Callsign
Callsign recognises returning bank customers by how they behave rather than by what they know, combining behavioural biometrics, device intelligence and contextual analytics through an orchestration engine that decides what authentication a given interaction actually needs. It covers account login, payments, account creation and network access, against account takeover, social engineering scams, malware and bots, SIM swap and call diversion, and synthetic identity.
Its dynamic intervention capability detects social engineering in real time and sends the customer a contextual, personalised warning before they transfer money to a fraudster, and it fuses telecommunications network signals indicating a live call during a payment. The company publishes commissioned economic research on digital exclusion and frames security as enabling access rather than restricting it.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
The removal test leaves a conventional multi factor prompt, which is exactly the friction the product exists to remove. Behavioural biometrics infer identity from how a person types and swipes, device intelligence establishes what they are using, and contextual analytics decide in real time what assurance a given interaction needs, with an orchestration engine sequencing the result.
Detecting social engineering while it is happening, from patterns in behaviour rather than in the transaction, is model work with no rules equivalent, and the company's identity claim rests on recognition rather than on credentials.
The intervention design keeps the customer in the decision rather than removing them from it. On detecting social engineering in progress the system does not silently block the payment but delivers a contextually relevant, personalised warning to the person about to send the money, so the human retains the choice while being told what the system has seen. That is a materially different posture from a fraud engine that declines and explains nothing.
Authentication itself is automatic and deliberately invisible, with a customer quote confirming users notice nothing different. What is absent is any description of thresholds, of what happens when a customer proceeds despite a warning, or of escalation to a human at the bank.
Three figures are published and the most important is stated in the right form, that solutions detect 40 percent more fraud while maintaining 99 percent acceptance rates, which holds the customer experience metric fixed while moving the detection metric and is the correct way to demonstrate genuine improvement rather than a shifted threshold. A separate result records a 70 percent fraud detection rate where telecommunications scam signals are combined with the company's own intelligence.
The third invites scrutiny rather than confidence: a 99.999 percent precision claim for the behavioural recognition feature is an extraordinary figure for this modality, published without methodology, sample or definition, and a number that precise needs its working shown.
Customers are quoted but not named, described as a major United States bank and a tier one retail bank, with the second observing that most of its customers detect nothing different about the experience, which is the right compliment for an authentication product. A 35 million dollar round closed in 2024, the platform is listed and reviewed on a major analyst peer review service, and a telecommunications partnership supplies live network signals.
Published performance figures are unusually specific for this category. The gap is naming: no institution is identified, and for a vendor whose customers are tier one banks in two markets, that leaves the scale of deployment unverifiable.
No data boundary statement was located. Behavioural models improve with exposure to more users and more fraud, and the platform serves competing banks in the same markets while additionally fusing telecommunications network intelligence that spans all of them, so what is learned from one institution's customers is directly valuable to another. Nothing states whether behavioural profiles or fraud patterns are contained per customer, whether an institution can decline to contribute, or how network derived signals are separated between banks.
Privacy is asserted as a design property, with the technology described as delivering unparalleled privacy and security alongside minimal friction, and no mechanism, retention schedule, subprocessor list or data processing term was located to support it.
The payload deserves more than an assertion, because behavioural biometrics means continuously observing how an individual types, swipes and holds a device, which is biometric data about the person rather than about the transaction, and it is collected passively during ordinary use rather than at a moment the customer recognises as verification.
A security section exists on the company's site and no attestation, certification, trust centre content or enumerated framework was located in accessible material. Deployment at tier one banks in two markets means vendor security assessment has been passed repeatedly at demanding standards, and telecommunications integration adds a further layer of scrutiny, so the assurance exists privately while nothing is published for a prospective buyer to read.
A regulator and a specific regime are named rather than gestured at, with the company writing about banks preparing for the payment regulator's changes on scam reimbursement, which is the rule that shifted liability for authorised push payment fraud onto banks and created the market this product serves. That is the correct instrument for a scam prevention business and naming it demonstrates the product was built against a defined obligation.
Zero trust access is addressed as a distinct journey. What holds this below the top grade is that no statute, authentication standard or supervisory expectation is cited, and no jurisdictional coverage of those regimes is described.
This vendor commissions and publishes economic research on digital exclusion, which is not something fraud vendors ordinarily do. Work with an economics consultancy found that only around two thirds of the population have positive online experiences and that more than a third of the global population has difficulty accessing online services, and the company frames security as the thing that lets people get on with their digital lives rather than as a barrier, publishing an acceptance rate alongside its detection rate so that both sides of the trade off are visible.
Against that, behavioural biometrics is precisely the modality where performance varies with age, motor control, disability and device, so the people who type and swipe atypically are those most likely to be challenged, and no performance breakdown across those populations is published.
No commercial guarantee or indemnity was located, and one design choice does something no other fraud vendor in this index does: it speaks to the person at risk. When social engineering is detected the system delivers a personalised warning to the customer in the moment, explaining the danger before they send money, which converts a silent institutional risk decision into information the affected person can act on.
Everywhere else in this lane the output goes to the institution and the customer learns only that something was declined. What is missing is the other half, since nothing describes recourse for a customer wrongly challenged or blocked, or how a false positive is corrected.
The most consequential external dependency is disclosed by type, with telecommunications operator scam signals identified as an intelligence source combined with the company's own models, which tells a buyer that part of the detection capability originates outside the platform and depends on carrier relationships in each market. Behavioural and device models appear to be the company's own. What is not disclosed is any individual provider, no carrier is named, no model provider is identified for the analytics layer, and no subprocessor list or hosting arrangement was located.
An orchestration engine sits at the centre, controlling which authentication or intervention applies to a given journey, which is what allows the platform to coordinate several signal types rather than deliver one. Integration with existing systems is stated, a documentation portal and partner programme exist, and the most substantive external connection is with telecommunications operators, ingesting network derived scam signals that indicate a customer is on a live call while making a payment. That is intelligence a bank cannot obtain on its own. What is not published is any named banking system, so a buyer cannot establish what implementation involves.
No hosting provider, region selection, residency commitment or private deployment option was located. The question carries weight because behavioural biometric profiles are personal data of a category treated as sensitive in several markets served, and the company operates across the United Kingdom, the United States and Asia, with telecommunications signal fusion adding further jurisdictional complexity that nothing published addresses.
No rate is published and the charging basis is, through independent analyst documentation which records volume or usage based licensing determined by number of users, authentication transactions or service integrations. That tells a bank which of its own metrics will drive cost, which is the question that actually matters when authentication volume runs to millions of events, and it identifies three distinct pricing dimensions rather than one. Held at B because the disclosure reaches the reader through a third party rather than the company, and no indicative figure accompanies it.
Coverage is organised around customer journeys rather than product modules, spanning account login and access, online payments and transactions, account creation and registration, and zero trust network access, so the same intelligence serves onboarding, transacting and internal security.
Five distinct fraud vectors are addressed by name, covering account takeover, social engineering and scams, malware and bots, network level attacks through SIM swap and call diversion, and synthetic identity. Buyers are banks in the United States and United Kingdom with stated expansion into new sectors. The limit is that no institution type beyond banking is evidenced.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Callsign
The closest documented capability profiles to Callsign in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Callsign
A lighter documented profile than Callsign
Stronger documented coverage on Operational and Outcome Evidence and Institution and Segment Coverage
A lighter documented profile than Callsign
Documents AI Safety and Data Stewardship where Callsign does not
Stronger documented coverage on Operational and Outcome Evidence and Institution and Segment Coverage
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.