+190 financial institutions across 30+ countries trust Facephi
What We Detect
Rooted Device, Emulator, or Hidden Network: The Signals We Analyze Before Any Operation
Signals related to the device, network, location, and activity, grouped around the four questions fraud teams ask during every session. Integrity signals are platform-specific: root detection on Android and jailbreak detection on iOS. A signal informs, it does not decide. Each institution determines what should be blocked, flagged for review, or allowed to proceed.
Remote access trojans, cloned applications, and emulators. These are the signals we monitor:
| Signal | What It Means |
|---|---|
| Rooted Device | Android system permissions have been opened, allowing the application to be manipulated from within the device.Permisos del sistema abiertos en Android: permiten manipular la aplicación desde dentro. |
| Jailbreak | The iOS equivalent, where core operating system protections have been disabled. |
| Android Emulator | Software designed to mimic a mobile device, commonly used to create fake devices and operate at scale. |
| Cloned Application | A modified copy of the original application used to duplicate accounts or bypass restrictions. |
| Tampering | The application or the requests it sends have been modified. |
| Dynamic Instrumentation | Tools attached to the application while it is running. Often a precursor to bypassing security controls. |
| Developer Tools | Development utilities active on a device or browser where they would not typically be expected. |
| Factory Reset | The device was recently reset and now presents itself as a new device. |
Traffic hidden behind VPNs, proxies, or falsified locations.
| Signal | What It Means |
|---|---|
| VPN | Routes traffic through another location. It has legitimate uses but conceals the true origin of the connection. |
| Residential Proxy | Traffic exits through a residential internet connection to appear as a normal user. |
| Datacenter IP | The connection originates from a server. Very few legitimate banking users connect from servers. |
| Tor Exit Node | The connection arrives through a network specifically designed to anonymize its origin. |
| Spoofed Location | The mobile device reports a location different from its actual one to appear consistent with the legitimate user. |
| Incognito Browsing | The browser does not store data between visits, making returning users harder to recognize. |
Sessions intercepted by a third party.
| Signal | What It Means |
|---|---|
| Man-in-the-Middle Attack | A third party has positioned itself between the application and the institution, with the ability to intercept or modify communications. |
| Network Anomalies | The connection configuration contains inconsistencies that suggest additional layers or manipulation. |
| IP on Attack Lists | The IP address has previously been associated with attacks or spam activity and carries accumulated risk reputation. |
Bots, automation, and device farms.
| Signal | What it Means |
|---|---|
| Bots | The activity originates from an automated program rather than a genuine user. |
| Velocity Anomaly | Too many IP addresses, countries, or identities are linked to the same source within a very short period of time. |
| High-Activity Device | A single device is associated with significantly more sessions than normal, indicating multiple identities may be managed from it. |
What Happens When a Signal Is Detected
From Signal to Decision in Three Steps
Signals do not act on their own. They are delivered instantly, institutions apply their own risk policies, and every review is documented.
01
Real-Time Detection
Before the user’s first transaction or operation.
02
Signals Inform, They Do Not Decide
Based on your institution’s risk tolerance.
03
Human Review with Full Traceability
A rooted device may still belong to a legitimate customer.
Every review records who assessed the session and when, including reviewer name and role.
Where It Fits
A real face from a device that’s no longer theirs
Identity verification confirms who a person is. This tells you where they’re operating from and what device they’re using right now. A customer verified a year ago may log in today from a compromised device, and onboarding could never have known that.
Every session, not just onboarding
Checks are performed on every session, not just once during onboarding.
How the person behaves
The person is analyzed through behavioral biometrics.
The image and video channel
Protected by injection attack defense.
Access to an existing account
Covered by account takeover prevention.
Signals that accumulate
Each signal is added to the identity risk profile and influences the next decision.
One kit across all channels
A single kit for web, iOS, and Android, from onboarding through every session, as part of the fraud prevention solutions.
Sessions and Auditability
Every Session Documented and Audit-Ready
Analysts can reconstruct a session transaction by transaction from a single interface. Compliance teams have a complete record of who reviewed the session and when.
Date, identifier, duration, environment, status, operating system, device, and location, with search, filtering, and sorting capabilities.
Six tabs: Signal Summary, Alerts, Device, Network & Location (with map), Timeline, and Audit. From the header, users can jump directly to the identity record.
Organized by operation, with its outcome. For login events: device details, network information including IP, ASN, and provider, assessed integrity, and actual velocity windows (distinct IPs within 5 minutes, 1 hour, and 24 hours).
Timestamp, user, profile, and action. Not only a record of what the end user did, but also who reviewed it. It answers the auditor’s question.
Industry Applications
Use Cases by Industry
Why Facephi
Four Criteria for Comparison
Signal Coverage
Signals covering device, network, location, and activity, transparently detailed throughout this page.
Evidence and Investigation
Complete session timelines and records of who reviewed every case.
Connected to Verified Identity
Device signals do not disappear when the session ends.
They become part of the individual’s identity risk profile and influence future decisions.
Deployment Flexibility
On-premises Kubernetes, private cloud, or SaaS, with data residency fully controlled by the customer.
Technical Specifications
What You Need to Compare Solutions
| Environments | Web, iOS, and Android, using a consistent data model across all platforms. |
| Signals | Device, network, location, and activity signals, including Android root detection and iOS jailbreak detection. |
| Action | Signals are identified instantly, before the first operation occurs. |
| Evidence | Transaction-level timelines and reviewer activity logs. |
| Deployment | On-premises Kubernetes, private cloud, or SaaS, with customer-controlled data residency. |
Next Step
Request a Demo
We’ll show you how fraud prevention fits into your workflow using a real use case from your industry, including: what was detected, what evidence was recorded and how the investigation is conducted. Just three fields and we’ll get in touch.
Frequently Asked Questions About Device Intelligence
Device Intelligence is the collection of signals related to the condition, integrity, and network environment of the device being used.
The market may also refer to it as device fingerprinting.
Its purpose is to identify technical threats in the most challenging scenario: the user’s identity remains unchanged, but the device involved cannot be trusted.
Behavioral Biometrics analyzes how a person interacts with a system: rhythm, pressure, gestures, and interaction patterns.
Device Intelligence analyzes the condition of the device and network being used.
Behavioral Biometrics identifies when the operator behaves differently from the legitimate account holder.
Device Intelligence identifies when the environment itself has been compromised.
They are complementary solutions designed to answer different questions.
Fraud originating from manipulated technical environments, including:
- Cloned and tampered applications
- Emulators
- Bot-driven automation
- Account impersonation from untrusted devices
- Sessions intercepted by third parties
In all these cases, the user’s identity data remains unchanged. The environment does not.
A remote-access banking trojan is malware installed on the victim’s device that allows attackers to view the screen and operate through the legitimate banking application.
Credentials are genuine and the device may appear familiar, meaning identity controls can produce successful results.
The warning signs come from environmental indicators such as:
- Compromised device integrity
- Dynamic instrumentation
- Active developer tools
- Man-in-the-middle activity
- Behavioral patterns inconsistent with a single legitimate user
Android emulators are detected directly through dedicated signals.
Device farms are not identified as a category themselves. Instead, the solution detects the bots and activity patterns that reveal them, including:
- Unusually high device activity
- Velocity anomalies
- Multiple identities or countries linked to the same device within short periods
These signals stop the activity pattern even without explicitly labeling a device farm.
Visibility includes real operational windows showing:
- Different IP addresses within 5 minutes
- Different IP addresses within 1 hour
- Different IP addresses within 24 hours
- Different countries detected during the last 24 hours
Each session includes:
- Detected signals
- A complete event timeline organized by operation
- Device and network details
- A record of who reviewed or modified the session
It captures not only what the end user did, but also what investigators and reviewers did, providing the answer auditors need: who reviewed the case and when.
The solution supports:
- Web
- iOS
- Android
using a consistent data model across all channels.
Integrity checks are platform-specific:
- Root detection on Android
- Jailbreak detection on iOS
Supported version matrices are reviewed during the technical assessment process and through public documentation.
Yes.
Device Intelligence can be deployed as:
- Kubernetes on-premises
- Private cloud
- SaaS
Data residency remains under the institution’s control and can be aligned with local regulatory requirements.
The deployment model does not change available signals or session investigation capabilities.