Fraud Detection Software
Fraud detection software that stops fraud at onboarding, not in the chargeback report
The cheapest fraud to stop is the account that never opens. Zyphe detects forged and counterfeit documents, synthetic identities and injection attacks at the point of verification, and keeps watching once the customer is through: device signals, biometric uniqueness, and transaction monitoring on every payment.
What is fraud detection software?
Fraud detection software identifies fraudulent activity automatically: analysing identity documents for forgery, detecting synthetic and stolen identities, spotting manipulated or injected images, and flagging behaviour inconsistent with a legitimate customer. It works at onboarding and continuously afterwards.
Trusted by those who trust no one.
What the detection layer runs on
Identity document versions from 213 countries and territories, with the full list published in the documentation.
Default face-match threshold between the live capture and the document portrait. Configurable per flow.
Deepfake and injection-attack detection models are updated every month, and run in-house rather than through a third-party vendor.
What the platform detects
This list describes the product, not the category. Each item is a control Zyphe runs today.
Document fraud detection
Template and format validation, security-feature checks, machine-readable-zone and barcode parsing, and image forensics on every capture, across 4,000+ document versions. Chip reading where the document supports it.
Liveness and injection-attack detection
Active liveness with anti-spoof checks against photographs, screens, videos and masks, plus detection of synthetic or replayed imagery fed directly into the capture stream. Models updated monthly.
Synthetic identity detection
Biometric uniqueness across a flow catches the same face under a different identity, and proof of address with name matching, geolocation and screening catch the assembled identity a genuine document cannot vouch for.
Device and geolocation signals
The geolocation step records a device fingerprint, checks GPS against IP country, and flags VPN or proxy use and blacklisted IPs.
Duplicate and linked accounts
Biometric uniqueness across a flow, enabled on request, plus transaction-monitoring counts of counterparties shared across identities, one of the more reliable signals of a mule network.
Post-onboarding fraud monitoring
Velocity checks over 1 hour, 24 hours, 7 days and 30 days per identity and counterparty, on a deterministic rules engine that decides before funds move, plus AML re-screening on list refreshes and events.
How fraud detection runs in the flow
Detection is layered because fraud is. Each stage catches what the previous one cannot.
Forged documents break the security features around the altered area; counterfeits fail template matching and MRZ validation. Both are caught here.
Active liveness and injection-attack detection on the live capture, then a face match to the document portrait at a configurable threshold, with the model set refreshed monthly.
Fraudulently obtained genuine documents pass every document check. They are caught downstream: biometric uniqueness, proof of address with name matching, geolocation and VPN mismatch, sanctions and adverse media screening, and transaction monitoring after the account is open.
Fraud signals without a data honeypot
Documents and biometrics are processed transiently, then encrypted and stored in the individual's own vault. Zyphe keeps the verification results, the audit log and the cryptographic proofs, so the fraud decision is recorded and defensible without a central store of ID images that becomes the next breach.
Where data is stored, what is retained, and the audit status: the security and trust pageThree kinds of document fraud, three different controls
- Forged documents
- Genuine IDs that have been altered: a changed photograph, date or name. Caught by security-feature analysis and by comparing the printed data with the machine-readable zone.
- Counterfeit documents
- An official template reproduced from scratch. Caught by template matching against known genuine specimens, print-quality forensics and machine-readable-zone validation.
- Fraudulently obtained genuine documents
- Real IDs, issued by the real authority, on false information. They pass every document check because there is nothing wrong with the document. Zyphe catches them downstream, across signals the document cannot fake. Ask any provider, including us, how they handle this category.
Fraud detection and compliance on one platform
Fraud and AML are usually separate teams with separate budgets, and increasingly the same underlying data. A synthetic identity is both a fraud loss and a KYC failure. Running them on one platform means the fraud signal informs the customer risk rating, the compliance record captures the fraud decision, and the transaction monitoring rules can read the KYC risk score as a field.
Test it against fraud you have already seen
Bring cases that got through. That is the only benchmark that means anything.
Book a demo →Better compliance in 190+ Countries
Banking Secrecy Act
Enforces strict record-keeping and reporting requirements for financial institutions to prevent money laundering and financial crimes in the United States.
Anti-money Laundering Act
Establishes measures and responsibilities for financial intermediaries in Switzerland to prevent money laundering and terrorist financing.
Proceeds of Crime
Canadian regulation requiring financial institutions to detect, prevent, and report suspicious transactions related to criminal proceeds.
Terrorist Financing Act
Legislation enforcing measures in Canada to detect, prevent, and report financial activities linked to terrorist financing.
Anti-money Laundering
Australian regulation mandating financial entities implement robust compliance measures to detect, prevent, and report money laundering activities.
Counter-Terrorism Financing Act
Australian law ensuring financial institutions identify, monitor, and report activities related to financing of terrorism to maintain national and global security.
Integrate in as little as 15 minutes
curl -X POST https://verify.zyphe.com/v1/login_sessions \
-H 'Authorization: Bearer <API_KEY>' \
-H 'Content-Type: application/json' \
-d '{"auth_type": "email"}'
Frequent Questions
Software that automatically identifies fraudulent activity: forged or counterfeit documents, synthetic and stolen identities, manipulated or injected images, and suspicious behaviour, at onboarding and on an ongoing basis.
Detection identifies fraud that is occurring or has occurred. Prevention stops it before completion. In practice modern platforms do both: detection accurate enough to act on in real time becomes prevention.
By validating the document against known genuine templates, checking security features such as holograms and microprint, reading and cross-checking the machine-readable zone, analysing the image for tampering, and confirming the data matches other records. Read the full explainer
Liveness detection and injection-attack detection address deepfake and replay attacks at the capture stage. This is an active arms race, so the relevant question for any vendor is not whether they handle it but how recently their models were updated and against what. Zyphe's are updated monthly and run in-house.
It should not for most applicants. The design goal is passive signals for the majority and additional checks only where risk indicates. A system that adds friction for everyone is badly configured.
Fraud detection targets losses to the firm or its customers. AML monitoring targets the movement of criminal proceeds and carries a reporting obligation. They overlap in data and diverge in purpose, which is why Zyphe runs both on the same identity and the same rules engine. AML software
Explore more Zyphe products
Know Your Customer
Verify people without keeping their documents
Document and liveness verification against 4,000+ identity document versions from 213 countries and territories, with injection detection and sanctions, PEP and adverse media screening.
Learn more →Liveness detection
that confirms a person, not a picture of one
Liveness detection that confirms a real, present person: active liveness with anti-spoof checks, a configurable face match, and injection-attack detection, with models updated monthly and run in-house.
Learn more →Anti-Money Laundering
Screening and monitoring built for regulators
Sanctions, PEP, watchlist and adverse media screening with a banded score and the number of contributing sources, alongside a deterministic transaction monitoring engine that returns Allow, Review or Block.
Learn more →