Incandor
Incandor builds behavioural intelligence infrastructure for banks, fintechs, neobanks and digital banks, on the argument that institutions verify identity at account creation but have no continuous signal for who is actually operating an account afterwards, while identity itself has become a commodity attackers buy in bulk. It constructs a behavioural map of every user from physical interaction signals including mouse dynamics, keystroke timing, scroll patterns and how a phone is held, requiring no fraud labels or historical data, so detection works from the first session.
Each individual forms a unique cluster regardless of which account they use, which surfaces account takeovers, mule handoffs, shared operators and coordinated rings, and supports bot detection and identification of sessions under stress or coercion. Rather than returning a risk score, it exposes the map as a programmable interface so a fraud team combines behavioural signals with its own transaction and customer data. It collects only behavioural signals, not what users type, read or view.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
Unsupervised behavioural clustering is the whole product. The system learns each user's physical interaction pattern from mouse dynamics, keystroke timing, scroll behaviour and device orientation, and places every session in a map where an individual forms a distinct cluster regardless of which account is used.
Crucially it requires no fraud labels or historical data, so it functions from the first session rather than after a training period, which is a genuine architectural distinction from supervised fraud scoring.
The design deliberately withholds the automated verdict, exposing the behavioural map as a composable programmable interface rather than a black box risk score, so the institution's own fraud team combines behavioural signals with its transaction history, customer records and business rules to express investigation logic the vendor could not replicate. That leaves judgement with the bank by construction. Held at B because one path runs the other way, since banned operators can be blocked during onboarding automatically, with no described review of that exclusion.
The architectural choice supports inspection: because the output is a navigable map rather than a score, an investigator can examine why sessions cluster together and follow an operator's activity across accounts rather than accepting a number. Working without historical labels also removes dependence on a bank's past fraud tagging, which is itself often incomplete.
Held at B because the above 99 percent accuracy figure is published without methodology, sample or false positive rate, and for a system that can lead to account blocking the false positive rate is the number that matters.
The company states it is onboarding early customers and no institution is named. Its accuracy claim of above 99 percent for account takeover detection carries no sample, baseline or false positive rate. An independent assessment notes that the founders are described only as two engineers from a named university with no verifiable work history available, and observes that university affiliation alone is the weakest possible signal. The company is a 2026 accelerator cohort member at pre-seed stage, so the record is appropriately thin rather than concealed.
No boundary statement was located. The behavioural map is described as covering every user on the customer's own platform, which implies per-institution scoping, while the ability to block a previously banned operator when they return implies persistence beyond any single account or credential.
Nothing states whether behavioural clusters are isolated per customer or whether an operator identified at one institution is recognisable at another, which is the question that determines how powerful and how dangerous the system is.
The collection boundary is stated explicitly and narrowly, capturing only behavioural signals and not what users type, read or view, with the company arguing that behaviour alone is sufficient for operator-level reconciliation and therefore keeps user data private by design. Drawing that line deliberately, and explaining why the excluded data is unnecessary, is better than most vendors here manage.
Held at B because no data protection agreement, retention schedule or subprocessor register was located, and continuous behavioural telemetry on every session is still a substantial personal data flow.
No attestation, certification, trust centre or enumerated control set was located, which is expected at this stage and remains the practical barrier to a first bank deployment, since the vendor is asking to receive continuous session telemetry from every customer of a regulated institution.
No regulator, statute or supervisory expectation is named. Identity verification pipelines are referenced as the existing control the product supplements, without engaging the customer due diligence rules that govern them, and continuous behavioural monitoring of banking customers raises consent and biometric data questions in several jurisdictions that published material does not address.
No fairness testing or bias disclosure was located, and the exposure is inherent to the method rather than incidental. Classifying people by mouse movement, typing rhythm, scroll behaviour and how they hold a device means motor control, age, disability, assistive technology and device quality all shape the signal, so a user with a tremor, one navigating by screen reader, or one on older hardware may cluster as anomalous for reasons unrelated to fraud. Detection of sessions under stress or coercion compounds it, since distress is inferred from physical behaviour. Nothing addresses differential performance across those populations.
No guarantee, indemnity or correction process was located, and the recourse gap is the sharpest consequence of the design. An operator flagged after a confirmed fraud case can be blocked at onboarding when they return, and because the identifier is behavioural rather than documentary, that exclusion follows the person across accounts, devices and credentials. Someone wrongly clustered has no identity document to correct, no score to dispute and no described route to learn that a behavioural profile is why they cannot open an account.
No base model, provider, hosting arrangement or subprocessor is identified. The signal source is the company's own telemetry rather than licensed data, which removes external data dependency, and the modelling approach behind the clustering is described only at concept level, so an institution cannot document what is producing the behavioural identities it acts on.
Integration is lightweight and clearly described: deploying a software development kit that sends behavioural telemetry, after which the interface for querying the map becomes live, with the map designed to be navigated inside the institution's existing workflows alongside transaction linking and other signals it already runs. Held at B because no fraud platform, case management or core system is named individually.
No hosting provider, region, residency commitment or self-hosted option was located. The architecture sends behavioural telemetry from every customer session to the vendor for mapping, which makes processing location a live question, particularly where behavioural biometric data attracts specific handling requirements.
No pricing, packaging or basis of charge was located. Delivery is by software development kit and interface access, which usually implies usage-based pricing, and nothing indicates whether charge follows sessions, users or platform volume.
The target market is named as commercial and consumer banks, fintechs, neobanks and digital banks, and it is a statement of intent rather than coverage, since the company is actively soliciting introductions to those buyers. No institution type, size band or geography is evidenced as served.
Alternatives to Incandor
The closest documented capability profiles to Incandor in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Operational and Outcome Evidence and Institution and Segment Coverage where Incandor does not
Documents Operational and Outcome Evidence and Institution and Segment Coverage where Incandor does not
Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Incandor does not
Documents Operational and Outcome Evidence and Institution and Segment Coverage where Incandor does not
A lighter documented profile than Incandor
Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Incandor does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.