-ready number.
Early fraud systems added points by hand: plus 20 for a proxy, plus 30 for a mismatched country. Modern systems use machine learning models trained on labeled outcomes, such as confirmed chargebacks, account takeovers and bot traffic, alongside rules that experts still write for clear-cut cases. The model learns which combinations matter. A VPN on its own may barely move the score, while a VPN plus an automated browser plus a device linked to twenty other accounts pushes it near the top.
- Network: IP reputation, proxy, VPN or Tor use, datacenter or residential origin.
- Device and browser: whether the device is real, consistent and not tampered with.
- Behavior: how the visitor types, moves and navigates, and how fast.
- Identity and history: whether this device or account has been seen before, and what it did.
Scores also drift. Fraud patterns change, so a model that is not retrained on fresh outcomes slowly loses its edge, and a threshold that was right last quarter may now block too much or too little.
From score to decision
A score is only useful with thresholds. Most teams use three bands and tune them per action.
| Band | Typical action | Example |
|---|---|---|
| Low | Allow without friction | Returning customer on a trusted device |
| Medium | Verify: invisible challenge, OTP or review | New device on a VPN at login |
| High | Block or hold the action | Automated browser linked to many accounts at signup |
Why the reasons matter as much as the number
A bare number is hard to trust. When a real customer is blocked, support needs to know why. When the fraud team tunes a rule, it needs to see what drove a score up. And when a score is used in a dispute or an audit, the evidence has to be there.
That is why a good risk score comes with an explanation. Kavra returns a score with a plain-language headline, the findings behind it, risk levels by domain such as automation, impersonation, network, tampering and abuse, and a recommended action. Your backend makes the final decision. You can start in observe-only mode and see how scores fall across your real traffic before you block anything. See how scores drive decisions at login in account takeover prevention, or read the integration notes for developers.