Fraud Detection & Transaction Risk
D

Darwinium

Darwinium moves the fraud decision out of a vendor's cloud and into the customer's own network perimeter. Rather than shipping a tag or a software development kit that calls an interface at chosen moments, it runs as an edge worker inside the content delivery network the business already operates, naming Cloudflare and Amazon CloudFront among them. Everything crossing that perimeter is therefore visible in one place, from the first page a visitor lands on through account creation, login, detail changes, listings, checkout and payment, and the platform can act on the journey as it happens rather than scoring a moment after the fact. The company puts deployment at as little as 15 minutes and native mobile software development kits were added in 2026 to extend the same coverage inside applications.

The data architecture is the second half of the design and is unusually strong. Customer data is encrypted at the edge using hybrid public key encryption where Darwinium holds only the organisation's public key, so by its own account it can encrypt but cannot decrypt without the customer's involvement. Analysed data can be stored encrypted in the organisation's own storage under its own keys. The stated consequence is that the vendor never sees customer data in the clear and does not become a target worth attacking.

What the models produce is identity from behaviour. The company calls these digital signatures, recognising a returning user even when device, browser or behavioural elements change, and describes itself as an intent engine rather than an identity one, consuming third party signals a customer already runs rather than displacing them. Financial lines are named and separately developed: retail banking and fintech as industries, and account takeover, payment fraud and scam detection as use cases, the last combining transaction intelligence, behavioural biometrics and what the vendor calls victim propensity modelling to alter a suspected scam journey in real time. Agent intent detection extends the same question to automated traffic.

Founded 2021 in San Francisco by Alisdair Faulkner and colleagues from ThreatMetrix, with offices in London and Sydney and 26 million dollars raised through a Series A led by U.S. Venture Partners.

Last VerifiedAugust 25, 2026
Compare Darwinium with other vendors
Founded
2021
Headquarters
San Francisco, California, United States
Categories
fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The architecture is plumbing and the product is the models, and the two should not be confused. Running inside a content delivery network is a deployment choice that determines what data can be seen; it decides nothing. Every determination the platform actually sells is learned.

Recognising a returning user when device, browser and behavioural elements have all changed cannot be done by matching, which is the failure the company describes in the incumbent approach it displaced at one customer, and the vendor's term for what it produces, a digital signature that turns behaviour into identity, is a description of a model output. Distinguishing a human from an automated agent by intent rather than by signature is a classifier.

Victim propensity modelling infers a state of mind. Scam detection is explicitly described as combining machine learning with transaction intelligence, behavioural biometrics and propensity modelling. The company positions itself as built in the era of artificial intelligence to fight artificial intelligence, and consumes third party signals as inputs rather than as substitutes. Strip the models and what remains is a very good data collection pipeline with nothing to say.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

This platform acts on a live customer session before any person is involved, and that is the point of it rather than an incidental capability. The vendor's language is consistent and unambiguous: decision and act on trust and risk in real time, journey time orchestration, dynamically tailoring customer journeys according to risk, and in the online banking scam brief, altering potential scam journeys in real time.

Sitting at the perimeter, the platform can insert a challenge, change what a customer sees, or stop an action mid session, and it does so at machine speed on traffic that has not yet reached the business's own systems. The customer writes the journey definitions and role based permissions govern who may change them, so the policy is the institution's, and that is a real control. What is absent is any published boundary on the policy.

Nothing states what the platform will not do autonomously, what a customer is told when their journey is altered, whether a wrongly interrupted session can be appealed, or what review a bank is expected to keep over decisions taken at the edge on its behalf.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Three headline figures, none of them anchored. The platform is credited with 50 percent less fraud, 40 percent greater operational efficiency and 30 to 40 percent greater visibility of user transactions, and not one carries a customer name, a sample, an observation period, a method or a definition of the baseline being improved on. The visibility figure is the weakest of the three because its comparator is unnamed siloed solutions, which is a category rather than a measurement.

Absent across two passes: accuracy, false positive rate, false negative rate, validation methodology, drift or retraining disclosure, and any model documentation of the kind a regulated buyer's risk function would require for a model influencing customer treatment.

The published work on adversarial artificial intelligence and red teaming is adjacent to this axis rather than on it, since it concerns attacks against the customer's environment rather than validation of the vendor's own models. The encryption architecture creates one genuine complication worth naming: if the vendor cannot decrypt customer data, the mechanics of how models are trained, tuned and validated across customers become a question the public record does not answer.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

The weakest part of an otherwise distinctive record, and the gap is customers rather than technology. One financial customer is named, a Brazilian fintech in business banking, with a published account of why it moved: poor persistency in its previous device fingerprinting drove excessive one time passcode challenges, and competing solutions had been ruled out on the cost of covering multiple points in the journey. That case study is specific and useful. Everything around it is not.

Other published case studies are anonymised by sector, and the headline outcome figures, 50 percent less fraud, 40 percent greater operational efficiency, and 30 to 40 percent greater visibility of user transactions, carry no customer attribution, no method, no sample and no definition of the baseline they improve on, with the visibility figure measured against unnamed siloed solutions.

Analyst recognition exists but is thin and stale, consisting of representative vendor listings in two 2022 market guides, which is inclusion rather than placement. No customer count, transaction volume or protected user figure is published, and total funding through Series A stands at 26 million dollars.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

The vulnerability disclosure policy is the best written located in this index and is worth describing precisely, because its virtue is candour rather than completeness. It states plainly that no bug bounty operates and no monetary reward is offered, which sets a researcher's expectation honestly instead of implying one.

It specifies what a useful report contains, commits to an initial reply on receipt and periodic updates through remediation, and then does the rare thing: it publishes a list of issues already assessed and accepted, covering transport layer configuration, security headers and mail and certificate related domain records, so a researcher knows in advance what will not be treated as a finding. Publishing your accepted risks is a form of disclosure almost nobody offers.

Alongside it, a dedicated page on adversarial artificial intelligence covering red teaming indicates the practice exists. The encryption design is itself a stewardship control, since data the vendor cannot decrypt cannot be misused by it. Absent across two passes: model card, evaluation methodology, incident history and any acceptable use boundary.

Regulatory and Compliance
GLBA and Data Privacy Posture
AA on GLBA and Data Privacy PostureThe privacy architecture is published in the specifics: data handling, retention, and a subprocessor list, which is rare in this index and valuable.
Vendor Published

The strongest privacy position in this index, because it is cryptographic rather than promissory. Most vendors here promise not to misuse customer data. This one states it cannot read it: user data is encrypted at the edge under hybrid public key encryption in which Darwinium's tools and automated processes hold only the organisation's public key, so by the vendor's own account it can encrypt but not decrypt without the customer's involvement, and analysed data can be stored encrypted in the organisation's own storage under its own keys.

A promise requires trust and can be broken silently; a design in which the vendor lacks the private key can be verified and cannot. Around it sit the ordinary artefacts done properly: a published privacy policy and terms and conditions, explicit positioning against Californian and European privacy law, and a plain statement that personal information is not rented, sold or traded. One tension belongs on the record.

The security page states flatly that customer data is not shared outside an organisation or across borders, while the company's own funding announcement describes a fully anonymised version of that data processed and leveraged globally as shared intelligence. Those reconcile only if the page's stronger claim is read as covering identifiable data.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

A trust centre on its own subdomain and a security page with real content rather than adjectives, which together put this above most of the segment. The security page describes controls specifically enough to be checked: hybrid public key encryption with the vendor holding only the public key, storage in the customer's own object storage, single sign on through named identity providers, and role based permissions enumerated by what they actually gate, namely whether a user may view event data, update journey definitions or manage deployments.

Internal threat modelling, routine internal and external assessment and secure development practice are stated. Terms and conditions are published. Deductions are about credentials rather than controls. The only certification signal is a professional institute mark in the site footer, with no framework named in text on the security page, no type or observation period stated, no report obtainable without passing through the trust centre, and no information security management certification located across two passes. A minor drafting error is worth noting for a reader checking the cryptography: the page renders the encryption standard's initials transposed.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

An unregulated software supplier that claims nothing it does not hold, with regulatory engagement narrower than its market. Privacy law is addressed directly and specifically, with the architecture positioned against Californian and European data protection requirements rather than described as generally compliant, and that engagement is substantive because the design actually answers those requirements rather than gesturing at them. Beyond privacy the record is quiet.

Across two passes nothing published addresses the European artificial intelligence regulation, despite the platform running behavioural and intent classification and a propensity model on consumers inside Europe. Nothing addresses the European operational resilience regime, despite a London office and a stated retail banking line, which would make the company an information technology supplier inside its banking customers' regulatory perimeter.

Nothing addresses European strong customer authentication, despite selling account takeover and payment fraud controls into retail banking where step up decisions interact directly with that regime. No supervisory contact or examination outcome is evidenced.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

One capability here raises a governance question sharper than anything else in this segment, and it is undisclosed. The scam material states that the platform applies victim propensity modelling, meaning it scores how likely a given customer is to be deceived. That is not a model of a transaction or a device; it is an inference about a person's susceptibility to manipulation, and susceptibility correlates with age, cognitive decline, isolation, grief, financial inexperience and disability.

The use is defensible and probably protective, which is precisely why it should be governed and visible rather than mentioned in passing in a solution brief. Nothing published describes what features enter that model, whether age or proxies for impairment are among them, how it performs across groups, how long a propensity label persists, or what a customer scored as highly susceptible experiences differently from one who is not.

The same silence covers behavioural identification and human versus agent intent classification. Across two passes no bias testing, fairness statement, model card, governance page or artificial intelligence regulation position was located.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Published contractual documents and one concrete remedy, neither of which reaches the risk that matters. Terms and conditions are published on the site, and subscription through the cloud marketplace requires acceptance of an end user licence agreement, so a buyer can read the governing terms before committing rather than after.

The remedy is unusually specific for this segment: refund requests are accepted within 30 days of a charge, submitted by email with an account identifier and order details, processed as a marketplace credit, with a stated five business day response target. Dated, actionable and public. What it covers is a subscription charge.

What it does not touch is the consequence of a wrong decision, and the consequences available here are unusually direct because the platform acts on live sessions at the perimeter: a legitimate customer whose journey is altered, whose payment is interrupted, or who is challenged repeatedly because a behavioural signature drifted. Across two passes no warranty, indemnity, liability cap or service level with credits was located, and nothing describes what the business or the affected customer is owed.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The infrastructure supply chain is named unusually well and the model supply chain not at all, and the split is stark because the same company did one thoroughly. Named on the public record: the content delivery networks the platform runs inside, the object storage the encrypted data lands in, the identity providers supported for single sign on, and the cloud marketplace it is sold through.

The architecture also discloses a dependency most vendors would hide, since running inside a customer's delivery network makes that provider a load bearing part of the product and the vendor says so plainly rather than describing itself as infrastructure agnostic. Third party enrichment services are described by function, including the ability to consume signals from tools the customer already runs.

Against that, no model provider, family, version or technique is named anywhere for behavioural identification, agent intent detection or victim propensity modelling. For a company whose positioning rests on being built in the era of artificial intelligence to detect agentic fraud, whether any third party foundation model participates in that detection is not stated.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Integration is not a feature of this product, it is the product's central argument, and it is evidenced rather than asserted. Deployment runs as an edge worker inside the content delivery network the business already operates, with Cloudflare and Amazon CloudFront named, so no new vendor enters the traffic path and no additional point of failure is created between the business and its users. The chief executive makes that comparison against competitors explicitly.

One published case study records a customer installing a named delivery network specifically to adopt the platform, with the vendor's professional services team supporting it, and the company puts deployment at as little as 15 minutes. Public technical documentation sits on its own subdomain with a quick start guide reachable without registration. Native mobile software development kits shipped in 2026 extend the same coverage inside applications where an edge worker cannot reach.

Out of the box integrations enrich decisions with third party services, and the platform is designed to consume signals from tools a customer already runs, including competing behavioural vendors, rather than requiring their removal. A cloud marketplace listing supports procurement. One reviewer on an analyst peer platform flags interface documentation accessibility as an area for improvement.

Deployment Model and Data Residency
AA on Deployment Model and Data ResidencyOn premise or hybrid deployment is offered and documented, alongside where data rests.
Vendor Published

Residency here is a consequence of where the software runs rather than a commitment the buyer has to trust. The detection layer executes inside the customer's own content delivery network at their own perimeter, so traffic is never routed through vendor infrastructure, and collected data can be written encrypted into the organisation's own object storage under its own keys.

A buyer therefore chooses their delivery network, their storage region and their key custody, and the vendor's answer on residency is that it does not hold the data in the first place. That is a stronger position than a list of supported regions, because a region list is a promise about where a vendor keeps something and this is an architecture in which the vendor keeps nothing readable. The security page states that customer data is not shared outside the organisation or across borders.

Two qualifications sit below the grade rather than against it. The control plane, covering journey definitions, dashboards and analytics, is vendor operated software whose hosting and regions are not described anywhere. And the anonymised shared intelligence layer is described elsewhere as processed globally, which is a separate data flow from the encrypted customer data and is not addressed on the security page.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

A pricing page with no pricing on it, and one genuine commercial term published elsewhere. The vendor maintains a page at a pricing address that carries a platform description and no price, tier, unit or term, which is worse for a buyer than having no such page at all, because the address promises the answer and the content withholds it. Two passes across the site, the platform and solution pages, the case studies and the aggregator listings produced no figure.

What is published, and deserves credit because almost nothing in this segment offers it, sits on the cloud marketplace listing: a stated refund policy accepting requests within 30 days of charge, a named process requiring an account identifier and order details by email, and a five business day response target, alongside private offer support for negotiated pricing and a requirement to accept an end user licence agreement at subscription.

That is a concrete, dated, actionable commercial commitment. A published case study also refers to a professional services team supporting deployment, with no indication whether that is chargeable or included.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

Financial services is two of six published industry lines and the named evidence inside them is thin. Retail banking and fintech each have their own material, alongside ecommerce, marketplaces, gaming and gambling, and airlines, and the financial use cases are properly developed rather than repurposed, covering account takeover, payment fraud and scam detection with an authorised push payment brief written specifically for online banking.

That is genuine product work rather than a vertical page, which is why this clears membership. What it does not have is institutional depth. One financial customer is named anywhere, a Brazilian business banking fintech. No bank is named, no institutional count is published, and no claim is made about penetration at any tier of the banking market.

The company describes its buyers as large business to consumer organisations above a billion dollars in revenue, payment service providers, ecommerce businesses, banks and some fintechs, which is a target description rather than a coverage claim. Offices in three countries support the stated geography without evidencing it.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, tier, unit of billing or contract term appears on any vendor surface, including the page published at a pricing address
Not published on any vendor surface. Nothing indicates whether charging follows traffic volume, monitored journeys, transactions, protected users, endpoints or modules, and the platform is sold as a single integrated system with use cases combinable rather than as separately priced products, so a buyer cannot tell whether adopting one use case or five changes the commercial shape. A cloud marketplace listing provides an alternative procurement route with private offers available for custom quotes and an end user licence agreement required at subscription. The published entry path on the vendor's own site is a demonstration request. No tiered data protection terms are published, and the architecture largely removes the need for them. Data is encrypted at the edge under hybrid public key encryption with the vendor holding only the customer's public key, analysed data can be stored encrypted in the organisation's own object storage under its own keys, and the security page states that customer data is not shared outside an organisation or across borders. A privacy policy and terms and conditions are published, with an end user licence agreement required at marketplace subscription. No data processing agreement, subprocessor list or retention schedule was located without contact, and the anonymised shared intelligence layer described in company announcements is not addressed in the published privacy material. No implementation, onboarding or professional services fee is published, and the vendor markets deployment speed rather than pricing it, putting integration at as little as 15 minutes on the basis that the software installs as a worker into a content delivery network the business already runs rather than requiring changes to backend systems. A professional services team is referenced in a published case study as supporting a customer's deployment, including that customer's installation of a delivery network, with no statement of whether that support is chargeable or included. Public technical documentation with a quick start guide is reachable on its own subdomain without registration, so an engineering team can scope the work independently before any commercial contact. Native mobile software development kits are stated as available immediately to existing customers, which indicates they are not separately licensed, though nothing says so directly. Vendor Published

Two passes across the vendor's own site, its platform and solution pages, its case studies and news archive, the cloud marketplace listing and the software aggregator listings produced no price, unit or tier. One finding is worth recording plainly because it will affect any buyer who goes looking: the vendor maintains a page at a pricing address which contains a platform description and no pricing of any kind.

A page that promises the answer and withholds it is worse for a buyer than no page, because it consumes the search that would otherwise end quickly. Offsetting that, the marketplace listing carries genuine commercial substance that most vendors in this segment never publish anywhere: a dated refund window, a named request process, a response commitment and a private offer route.

Buyers should also note one cost the vendor does not carry and does not price: deployment requires a content delivery network, and at least one published customer installed one specifically in order to adopt the platform, so a business without an existing edge provider is taking on a second supplier relationship.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746