Accertify
Accertify is an enterprise fraud prevention and payments company based in Itasca, Illinois, and led by president Mark Michelon. It was a wholly owned subsidiary of American Express from 2010 until May 2024, when the private equity firm Accel-KKR completed a carveout acquisition on undisclosed terms, returning it to standalone independent ownership while American Express continued as a partner.
The product set is broader than most competitors in this lane and spans four connected areas: fraud prevention and decisioning built on the historic Interceptas platform, chargeback management, account protection through Accertify Digital Identity, an application programming interface product launched in 2020 covering account opening and account takeover, and a payment gateway, which takes the company into payments infrastructure rather than sitting beside it. Device intelligence is delivered through InAuth technology.
The company describes its platform as resting on four pillars of artificial intelligence and machine learning, community insights drawn from pooled customer data, expertise, and customer held flexibility and control, with user behaviour analytics alongside device signals. Customer concentration is stated at 40 percent of the top 100 online retailers together with major global airlines, sports betting platforms, travel and hospitality operators and financial services enterprises. Delta Air Lines is named as a customer since 2010, with the airline's Revenue Protection Unit using the platform and the partnership publicly renewed. The company announced ISO 27001 certification in 2011 and published its information security management system scope at the time.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
Machine learning is named as the first of four platform pillars rather than as an attribute, and the surrounding components are all inference. The company describes an enterprise platform underpinned by advanced machine learning, device intelligence and user behaviour analytics, with community insights from pooled customer data feeding the models.
User behaviour analytics is inference by definition, device intelligence delivered through InAuth technology is identity resolution against an adversary changing observable attributes, and the decisioning architecture is described by third party assessment as elastic and capable of absorbing peak retail and travel booking volumes, which is a description of a scoring system rather than a queue of rules.
Strip the models and what remains is a consortium of pooled fraud data and a case management interface, which is where this product began as Interceptas and is not what is sold now. The community data would persist without the models; the decisions would not.
Customer held control is named as one of the four platform pillars, described as flexibility and control, and independent procurement assessment corroborates it by evaluating the platform on rule controls, machine learning tooling and evidence workflows as distinct capabilities the customer operates.
The product's origin supports the position, since the historic Interceptas platform was built around integrating every component of fraud prevention with case management and data handling for analysts rather than around an opaque verdict. Because no chargeback guarantee is offered, the merchant retains both the decision and the loss, so authority and accountability sit together. Two things are absent.
No specification of default behaviour is published, so a buyer cannot tell what the platform does before they configure it. And third party assessment flags that modules scale unevenly when only partially deployed and that peak season tuning requires additional capacity planning, which implies the operating point shifts under load in ways the vendor does not document.
No accuracy figure, precision or recall measure, false positive rate, validation report, model documentation or monitoring statement was located for any component. The four pillars framing describes the platform's architecture at a marketing level, naming machine learning, community data, expertise and customer control, without specifying what any model does or how well.
The most concrete performance information available comes from third party procurement assessment rather than the vendor, which rates scalability at 4.4 out of 5, credits an elastic decisioning architecture that absorbs peak shopping and booking volumes, and simultaneously flags that peak season tuning requires additional capacity planning and that modules scale unevenly when only partially deployed. Those are operational observations from buyers, and the fact that they are the best available evidence about how this system behaves under load is itself the finding.
One named customer with genuine depth and a specific market share claim, against no quantified outcomes at all. Delta Air Lines has been a customer since 2010, the airline's Revenue Protection Unit is named as the using business unit, and the partnership was publicly renewed, which is a sixteen year enterprise relationship that a buyer can take a reference on.
Customer concentration is stated precisely enough to be checkable in principle, at 40 percent of the top 100 online retailers, alongside major global airlines, sports betting platforms, travel and hospitality operators and financial services enterprises. The Accel-KKR carveout from American Express is an externally attested transaction, though terms were not disclosed. What is absent is any outcome number.
No fraud prevented, chargeback reduction, approval rate movement or false positive figure is published for any customer, no transaction volume or customer count is stated, and the company is privately held with no financial disclosure, so the only quantities available describe who buys it rather than what it does.
The consortium is explicit and ungoverned. Community insights is named as one of four platform pillars and the company states its machine learning is backed by extensive community data, which means each customer's fraud outcomes train models that decide for every other customer, including their direct competitors among the top 100 online retailers the company counts as clients. That is the pooled data model stated as a selling point, and nothing published governs it.
No statement describes whether a customer can decline to contribute, how one retailer's transaction and outcome data is separated from a competitor's view, what a retained record contains, how long contributions persist, or what happens to a departing customer's contributed history. The question has extra force here because the customer base is concentrated among direct competitors in the same categories, so the pooling is not across unrelated industries but within them.
Nothing was located across repeated retrieval. No data processing addendum, subprocessor list, retention schedule, named supervisory authority, transfer mechanism or named privacy regime appears anywhere on the vendor's surface.
That is a thin position for a platform that operates a payment gateway, holds device identifiers through InAuth technology, runs user behaviour analytics on consumers, and pools customer data into a shared community dataset, which taken together is a wide collection of personal and transactional data across four distinct processing purposes.
The ownership change compounds the gap rather than closing it: a platform that spent fourteen years inside a regulated card issuer, where privacy obligations flowed from the parent, has since 2024 been a standalone private equity held company, and nothing published describes what data protection apparatus travelled with it or what governs the community dataset now.
One real certification with a genuinely published scope, and it is fifteen years old. In 2011 the company announced ISO 27001 certification and, unusually, published the information security management system scope alongside it, covering the provision and management of processes, activities and dependencies associated with operating the information systems and infrastructure supporting its products and services including high availability across all customer environments.
A published scope statement is the artifact whose absence has capped this axis for most vendors in this lane, and this record has one. It is also from 2011, and ISO certification runs on three year cycles with annual surveillance audits, so a certificate announced fifteen years ago says nothing about current status unless maintained, and no recertification, current certificate, service organisation control report, payment card attestation or trust centre was located.
Pre emptive negative finding: recirculating the 2011 announcement will not move this grade. A current certificate with its date and registrar, or any attestation covering the payment gateway, is what would.
Privately held under private equity ownership, holding no licence, with no supervisory relationship, named regulator counterparty or regulatory approval located. The payment gateway product would ordinarily bring the company within payment card industry scope as a service provider, and third party procurement guidance treats payment card compliance as a standard evidence request for this vendor, but no attestation, compliance level or assessor was located and the company makes no such claim in its own material.
Compliance assistance is described as something the platform helps customers achieve rather than a status the company holds. No privacy or payments regime is named. Nothing here counts against a technology supplier not expected to hold a licence, and nothing lifts the record above the floor.
Nothing this axis asks for was located. No error rate, false positive rate, confidence measure or calibration statement is published for any component. No fairness testing, disparate impact analysis or coverage statement exists. Two exposures specific to this platform go unexamined. User behaviour analytics carries known performance variation by age, disability and device capability, since the signals are interaction patterns that differ systematically across those populations.
And the community data model means a customer inherits fraud associations formed at other merchants, so a consumer refused at one retailer may carry that outcome into decisions at competitors without any of the merchants involved knowing why. Nothing published describes how such an inherited association is reviewed or corrected, who approves a model change, or what validation a new signal passes before it affects live decisions.
No guarantee, indemnity, accuracy service level or falsifiable commitment was located. The company sells chargeback management, which recovers and contests disputes on the merchant's behalf, but that is a service for handling losses rather than a transfer of them, and the merchant retains liability for any transaction the platform approves. For the individual the position is worse than the lane norm because of the community data model.
A consumer refused at one merchant may carry that association into decisions at other merchants sharing the same consortium, so the consequence of an error propagates beyond the institution that made it, and nothing published describes notification, evidence disclosure, an appeal route, a correction mechanism, or how a corrected record reaches the other customers who already acted on it.
Two components of the chain are identified and the rest is not. Device intelligence is stated to be powered by InAuth technology, which names the specific capability behind one of the platform's core signal sets rather than presenting it as proprietary, and that is a real disclosure of a kind several competitors avoid. Community data is named as an input category, telling a buyer that pooled customer outcomes train the models even though no participant is identified. Beyond those, nothing.
No subprocessor list exists, no cloud infrastructure provider is named, no external data supplier, identity provider or enrichment service is identified, and no model or foundation model provider is stated for any component. The payment gateway would necessarily involve acquiring and processing relationships and none is disclosed. Naming the technology behind one signal set while leaving the payments chain entirely undescribed is an uneven disclosure.
The distinguishing integration is that the company operates part of the rail rather than connecting to it. Accertify sells a payment gateway alongside its fraud products, so a merchant can route authorisation and risk decisioning through the same supplier, which removes the reconciliation problem that separates fraud verdicts from payment outcomes at every competitor in this lane that only scores.
Around it, Digital Identity is delivered as an application programming interface, device intelligence ships through InAuth technology embedded in the customer's application, and an ecommerce application marketplace listing provides a packaged path for smaller merchants. The platform is also distributed through a major financial crime software marketplace, which reaches banking buyers through a channel rather than direct sales.
What is absent is an enumerated catalogue: no commerce platform connector list, no payment processor integrations beyond the company's own gateway, and no published developer documentation were located.
Hosted software, described by the company in its own historic material as hosted software solutions, with no private, single tenant or on premise option located. On residency nothing current is published: no cloud provider, region, data centre or country of processing is named, no region selection is described, and no transfer mechanism appears.
The only infrastructure statement available is fifteen years old, contained in the scope of a 2011 information security certification, which committed to high availability operation across all customer environments without stating where any of it runs.
For a company selling a payment gateway to major global airlines and international retailers, both of which face cross border data obligations on transaction and cardholder data, the absence of any published processing location is a material gap.
No rate is published on the vendor's own surface across two dedicated passes, and the one vendor controlled listing that carries a price field, an ecommerce application marketplace, states only that the application is free to install and that additional charges may apply.
Third party procurement analysis describes the commercial model with more specificity than the vendor does, reporting that pricing combines transaction fees, monthly fees and setup costs, with custom enterprise pricing on request.
That structure is worth recording precisely because of the third element: setup costs are an explicit component here, where several competitors in this lane publish that they charge none, so a buyer should expect an implementation fee rather than assume its absence. None of the three components carries a figure, no tier, band or entry point exists, and no free tier or trial was located.
Breadth comes from the product line reaching further along the payments chain than its competitors rather than from serving more industries. Alongside fraud decisioning, chargeback management and digital identity, the company sells a payment gateway, which puts it in front of payments and treasury buyers as well as fraud teams and makes it a supplier of infrastructure rather than only of risk signals.
Industry coverage is evidenced rather than listed: 40 percent of the top 100 online retailers, major global airlines with Delta named, sports betting platforms, travel and hospitality, and financial services enterprises, with the Digital Identity launch additionally naming utility, dining, loyalty and rewards account protection. Travel and airline depth is the distinguishing feature and no other vendor graded in this lane demonstrates it.
What holds this below the top grade is that no geographic footprint, country count or regional presence is stated anywhere, and the evidenced customer base is concentrated in North American enterprise retail and travel.
What Changed
Material product, regulatory, evidence and commercial changes at Accertify, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Accertify achieved HIPAA compliance and extended its fraud prevention platform into healthcare. The certification covers the platform's handling of protected health information.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Third party procurement analysis describes a combination of transaction fees, monthly fees and setup costs with custom enterprise pricing on request; no figure attaches to any component.
|
Custom enterprise pricing, with third party analysis describing a three part structure of transaction fees, monthly fees and setup costs. Nothing is published by the vendor, so neither the metering unit nor the relationship between the components is confirmed. The structure is plausible given the product range, since the company sells fraud decisioning, chargeback management, digital identity and a payment gateway as separable lines, and a gateway is conventionally priced per transaction while a decisioning platform is conventionally priced on a subscription with volume tiers, so a combined model would follow from selling both. Because no chargeback guarantee is offered and the merchant retains the loss, the fee is a software and processing price rather than an underwriting output, which means a published rate card would be possible here in a way it is not for a guarantee seller. None exists. | No data processing addendum, subprocessor list, retention schedule or named privacy regime was located. The gap is worth stating in the context of the ownership change: this platform operated inside American Express from 2010 until May 2024, when Accel-KKR completed a carveout, and nothing published describes what data protection apparatus travelled with the business or what now governs the pooled community dataset that trains its models. On assurance the only artifact is an ISO 27001 certification announced in 2011 with a published scope statement, and no current certificate, recertification, service organisation control report or payment card attestation was located despite the company operating a payment gateway. | Chargeable, and this is the unusual part. Third party procurement analysis identifies setup costs as an explicit component of the commercial model alongside transaction and monthly fees, which contrasts with several competitors in this lane that publish an express no setup fee commitment. No figure, band or basis is stated for it. The implementation itself would reasonably carry cost, since the platform spans fraud decisioning, chargeback management, digital identity and a payment gateway, and a customer adopting the gateway is changing payment infrastructure rather than adding a screening call. Third party assessment additionally flags that modules scale unevenly when only partially deployed and that peak season tuning requires capacity planning, both of which imply configuration effort beyond initial integration. | Third Party Estimated |
Two dedicated passes. No rate appears on the vendor's own surface, and the one vendor controlled listing carrying a price field, an ecommerce application marketplace, states only that the application is free to install with additional charges possible. Third party procurement analysis is more specific about the structure than the vendor is, describing a model combining transaction fees, monthly fees and setup costs with custom enterprise pricing on request.
The third component is the one worth flagging to a buyer: setup costs are an explicit part of this model, where several direct competitors publish that they charge none, so an implementation fee should be assumed rather than assumed away.
Pre emptive negative finding: this vendor has been enterprise sales led for close to two decades and spent fourteen of those years inside a card issuer, so the absence of published pricing is structural rather than an oversight, and a rate surfacing on a reseller or marketplace listing should be treated as one negotiated deal rather than as a list price.