Fraud Detection & Transaction Risk
F

Fingerprint

Fingerprint sells device identification as a developer primitive rather than as a fraud decision. Its commercial product, Fingerprint Identification, combines browser and mobile signals with server augmented matching to produce a visitor identifier the company states is 99.5 percent accurate and stable across months rather than days, delivered through an API with software development kits for web, Android, iOS, React Native and Flutter. Smart Signals sit alongside the identifier, covering bot detection, virtual private network detection and internet protocol geolocation.

The company also publishes FingerprintJS, a source available browser library carrying more than 28,000 stars on its public repository, which the company itself notes is materially less accurate than the paid server augmented product. Because the identifier is a primitive, it is sold horizontally, and only the financial lines are graded in this record: payment fraud covering fraudulent orders, unauthorised transactions, card testing and chargeback evidence, promotion and multi accounting abuse, loan application validation against previously rejected submissions, and account takeover.

Personalisation, paywall enforcement, content metering, persistent shopping carts and analytics are sold from the same identifier and are excluded here. Commercially it is the most open vendor in this lane, publishing a three tier rate card with a free plan, a 99 dollar monthly plan including 20,000 web and iOS requests plus 500,000 Android requests, overage at 4 dollars per thousand, a 14 day unlimited trial, and a precise definition of what constitutes a billable request. Assurance runs through a trust centre carrying a SOC 2 Type 2 report, ISO 27001 certification with its Statement of Applicability, a penetration test report and a full policy set. Named customers include Neiman Marcus, Uni Cards and Zebeede.

Last VerifiedAugust 24, 2026
Compare Fingerprint with other vendors
Founded
Headquarters
Website
fingerprint.com
Categories
fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 11 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The company answers the removal test against itself, which is unusual and decisive. Fingerprint publishes two products: a source available browser library that hashes public browser attributes, and a commercial service that adds server augmented matching.

It states plainly that the free browser only library reaches a materially lower identification rate than the paid product, so the accuracy gap between hashing observable attributes and inferring identity is the company's own stated value proposition. That gap is the model.

The commercial service is described as processing and analysing large volumes server side to find patterns and recurring activity, combining more than 100 signals into an identifier the company puts at 99.5 percent accuracy with stability across months rather than days, surviving cookie clearance, incognito browsing and virtual private networks. Persistence of that kind against a user actively changing their observable attributes cannot come from lookup. Strip the models and what remains is the free library, which the vendor itself positions as the weaker thing.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The vendor decides nothing, and the design intent is stated rather than implied. Fingerprint returns a visitor identifier and a set of discrete Smart Signals covering bot detection, virtual private network detection and geolocation, and the customer composes those into whatever logic they choose.

The company positions this explicitly against products that sit on top of applications and are managed by business teams, describing itself instead as built for developers to construct custom solutions, so the decision layer is the customer's own code by construction.

Discrete signals rather than a composite score is a meaningful difference from the scoring vendors in this lane, because a customer can see which specific condition fired rather than inferring it from a number, and can weight each independently. Documented caching strategies let a customer control how often identification actually runs.

What is absent is any specification of the primitive itself: nothing published states the confidence attaching to an identifier, when the service considers a match uncertain, or how a customer should treat a borderline identification, so the composition is entirely the customer's problem to reason about.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

A specific published accuracy claim on the core capability, and an unusual amount of structural transparency around it. The company states 99.5 percent identification accuracy with stability lasting months, and separately publishes the honest comparison that makes the number meaningful: its free browser only library achieves materially lower accuracy than the paid server augmented product, which tells a reviewer where the performance actually comes from rather than attributing it to the whole system.

Part of the signal collection layer is literally readable, since the browser library is published as source under a business source licence with more than 28,000 stars, so an engineer can inspect what is gathered client side before adopting anything. The billing documentation defines precisely what constitutes a successful identification event, which doubles as a definition of when the model is considered to have produced a result.

Customers hold the identifiers and can validate them against their own realised outcomes. What is missing is the documentation: no methodology, population or measurement period accompanies the 99.5 percent figure, and no false positive rate, validation report or monitoring statement was located.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Named customers with attributed quotes and some quantified results, weighted toward smaller and mid sized technology buyers. Uni Cards and Zebeede both appear with named product managers on the record, a Canadian fintech reports roughly 70 percent of logins no longer requiring multi factor challenge, and one customer describes implementing during a live card testing attack and blocking fraudulent traffic within six hours of deployment.

Neiman Marcus reports recognising 23 percent of total site visits against a prior baseline of 8 to 10 percent, though that is a personalisation outcome and sits outside the scope of this record. Independent signal is genuine: more than 28,000 stars on the public repository for the open source library, and a 4.7 out of 5 average across several hundred reviews on the major software marketplaces. What is absent is scale and standing.

No request volume, customer count, or fraud prevented figure is published anywhere, the company is privately held with no financial disclosure, and no analyst house evaluation or market position was located.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

The company is honest about what the technology does, which is the first thing this axis should reward for a product designed to defeat the controls users employ to avoid being tracked. Published material states plainly that the identifier persists across cookie clearance, incognito browsing and virtual private network use, and the privacy guidance separates the uses that require consent from those that do not rather than blurring them.

Technical controls support the position: Zero Trust mode on the API makes it difficult to submit identification requests impersonating another visitor, cached lookups never reach the backend so the data is not transmitted at all, and a customer configurable request filter lets a customer restrict which of their own properties may call the service. Data deletion on controller request is documented.

The unanswered question is the shared one across this lane, and here it is sharper than usual: nothing published states whether a device identified at one customer's property informs identification at another's, which for a persistent cross site identifier is the difference between a per customer tool and a global tracking graph. The company does not say, and the architecture would permit either.

Regulatory and Compliance
GLBA and Data Privacy Posture
AA on GLBA and Data Privacy PostureThe privacy architecture is published in the specifics: data handling, retention, and a subprocessor list, which is rare in this index and valuable.
Vendor Published

The strongest privacy position located in this lane, which matters because device fingerprinting is the most privacy contested technology in it. Two separate data processing addenda are published, one for the General Data Protection Regulation and one for the California Consumer Privacy Act, with the roles allocated explicitly under each: the customer is controller and Fingerprint is processor under the European regime, the customer is business and Fingerprint is service provider under the Californian one.

A documented data deletion process obliges the company to delete personal information on the controller's request, and retention is addressed in published support material. The distinguishing artifact is a public guidance document that separates legal bases by use case, stating that fraud prevention and security generally rest on legitimate interest and therefore do not require explicit consent, while attribution and personalisation likely do.

That is a vendor telling customers when they need consent rather than leaving them to assume they do not, on precisely the question that determines whether their deployment is lawful. The company also documents that its open source library is stateless and stores nothing, distinguishing it from the commercial service. No supervisory authority is named and the subprocessor list sits behind the trust centre rather than in public.

Security Certifications and Trust Center
AA on Security Certifications and Trust CenterCertifications named with their type and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

This record answers the question every other vendor in this lane has left open. A dedicated trust centre publishes SOC 2 Type 2 and ISO 27001 certification together with the ISO 27001 Statement of Applicability, which is the scope document defining exactly which controls the certificate covers and which are excluded, and which is precisely the artifact whose absence has capped this axis for peer after peer.

Alongside it sit a penetration test report, a network diagram, a Cloud Security Alliance consensus assessment self assessment, and nine named governance documents covering acceptable use, access control, business continuity and disaster recovery, data classification, incident response, information security, network security, risk assessment and vulnerability management. A recovery time objective of four hours is published.

The certification history is documented in sequence, from SOC 2 Type I in 2021 to Type II in 2022 to ISO 27001 thereafter, with the company stating that maintaining the latter requires annual audits by an independent auditor and that the certificate itself can be viewed. Annual penetration and vulnerability testing is stated, transport is encrypted, and the API supports a Zero Trust mode against impersonation.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

Privately held, holding no financial licence, with no supervisory relationship, named regulator counterparty or regulatory approval located. Engagement with the General Data Protection Regulation and the California Consumer Privacy Act is substantive and is credited on the privacy axis where its evidence sits.

A third party software directory characterises the product as offering compliance support for payment card industry and second Payment Services Directive requirements, but no such claim was located in the company's own material and neither a payment card industry attestation nor any strong customer authentication compliance statement was found, so neither is credited. No named regulator appears as a customer or partner and no industry body membership was located. None of this counts against a technology supplier not expected to hold a licence, and none of it lifts the record above the floor.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

One headline accuracy figure and no governance behind it. The company publishes 99.5 percent identification accuracy with stability stated across months rather than days, which is a specific claim on the core capability, and it is credited on the model risk axis. This axis asks for something else and finds it absent. No false positive rate, confidence measure or calibration statement accompanies the accuracy figure.

No fairness testing, disparate impact analysis or coverage breakdown by device type, operating system version or region exists. That gap has real consequences for a device identifier: shared, refurbished, rooted and older hardware are systematically harder to distinguish, which correlates with lower income users, and a device wrongly matched to another visitor inherits that visitor's history including any fraud associated with it.

Nothing published describes how such a collision is detected, how often it happens, or how it is corrected. Nothing states who approves a model change or what validation a new signal passes before it affects identification.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity, accuracy service level or falsifiable commitment attaching to identification quality was located, and structurally there would be little to guarantee, since this vendor supplies an identifier and the customer decides what to do with it. The 99.5 percent accuracy figure is a marketing claim rather than a contractual term.

What does exist, and is worth recording precisely because it is a real financial commitment where none was required, is billing protection: the company undertakes not to bill for identification requests generated during a denial of service attack, filters abusive bot traffic through a web application firewall before billing, provides a customer configurable request filter, and states it will waive charges if a malicious surge penetrates those layers.

That protects the customer from paying for an attack on themselves. It is not recourse for a wrong identification. For the individual the position is the standard one for this lane with one addition: someone whose device is matched to another visitor's history has no visibility and no appeal at the vendor, though the published deletion process gives them a route through the customer acting as controller.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

Part of the chain is published as source code, which is the strongest form this disclosure can take. The browser library that performs client side signal collection is available under a business source licence with more than 28,000 stars on its public repository, so an engineer can read exactly what is gathered from a visitor's browser before deploying anything, and the company notes that competitors build on that same open source component.

Infrastructure is named, with Amazon Web Services identified as the data centre operator. Edge and delivery partners are named at Cloudflare, Akamai, Fastly, CloudFront and Azure, and data platform partners at Segment and Google Tag Manager, so the path a request travels can be traced. What is not disclosed is the part that creates the value.

Server augmented matching is where the company states its accuracy advantage over the open library comes from, and nothing describes what data, models or external sources feed it. No third party data supplier or enrichment service is named, and the subprocessor list sits behind the trust centre rather than in public.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

An enumerated and independently verifiable catalogue across three distinct layers, which is what the top grade on this axis requires. Client software development kits ship for web, Android, iOS, React Native and Flutter, distributed through the package registries developers already use including npm, yarn, pnpm and Kotlin tooling.

Edge and content delivery integrations are named at Cloudflare, Akamai, Fastly in both its Compute and VCL forms, Amazon CloudFront and Azure, which lets identification traffic be served through the customer's own first party origin rather than a third party domain, a capability that materially changes reliability and is rare. Data platform integrations are named at Segment and Google Tag Manager. A server API supports Zero Trust mode against request forgery.

Public documentation is served at two developer domains covering integration, billing and caching strategy. A named partner integration exists with Oscilar, itself indexed here. What is absent is any connector into the business systems a fraud team runs, since this is a primitive consumed by engineers rather than a platform operated by analysts.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Hosted software consumed through client software development kits and a server API. The infrastructure operator is named, with the company stating that data sits in a series of global Amazon Web Services data centres with enterprise grade physical and network security, which is more than several competitors in this lane disclose.

Beyond that naming the residency position is absent: no region, availability zone or country of processing is stated, no region selection is offered or described for the commercial product, and no transfer mechanism or standard contractual clause provision was located despite the company publishing data processing addenda under both European and Californian regimes and serving customers across four continents.

No private, single tenant or on premise deployment of the commercial service exists. The source available browser library can be self hosted, but the company is explicit that it is materially less accurate than the hosted product, so self hosting is a downgrade rather than a deployment option.

Commercial
Commercial Transparency
AA on Commercial TransparencyPublished per unit rates a buyer can price against before any conversation.
Vendor Published

The most complete commercial disclosure located anywhere in the ecommerce fraud lane, and the only published rate card among them. Three tiers are named with figures: a free plan, Pro Plus at 99 dollars a month including 20,000 web and iOS identification requests plus 500,000 Android requests, and Enterprise by contract, with self serve tiers scaling to a million requests a month and a stated threshold of nine million annual requests above which a custom contract is required.

Overage is published at 4 dollars per thousand requests. A 14 day trial with unlimited calls is offered, and the company publishes guidance on estimating volume before committing. What lifts this beyond a rate card is that the billing unit is defined precisely rather than left to interpretation: a request is billable only when it successfully identifies a device and returns an event identifier, requests without one are not billed, and requests served from the application cache are not billed at all.

Three further protections are published against overbilling, covering distributed denial of service traffic, a web application firewall filtering abusive bot requests, and a customer configurable request filter, with a stated willingness to waive charges if a malicious surge penetrates them. Any billing model change carries 30 days notice.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Sold horizontally as a primitive, with real depth in the financial segments that fall inside this record's scope. Dedicated material addresses fintech, banking, buy now pay later, cryptocurrency and payment fraud, alongside ecommerce, gaming and gambling, travel and technology platforms that sit outside it.

Company size coverage is genuinely wide because the pricing structure makes it so, running from a free tier a single developer can adopt through to enterprise contracts above nine million annual requests, which is a broader band than any competitor in this lane serves. Geographic reach is stated across North America, Europe, Asia Pacific and Latin America. Two things hold this below the top grade.

The buyer is a developer rather than a fraud function, so the product is adopted per use case rather than sold into an institution, and there is no evidence of sales into banking operations, insurance or capital markets. And a substantial share of the customer base uses the identifier for purposes excluded from this record entirely.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Free plan at zero cost, Pro Plus at 99 dollars per month including 20,000 web and iOS identification requests plus 500,000 Android requests, overage at 4 dollars per 1,000 requests, Enterprise by contract. A 14 day trial with unlimited calls is offered.
$0 baseline
Per identification API request, billed monthly, across three published tiers. Free covers a small monthly allowance for evaluation. Pro Plus at 99 dollars a month includes 20,000 web and iOS requests together with 500,000 Android requests, an asymmetry the company states explicitly rather than burying, with overage at 4 dollars per thousand. Self serve tiers scale by monthly request volume to approximately one million a month, above which an enterprise contract is required, and custom pricing applies from around nine million annual requests. The billable unit is defined tightly: only a request that successfully identifies a device and returns an event identifier is charged, unsuccessful requests are free, and cache served lookups that never reach the backend are not billed, so a customer's caching strategy directly determines their bill. Smart Signals are included at Pro Plus and above rather than metered separately. The company commits to 30 days notice before any change to the billing model. Two separate data processing addenda are published, one under the General Data Protection Regulation and one under the California Consumer Privacy Act, with roles allocated explicitly under each: customer as controller and Fingerprint as processor in the European case, customer as business and Fingerprint as service provider in the Californian one. A data deletion obligation on controller request is documented, and retention is addressed in published support material. Assurance sits in a trust centre carrying the SOC 2 Type 2 report, the ISO 27001 certificate and its Statement of Applicability, a penetration test report, a network diagram, a Cloud Security Alliance self assessment and nine governance policy documents. No supervisory authority is named and the subprocessor list sits behind the trust centre access request rather than in public. None published and none apparent. Integration is self serve through package registries, with client software development kits for web, Android, iOS, React Native and Flutter installed by a single command, and no setup, onboarding or professional services fee appears anywhere. A developer can reach production without contacting the company at all, and one published customer account describes implementing during a live card testing attack and blocking traffic within six hours. Edge integrations at Cloudflare, Akamai, Fastly, CloudFront and Azure are available for first party serving and carry no stated additional charge from this vendor, though the customer's own edge provider costs apply. Smart Signals covering bot detection, virtual private network detection and geolocation are gated to the paid tiers rather than sold as separate add ons. Vendor Published

Two dedicated passes, both confirming on the vendor's own surface rather than through third parties. This is the only published rate card in the ecommerce fraud lane and the most complete commercial disclosure located anywhere in this session.

The distinguishing feature is not the number but the definition around it: a request is billable only when it successfully identifies a device and returns an event identifier, requests that fail to produce one are not billed, and requests served from the application cache never reach the backend and are not billed at all.

That means a buyer can calculate cost from their own architecture rather than from a sales conversation, and the company publishes guidance on estimating volume from page views on signup, login and pre payment pages. Three overbilling protections are published: denial of service traffic is not billed, a web application firewall filters abusive bot requests before billing, and a customer configurable filter can reject requests from unknown sources at the header level, with a stated willingness to waive charges if a surge penetrates all three.

Pre emptive negative finding: at least one unrelated company at a similar domain sells a people search product under the same name with a completely different rate card, so any quoted Fingerprint price must be checked against the device identification product before use.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746