The fraud detection use case ranks an email validator first, and eleven fraud vendors are not on it

The fraud detection use case ranks an email validator first, and eleven fraud vendors are not on it

Fraud Detection & Prevention now resolves 24 providers and 158 APIs. The highest-rated of them is Mailboxlayer, an email validation API, at 68.9. Behind it come Amazon SageMaker and Amazon Neptune. The companies whose entire business is stopping fraud sit much further down, or are not on the page at all.

When this blog built a fraud stack from the same page in July it had 29 providers and 723 APIs, and Sift was the pure-play anchor at 73.4. Sift is 35.0 today, thin, and no longer a member.

Who is on the page

Provider Band Score Kind
Mailboxlayer exemplar 68.9 email validation
Amazon SageMaker exemplar 67.3 ML platform
Amazon Neptune exemplar 66.7 graph database
IPinfo strong 64.1 IP intelligence
Alloy strong 54.7 identity and fraud decisioning
Ravelin thin 36.2 payment fraud
Riskified thin 34.2 payment fraud
Kount emerging 19.5 payment fraud

Every one of those is a legitimate part of a fraud build. But a page that ranks the signal sources and the infrastructure above the decisioning vendors is telling a buyer something the market would not.

Why the specialists are missing

Membership comes from the use cases a provider declares, matched against twelve aliases: fraud prevention, chargeback, account takeover, bot detection, device fingerprint, payment fraud and the rest. Alloy, Ravelin, Riskified and Kount each carry a written list of use cases, so they match. Eleven providers tagged Fraud Prevention carry an empty one, so they do not:

Provider Band Score
Socure strong 63.6
SEON developing 45.4
Castle developing 43.7
Telesign developing 40.7
Fingerprint thin 36.5
Sift thin 35.0

Plus Forter (27.6), Incognia (26.1), Feedzai (25.7), Signifyd (25.0) and Sardine (20.5). Socure alone would enter the page fifth. The tag and the use case are two different fields, and the page reads only one of them.

What the specialists’ scores say

Even counted, the pure-plays are not describing themselves well. Riskified’s Agent Readiness is 3.8, Kount’s is 2.5, Signifyd’s is 2.5. This is a category built on real-time machine decisions, where an agent calling a risk score before approving a payment is the obvious next customer, and its vendors’ public surfaces are close to unreadable to that customer. The July post said specialist companies describe themselves properly because the API is the company. Two months of scoring say that is true of Alloy and Socure and not of most of the rest.

A build path that survives the gap

Cheap signals first: IPinfo and Mailboxlayer at signup. Identity and onboarding decisions with Alloy or Socure. Payment-side scoring with Ravelin, Riskified or Kount, knowing you will read their docs more than their contracts. Neptune when you realise you are fighting rings, not individuals.

Takeaway

The page is half a map. The fix on our side is to read the Fraud Prevention tag as membership evidence, which would add eleven vendors. The fix on theirs is the same as ever: publish the contract, the error model and the scopes, so the risk decision an agent needs is one it can actually find.

Browse the use case at apis.io/use-cases/fraud-detection/.

← DigitalOcean measured structured output under load, and its own managed endpoint slipped
The Svix Message Attempt API is the receipt for every webhook, and eight of its nine operations only read →