Fraudio
Fraudio is an Amsterdam company founded in 2019 by João Moura and Nathan Trousdell, both from the payments industry, selling fraud and financial crime detection to the payment chain rather than to merchants. Its buyers are payment service providers, merchant acquirers, card issuers, processors, card schemes, payment facilitators and large merchants operating their own gateway. Three products run on one platform: payment fraud detection, merchant initiated fraud detection for acquirers monitoring their own merchant portfolios, and money laundering detection.
The architecture is the defining choice and it is the opposite of the per customer approach taken elsewhere in this lane. Fraudio pools the transaction datasets of all its customers into a single centralised model it calls a brain, trained on billions of transactions, requiring no per customer configuration and learning continuously from every transaction that passes through any customer. The company describes this as a third generation approach, a deliberate break from rules based systems and from machine learning trained on an individual customer's own data, and holds patents or patent applications over it. Responses are stated at under 100 milliseconds.
Commercially it sells on a pay per use basis with monthly subscriptions and no commitment, and offers a free Proof of Results in which a prospect supplies historical transaction data and compares Fraudio's detection output against their incumbent before paying anything. The company reports around 31 staff, roughly 3.3 million dollars raised across three rounds including a Series A in June 2026, and backing associated with ING, Payvision and Viva Wallet.
Capability Axes
Capability grades
15 of 15 axes rated · 4 graded A or B
The removal test is trivial here because there is nothing else. Fraudio sells a single centralised model trained on the pooled transaction data of every customer, explicitly requiring no per customer configuration, no rules to author and no tuning, and returning a score in under 100 milliseconds.
The company positions this as a third generation approach and defines the generations it is leaving behind: rules based systems first, then machine learning trained on an individual customer's own data. There is no rules engine underneath, no analyst review layer, no case management product and no separate data asset that would survive the model's removal.
The claimed advantage is itself a modelling claim rather than a data one, since the argument is that a model seeing many institutions' transactions generalises better than one seeing a single institution's. Patents or applications are claimed over the centralised architecture. This is the purest model dependency in this lane.
The design deliberately removes the controls this axis measures, and that trade is the sales pitch rather than an oversight. Fraudio markets itself as plug and protect, requiring no costly configuration, and contrasts that with vendors demanding long implementation projects and rule authoring.
The consequence is that the customer has no rules to write, no thresholds described as configurable, no sandbox to test changes against, no case management or review queue, and no ability to tune the model, because the model is shared across all customers and tuning it for one would change it for everyone. What the customer receives is a real time score returned to their own system, and the decision about what to do with that score is theirs, which is where the oversight sits. The stated position against black box solutions implies explanation is available, but no mechanism is described anywhere: no reason codes, no feature attribution, no alert narrative.
Proof of Results is the substantive artifact and it addresses the hardest problem in buying a model: knowing whether it works on your data before you commit. A prospect supplies their own historical transactions, Fraudio produces detection output against them, and the prospect compares that output against their incumbent system's results, free of charge, obligation free, and within a week.
That is empirical validation on the buyer's own population conducted before purchase, and almost nothing else in this index offers it. The company also reports having submitted to a blind test run by a customer's own risk department, which is third party evaluation of the same kind. What is entirely absent is documentation.
No accuracy figure carries a methodology, no validation report, precision or recall measure, false positive rate or monitoring statement was located, and because the model is centralised and unconfigurable the customer cannot inspect, tune or version control what they are running.
Strong performance claims, no named customer behind any of them. The company publishes several comparative results: 40 percent fewer false positives than one of the world's top vendors in a blind test run by the risk department of a payment service provider and acquirer, up to 30 times better results than single dataset models, 15 times better than a card scheme solution, and 40 percent better than one of the top three fraud detection vendors.
Every comparator is unnamed, every evaluating customer is unnamed, and no methodology, population, period or baseline accompanies any figure, so none can be checked. No customer is identified anywhere. Corporate scale is small and verifiable: around 31 staff as of mid 2026, and roughly 3.3 million dollars raised across three rounds since 2021 including a Series A in June 2026 at an undisclosed amount, which is modest funding for a company seven years old. Association with ING, Payvision and Viva Wallet appears in the company's own material as backing rather than as customer evidence.
This is the sharpest pooling question in the index and it is not a side effect to be governed but the product itself. The company states plainly that it connects the datasets of all customers into a single centralised model, and that this is precisely what makes it better than solutions trained on an individual customer's data.
So a payment service provider's transaction history trains the model that scores a competing provider's transactions, and an acquirer's merchant portfolio behaviour informs verdicts at other acquirers. Nothing published governs any of it. There is no opt out, and there could not meaningfully be one without removing the stated advantage. No segregation statement exists, and segregation would defeat the design.
No retention position, no statement of what a departing customer's contributed data continues to do inside the model, and no description of what is extracted from a transaction before it joins the pool. The founders state they do not believe in black box solutions, which addresses explainability rather than stewardship.
Nothing was located. No data processing addendum, subprocessor list, retention schedule, named supervisory authority, transfer mechanism or named privacy regime appears on the vendor's own surface, despite the company being established in the Netherlands where the General Data Protection Regulation applies directly and a supervisory authority is readily identifiable. The exposure is structurally higher here than for any other vendor graded in this lane.
The product's central mechanism is the pooling of every customer's transaction data into one model, so cardholder level payment records from many institutions are combined in a single system by design rather than as a by product, and personal data flows across institutional boundaries as a condition of the service working. A platform built that way needs the most detailed processing documentation in this index and publishes the least.
Two dedicated passes located no security certification, attestation, trust centre, penetration test summary or enumerated control framework. One caveat on confidence: the second pass returned results dominated entirely by generic compliance automation and certification cost content rather than anything about this company, so this is recorded as not located rather than as established absence. The gap matters more here than for most vendors at this size.
The platform ingests card transaction data from acquirers, processors and issuers into a shared central model, which places it squarely inside the cardholder data environment its customers are themselves assessed against, and those customers cannot pass their own payment card assessments without evidence about this supplier. Pre emptive negative finding: a general statement of security practices will not move this grade. A payment card attestation naming this company, with its compliance level and the assessor, is what would.
A privately held Netherlands company holding no licence, with no supervisory relationship, named regulator counterparty, regulatory approval or industry body membership located. That is unremarkable for a technology supplier and is not a deduction in itself, but two things about this vendor's position would ordinarily produce more. It sells a money laundering detection product, which exists to discharge obligations under named anti money laundering directives, and none is cited.
And its customers are acquirers and payment service providers who face card scheme fraud ratio thresholds and can be fined or lose licences if those thresholds are breached, a risk the company describes accurately in its own market material, yet it makes no claim about scheme recognition, registry listing or certification against any scheme programme.
A stated principle with no mechanism behind it, and several performance claims with no methodology. The founders state they do not believe in black box solutions, but nothing published describes how a score is explained: no reason codes, feature attribution, alert narrative or audit output appears.
The comparative claims of 40 percent fewer false positives, 30 times better results than single dataset models and 15 times better than a card scheme solution carry no population, period, baseline or named comparator, so they cannot function as governance evidence. No error rate, precision measure, calibration statement or fairness testing exists.
The centralised architecture creates a bias pathway specific to this vendor and unaddressed by it: because one model serves every customer, a pattern learned from one geography, vertical or merchant category is applied everywhere at once, so a systematic misjudgement about a population propagates across the entire network simultaneously rather than being contained to the institution whose data produced it.
No guarantee, indemnity, accuracy service level or falsifiable commitment attaching to detection quality was located. The commercial terms substitute exit for liability: monthly subscriptions with no commitment mean a dissatisfied customer can leave quickly, and Proof of Results means they can decline to start, but neither compensates an institution for a loss the model failed to prevent or a good transaction it declined.
That is a reasonable position for a supplier at this scale and it should be recognised as what it is rather than mistaken for protection. For the individual there is nothing, and the architecture makes it worse than the lane norm: a cardholder or merchant scored as fraudulent is scored by a model trained on data pooled from institutions they have never dealt with, so the basis of an adverse decision about them exists nowhere they could reach it, and no notification, explanation, appeal or correction route is published.
The primary training input is identified openly, which is worth crediting because most vendors leave it vague: the company states that the model is trained on the pooled transaction datasets of all its customers, so a buyer knows the provenance of what scores their traffic and knows that their own data becomes part of it. That honesty is the disclosure. Nothing else in the chain is named.
No external data supplier, enrichment provider, device intelligence source, sanctions or watchlist provider is identified for any of the three products, which matters particularly for the money laundering detection line where screening quality depends on list provenance. No subprocessor list exists, no cloud infrastructure provider is named despite the platform being cloud native and centralised, and no model or foundation model provider is identified. Investors including ING, Payvision and Viva Wallet appear in company material as backers and are not suppliers.
Integration is presented as simple rather than deep, and the evidence supports the first claim and not the second. The company describes a simple application programming interface integration, a plug and protect model requiring no configuration, and responses returned in under 100 milliseconds, which suits a real time authorisation path and is the right latency profile for the acquirers and processors it targets. Beyond that nothing is enumerated.
No named connector, gateway, processor, core banking or case management integration was located, no software development kit inventory exists, and no public developer documentation was found. For a product whose buyers are payment service providers and acquirers running heterogeneous processing stacks, the absence of any published integration catalogue means a prospect cannot establish before contact whether the product drops into their environment.
Cloud native hosted software with no private, single tenant, regional or on premise option located, and in this case that is architectural rather than a gap the vendor might close. The product's value rests on a single centralised model trained across all customers, which means the data has to reach one place, so isolating a customer's processing into their own region or infrastructure would remove the network effect being sold.
No cloud provider, region, data centre or country of processing is named, and no transfer mechanism appears. The constraint is worth stating plainly for a buyer: an acquirer or issuer subject to data localisation requirements, or one whose supervisor expects cardholder data to remain within a jurisdiction, cannot satisfy that with this architecture regardless of what commercial terms are agreed.
The commercial model is published clearly and the evaluation route is genuinely unusual. Pricing is stated as pay per use only, on monthly subscriptions with no commitment, and the company frames that as removing the barrier to entry deliberately.
Alongside it sits Proof of Results: a prospect supplies their own historical transaction data, Fraudio produces detection output against it, and the prospect compares the results with their incumbent, free of charge, obligation free, with results in a week or less. The company is explicit about what it is attacking, naming competitors that charge six figures for a proof of concept and then take half a year to implement.
So a buyer learns the metering basis, the contractual shape, the exit terms and the evaluation cost before speaking to anyone. What is not published is the rate itself: no price per transaction, tier, band or worked example appears anywhere, so the shape of the deal is known and its size is not.
The buyer list is unusually wide across the payment chain and it is named rather than implied: payment service providers, merchant acquirers, card issuers, processors, card schemes, payment facilitators, neobanks, wallet providers, and large merchants running their own checkout or gateway. That spread follows from the architecture, since a centralised model gains from connecting institutions at every layer rather than serving one.
Product coverage matches it across three lines: payment fraud detection, merchant initiated fraud detection, and money laundering detection. The middle one is the distinguishing capability, addressing acquirers monitoring their own merchant portfolios for merchants who are themselves the fraudsters, a risk the company sizes with the observation that roughly 3 percent of newly digitally onboarded small businesses turn out to be fraudulent.
Few vendors in this index address acquirer side merchant risk at all. What holds this below the top grade is that none of those buyer types is evidenced by a named customer, and no geographic footprint is stated beyond the Amsterdam base.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
No rate published. Sold pay per use on monthly subscriptions with no commitment, preceded by a free, obligation free Proof of Results evaluation returning results in a week or less.
|
Pay per use, billed on monthly subscriptions with no commitment, which the company states is its only commercial model. The unit of use is not specified, so it is not confirmed whether the charge attaches to transactions scored, alerts raised or another measure, and no rate, tier or volume band is published. The structure follows the architecture: because a single centralised model serves every customer with no per customer configuration or training, the vendor's marginal cost of serving an additional customer is low, which makes a low friction usage based model and a free evaluation commercially feasible in a way it is not for vendors building bespoke models per client. Three product lines are sold from the same platform, covering payment fraud detection, merchant initiated fraud detection and money laundering detection, and no information indicates whether they are metered together or separately. | No data processing addendum, subprocessor list, retention schedule or named privacy regime was located, despite the company being established in the Netherlands where the General Data Protection Regulation applies directly. That absence is more consequential for this vendor than for most in this index, because the product works by pooling every customer's transaction data into one shared model, so personal payment data crosses institutional boundaries by design and a buyer needs processing terms to establish on what basis. Two dedicated passes also located no security certification, attestation or trust centre, though the second returned entirely generic compliance content so this is recorded as not located rather than established absence. | None indicated, and the absence is central to the sales position rather than incidental. The company markets a plug and protect model requiring no costly configuration, no rule authoring and no per customer model training, because the model is centralised and already trained, and it contrasts this directly with vendors it says charge six figures for a proof of concept and then take half a year to implement. Integration is described as a simple application programming interface connection. Proof of Results is explicitly free of charge and obligation free, so the evaluation that competitors bill for carries no fee here. No setup, onboarding or professional services charge appears anywhere, and given the architecture there is little professional services work for the vendor to perform. | Vendor Published |
Two dedicated passes. The commercial model is published clearly even though the rate is not, which is the reverse of most vendors in this lane. Stated on the vendor's own surface and in vendor supplied directory profiles: pay per use only, monthly subscriptions, no commitment, and no barrier to entry as a deliberate positioning choice.
Alongside it, Proof of Results gives a prospect a free, obligation free evaluation in which they supply their own historical transaction data and compare Fraudio's detection output against their incumbent, with results in a week or less. The company frames both against competitors it says charge six figures for a proof of concept and take half a year to implement. So the metering basis, contract shape, exit terms and evaluation cost are all knowable before contact.
Pre emptive negative finding: because pricing is per use and the model is shared, a rate quoted to one customer reflects their transaction volume rather than a list price, and no tier structure has been published against which a quote could be benchmarked.