Fraud Intelligence Report: Discover how digital fraud is evolving and protect your customers’ identities

Device intelligence

Device Intelligence: More Context About the Device, Less Uncertainty About Who’s Operating

Who you are doesn’t change. Where you connect from and what you connect with does, and that also forms part of your identity.

Rooted device detection, emulator detection, masked network identification, cloned application detection, and remote control monitoring on every connection. We add these signals to the user’s identity profile, providing evidence of what was detected and who reviewed it.

iBeta Level 1 quality certification logo

iBeta level 1

iBeta Level 2 quality certification logo

iBeta level 2

LRQA ISO 22301 certification logo

ISO 22301

AICPA SOC 2 quality certification logo

SOC 2 Type 2

LRQA ISO 27017 certification logo

ISO 27001

LRQA ISO 27017 certification logo

ISO 27017

NIST quality certification logo

NIST FPAD

SEPBLAC quality certification logo

SEPBLAC

GDPR Ready certification logo

GDPR Ready

+190 financial institutions across 30+ countries trust Facephi

What We Detect

Rooted Device, Emulator, or Hidden Network: The Signals We Analyze Before Any Operation

Signals related to the device, network, location, and activity, grouped around the four questions fraud teams ask during every session. Integrity signals are platform-specific: root detection on Android and jailbreak detection on iOS. A signal informs, it does not decide. Each institution determines what should be blocked, flagged for review, or allowed to proceed.

Digital session auditing solution that detects VPNs, residential proxies, incognito browsing, and other fraud indicators to validate user authenticity. Advanced fraud detection and identity verification for online sessions.

Remote access trojans, cloned applications, and emulators. These are the signals we monitor:

Rooted Device Jailbreak Android Emulator Cloned Application Tampering Dynamic Instrumentation Developer Tools Factory Reset
Signal What It Means
Rooted Device Android system permissions have been opened, allowing the application to be manipulated from within the device.Permisos del sistema abiertos en Android: permiten manipular la aplicación desde dentro.
Jailbreak The iOS equivalent, where core operating system protections have been disabled.
Android Emulator Software designed to mimic a mobile device, commonly used to create fake devices and operate at scale.
Cloned Application A modified copy of the original application used to duplicate accounts or bypass restrictions.
Tampering The application or the requests it sends have been modified.
Dynamic Instrumentation Tools attached to the application while it is running. Often a precursor to bypassing security controls.
Developer Tools Development utilities active on a device or browser where they would not typically be expected.
Factory Reset The device was recently reset and now presents itself as a new device.

Traffic hidden behind VPNs, proxies, or falsified locations.

VPN Residential Proxy Datacenter IP Tor Exit Node Spoofed Location Incognito Browsing
Signal What It Means
VPN Routes traffic through another location. It has legitimate uses but conceals the true origin of the connection.
Residential Proxy Traffic exits through a residential internet connection to appear as a normal user.
Datacenter IP The connection originates from a server. Very few legitimate banking users connect from servers.
Tor Exit Node The connection arrives through a network specifically designed to anonymize its origin.
Spoofed Location The mobile device reports a location different from its actual one to appear consistent with the legitimate user.
Incognito Browsing The browser does not store data between visits, making returning users harder to recognize.

Sessions intercepted by a third party.

Man-in-the-Middle Attack Network Anomalies IP on Attack Lists
Signal What It Means
Man-in-the-Middle Attack A third party has positioned itself between the application and the institution, with the ability to intercept or modify communications.
Network Anomalies The connection configuration contains inconsistencies that suggest additional layers or manipulation.
IP on Attack Lists The IP address has previously been associated with attacks or spam activity and carries accumulated risk reputation.

Bots, automation, and device farms.

Bots Velocity Anomaly High-Activity Device
Signal What it Means
Bots The activity originates from an automated program rather than a genuine user.
Velocity Anomaly Too many IP addresses, countries, or identities are linked to the same source within a very short period of time.
High-Activity Device A single device is associated with significantly more sessions than normal, indicating multiple identities may be managed from it.

What Happens When a Signal Is Detected

From Signal to Decision in Three Steps

Signals do not act on their own. They are delivered instantly, institutions apply their own risk policies, and every review is documented.

01

Real-Time Detection

Before the user’s first transaction or operation.

02

Signals Inform, They Do Not Decide

Based on your institution’s risk tolerance.

Block
Flag for Review
Allow

03

Human Review with Full Traceability

A rooted device may still belong to a legitimate customer.

Every review records who assessed the session and when, including reviewer name and role.

Where It Fits

A real face from a device that’s no longer theirs

Identity verification confirms who a person is. This tells you where they’re operating from and what device they’re using right now. A customer verified a year ago may log in today from a compromised device, and onboarding could never have known that.

Person checking a smartphone while walking along an urban street, with buildings and trees in the background.

Every session, not just onboarding

Checks are performed on every session, not just once during onboarding.

Person using a smartphone in a well-lit indoor environment and viewing the device screen.

How the person behaves

The person is analyzed through behavioral biometrics.

Person participating in a video call from a terrace with a blurred urban backdrop.

The image and video channel

Person using a smartphone in front of an office building, accompanied by an overlaid activity and risk metrics dashboard.

Access to an existing account

Covered by account takeover prevention.

Person seated in an outdoor setting using a smartphone, alongside a high-risk alert displayed on screen.

Signals that accumulate

Each signal is added to the identity risk profile and influences the next decision.

Laptop displaying a monitoring dashboard featuring key metrics, alerts, and geolocation intelligence.

One kit across all channels

A single kit for web, iOS, and Android, from onboarding through every session, as part of the fraud prevention solutions.

Sessions and Auditability

Every Session Documented and Audit-Ready

Analysts can reconstruct a session transaction by transaction from a single interface. Compliance teams have a complete record of who reviewed the session and when.

Date, identifier, duration, environment, status, operating system, device, and location, with search, filtering, and sorting capabilities.

Six tabs: Signal Summary, Alerts, Device, Network & Location (with map), Timeline, and Audit. From the header, users can jump directly to the identity record.

Organized by operation, with its outcome. For login events: device details, network information including IP, ASN, and provider, assessed integrity, and actual velocity windows (distinct IPs within 5 minutes, 1 hour, and 24 hours).

Timestamp, user, profile, and action. Not only a record of what the end user did, but also who reviewed it. It answers the auditor’s question.

Industry Applications

Use Cases by Industry

Facephi user signing a document at a bank

Banking

Remote-access banking trojans operate from devices that have already passed authentication checks. Verifying the operating environment before a transaction creates the first layer of defense.


Mobile Banking Fraud Prevention
Man reviewing multiple monitors displaying financial information

Fintech

Digital onboarding and high transaction volumes attract large-scale automated fraud, including emulators, device farms, bots, and cloned applications.

Detection stops threats before they consume onboarding resources.


Fraud Prevention for Fintech
Man and woman meeting in an office

Insurance

Policyholders interact during both policy issuance and claims processes, often leaving limited historical activity for comparison.

Device status is just as important during the first session as during the hundredth.


Identity Verification for Insurance
Cámara de alguna administración pública con muchas sillas y mesas perfectamente organizadas

Public Sector

Fraud involving public services and benefits is increasingly automated through emulators and device farms.

Blocking bots at the entry point requires no additional effort from legitimate citizens.


Identity Solutions for the Public Sector

Why Facephi

Four Criteria for Comparison

Signal Coverage

Signals covering device, network, location, and activity, transparently detailed throughout this page.

Evidence and Investigation

Complete session timelines and records of who reviewed every case.

Connected to Verified Identity

Device signals do not disappear when the session ends.
They become part of the individual’s identity risk profile and influence future decisions.

Deployment Flexibility

On-premises Kubernetes, private cloud, or SaaS, with data residency fully controlled by the customer.

User interacting with a mobile device during a digital identity verification process that combines liveness detection, geolocation intelligence, and credential validation. Identity verification and digital fraud prevention platform.

Technical Specifications

What You Need to Compare Solutions

Environments Web, iOS, and Android, using a consistent data model across all platforms.
Signals Device, network, location, and activity signals, including Android root detection and iOS jailbreak detection.
Action Signals are identified instantly, before the first operation occurs.
Evidence Transaction-level timelines and reviewer activity logs.
Deployment On-premises Kubernetes, private cloud, or SaaS, with customer-controlled data residency.

Next Step

Request a Demo

We’ll show you how fraud prevention fits into your workflow using a real use case from your industry, including: what was detected, what evidence was recorded and how the investigation is conducted. Just three fields and we’ll get in touch.

Contact us

Frequently Asked Questions About Device Intelligence

Device Intelligence is the collection of signals related to the condition, integrity, and network environment of the device being used.

The market may also refer to it as device fingerprinting.

Its purpose is to identify technical threats in the most challenging scenario: the user’s identity remains unchanged, but the device involved cannot be trusted.

Behavioral Biometrics analyzes how a person interacts with a system: rhythm, pressure, gestures, and interaction patterns.

Device Intelligence analyzes the condition of the device and network being used.

Behavioral Biometrics identifies when the operator behaves differently from the legitimate account holder.

Device Intelligence identifies when the environment itself has been compromised.

They are complementary solutions designed to answer different questions.

Fraud originating from manipulated technical environments, including:

  • Cloned and tampered applications
  • Emulators
  • Bot-driven automation
  • Account impersonation from untrusted devices
  • Sessions intercepted by third parties

In all these cases, the user’s identity data remains unchanged. The environment does not.

A remote-access banking trojan is malware installed on the victim’s device that allows attackers to view the screen and operate through the legitimate banking application.

Credentials are genuine and the device may appear familiar, meaning identity controls can produce successful results.

The warning signs come from environmental indicators such as:

  • Compromised device integrity
  • Dynamic instrumentation
  • Active developer tools
  • Man-in-the-middle activity
  • Behavioral patterns inconsistent with a single legitimate user

Android emulators are detected directly through dedicated signals.

Device farms are not identified as a category themselves. Instead, the solution detects the bots and activity patterns that reveal them, including:

  • Unusually high device activity
  • Velocity anomalies
  • Multiple identities or countries linked to the same device within short periods

These signals stop the activity pattern even without explicitly labeling a device farm.

Visibility includes real operational windows showing:

  • Different IP addresses within 5 minutes
  • Different IP addresses within 1 hour
  • Different IP addresses within 24 hours
  • Different countries detected during the last 24 hours

Each session includes:

  • Detected signals
  • A complete event timeline organized by operation
  • Device and network details
  • A record of who reviewed or modified the session

It captures not only what the end user did, but also what investigators and reviewers did, providing the answer auditors need: who reviewed the case and when.

The solution supports:

  • Web
  • iOS
  • Android

using a consistent data model across all channels.

Integrity checks are platform-specific:

  • Root detection on Android
  • Jailbreak detection on iOS

Supported version matrices are reviewed during the technical assessment process and through public documentation.

Yes.

Device Intelligence can be deployed as:

  • Kubernetes on-premises
  • Private cloud
  • SaaS

Data residency remains under the institution’s control and can be aligned with local regulatory requirements.

The deployment model does not change available signals or session investigation capabilities.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link