Fraud Detection & Transaction Risk
I

Incognia

Incognia answers the identity question with geography. Its premise is that where a person is, over time, is a harder credential to fake than what device they are holding, because people handle important account actions from places they habitually occupy. The platform learns a user's trusted locations, typically home and workplace, from background location signals and motion sensors collected through a mobile software development kit, and treats a departure from that pattern at the moment of login or payment as a risk indicator. The company reports that 90 percent of device authorisations on its network occur at one of the user's trusted locations.

The second half is device work. Incognia ID is sold as a persistent identity that survives what ordinarily defeats fingerprinting, namely factory resets and device swaps, and the company pairs it with tamper and location spoofing detection on the grounds that a location signal is only worth anything if it cannot be faked. Clusters of devices are surfaced to expose device farms and repeated resets. The company describes the combination as identity affirmation rather than identity validation, citing an analyst definition, and is explicit that the signal supports an identity claim rather than proving the claimant is present.

Financial lines are separately developed and carry finance specific logic, which is what places this record here rather than outside scope. A dedicated banking and fintech line covers account takeover, device authorisation at high risk events, new account fraud, and a transaction risk model that scores an individual payment high, low or unknown from hundreds of inputs spanning the user's past transactions, location history, prior fraud events and device data. The company also publishes original research on mule account handover. Food delivery, ride hailing and marketplace lines are sold from the same network and are excluded here.

The network is the moat: close to a billion devices, more than 500 million places mapped, and monthly activity across hundreds of millions of devices. Founded 2010 by Andre Ferraz and Alan Gomes, pivoted to fraud prevention in 2020, with 47 million dollars raised and offices in California, New York, Sao Paulo and Recife.

Last VerifiedAugust 25, 2026
Compare Incognia with other vendors
Founded
2010
Headquarters
Palo Alto, California, United States
Categories
fraud-and-transaction-risk, aml-kyc-financial-crime
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

Models are essential to what the product claims and the moat underneath them is data rather than modelling. The claims that distinguish this vendor cannot be met by lookup: recognising the same person after a factory reset or a device swap, learning which places count as trusted for one individual, telling a genuine location from a spoofed one, and clustering devices to expose farms are all inference problems.

The transaction risk component is described as a machine learning model referencing hundreds of data points that vary by scenario and returning a high, low or unknown assessment, which is model output rather than rule output. Against that, the asset a competitor could not replicate by hiring better modellers is the network itself, close to a billion devices and more than 500 million mapped places accumulated over years, and the raw signal collection through motion sensors and location services is engineering rather than learning.

Strip the models and device fingerprinting and raw location remain and retain some value, which is more residue than the top band allows. The company describes itself as artificial intelligence powered cross device risk intelligence.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The vendor scopes its own claim more carefully than most, and that scoping is the substance of this grade. Rather than presenting its output as proof of identity, the company adopts an analyst distinction between affirmation and validation and states explicitly that its signals support an identity claim and confirm the identity exists, but do not establish that the valid owner is present.

A vendor telling a bank what its product does not prove is doing the buyer's risk function a real service, and it sets an implicit expectation that a further control carries the rest. The output is a high, low or unknown risk assessment returned to the institution, which decides. Nothing in the published material describes the platform closing an alert, blocking a transaction on its own authority, generating a filing or acting without the customer's rule.

What is missing is the other half of the boundary. Nothing states what an institution should not do with the signal alone, what a customer wrongly assessed as high risk is told, or whether an assessment can be appealed or overridden, which matters because a wrong assessment here means a legitimate person cannot transact.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

One passage of real methodological candour, surrounded by figures that cannot be assessed at all. The candour is worth quoting in substance: asked for transaction risk numbers, the company explains that the model references hundreds of data points which change according to the scenario, states that it therefore cannot share specific figures, and instead lists examples of the risk indicators considered.

That is a vendor explaining why a number would mislead and offering something useful instead. The surrounding claims do the opposite. Identification accuracy is published at 99.999999 percent, eight nines, with no definition of what is being identified, no sample, no observation period and no method. A zero percent account takeover fraud rate is claimed for location enabled mobile sessions, an absolute that admits no error.

A 17 times performance improvement over leading facial recognition systems compares two different modalities measuring different things against an unnamed comparator. None of the three could be reproduced or falsified from anything published, and no false positive rate, validation methodology or drift disclosure was located across two passes.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Substantial evidence with a specific hole in the middle of it. The commercial evidence is unusually concrete and comes partly through investors rather than only from the vendor: tripled revenue, 200 percent net revenue retention, conversion of every trial, an average six times return on investment and stated savings of millions of dollars per contract, published around a 31 million dollar round led by a well known growth investor with a large hedge fund and an international technology investor also on the register.

Network scale is stated precisely and repeatedly, at close to a billion devices, more than 500 million places mapped and hundreds of millions of devices seen monthly. Independent signal exists through a software marketplace with reviews naming both a strength, ease of integration and support responsiveness, and a weakness, dashboard usability. The company publishes original financial crime research on mule account handover. The hole is that no financial institution is named anywhere.

The customers identified by name are a food delivery business and a delivery platform, both outside the scope of this record, while the financial references appear only as an unnamed financial services enterprise reporting a 30 percent reduction in authentication costs.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

Stewardship commitments that are specific enough to be held to, paired with the usual silence on model safety. Three commitments stand out. Data collected through the software development kit is stated as used for no purpose beyond providing the service, which forecloses the secondary use and onward sale that has defined the worst behaviour in the location data industry.

The company undertakes to take legal action where it identifies that a client's processing instruction is unlawful, which is a stated willingness to act against its own paying customer and is rare anywhere in this index. And a dedicated address is published for requesting security reports, giving a buyer a named channel rather than a sales form. Privacy by design is claimed as a product principle rather than a policy. Two things temper it.

The assertion that the solution does not continuously track or monitor users sits awkwardly beside a product built on learning where an individual habitually is, and nothing published reconciles the two. And across two passes no model card, evaluation methodology, red team result, incident disclosure or acceptable use boundary was located.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

The most detailed privacy documentation in this segment, and a legal basis that deserves to be read closely rather than taken as reassurance. The documentation is genuinely strong: separate published policies for global and United States processing plus a dated archive of a superseded version, an annual assessment of controls against European data protection requirements with an attestation letter stated as available, coverage claimed under the European, Californian and Brazilian regimes, and two commitments more specific than the category norm, that data collected through the software development kit is not used for any purpose beyond service provision, and that where a client's processing instruction is identified as unlawful the company will take legal action.

The basis is where a buyer should slow down. The company states plainly that the device location permission is not treated as consent but as an operational requirement, and that legitimate interest is applied as the legal basis, which by its own words dispenses with consent from the data subject. Responsibility for permissions and transparency is assigned to the client application. And the policy declines to identify which applications collect through it, citing client confidentiality, so a person cannot establish where their own location history originated.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

A credential described as a process rather than displayed as a badge, which is the distinction this axis should reward. The company names the framework in text, enumerates the five trust services criteria it covers including privacy, states that the audit is performed annually by an independent third party, and publishes a dedicated address at which the report can be requested under a non disclosure agreement. That is a route a buyer can actually take.

Alongside it, annual assessments of controls against European data protection requirements are stated with an attestation letter offered, and specific engineering practices are described rather than gestured at, covering secure development lifecycle, code review, security testing within the development process, and enforced separation between development, staging and production environments. Deductions are precise.

No trust centre exists, no certificate or report is downloadable, no penetration test summary or subprocessor list is published, and no information security management certification was located. The site also repeatedly describes the attestation as a certification and says an auditor has certified compliance, where this framework produces an opinion in a report and confers no certificate.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

An unregulated supplier with genuine regulatory work concentrated entirely on one side of its exposure. The privacy side is properly addressed and evidenced rather than asserted, with stated compliance across the European, Californian and Brazilian data protection regimes, annual assessments of controls against European requirements, an attestation letter offered, and a published analysis of how the company positions its legal basis for collection.

Few vendors here engage three regimes with that specificity. The financial side is untouched. The company holds no financial services authorisation and claims none, which is correct, but across two passes nothing published addresses the Gramm Leach Bliley Act despite a United States base and financial customers, nothing addresses the European artificial intelligence regulation despite running inference on consumers in Europe, and nothing addresses European strong customer authentication despite selling location behaviour as an authentication signal into European banking, where whether a location signal can serve as an authentication element is a live regulatory question rather than a product one.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The exposure follows from the central idea and is not addressed anywhere public. Treating a departure from a person's habitual locations as a risk signal assumes that habitual locations exist and are stable, and that assumption fails for identifiable groups rather than at random.

People who move house often, who rent short term, who are between homes, who work shifts across sites, who travel for work, who have recently arrived in a country, or who have left a household because of domestic abuse will all present as away from their trusted locations while doing nothing wrong. Dense housing degrades the precision the model depends on.

The company's own figure that 90 percent of device authorisations occur at a trusted location defines the exposed group as the other 10 percent, and that group is not a random sample of customers. Because the product gates transactions and device authorisation at banks, the consequence of being in it is friction or refusal at the moment money is needed. Across two passes no breakdown of assessment outcomes by housing stability, mobility, region or income was located, and no bias testing, fairness statement, model card or governance page exists.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

No commercial instrument is published. Across two passes no terms of service, master subscription agreement, warranty, indemnity, liability cap, service level or uptime commitment was located on any vendor surface. What is published sits adjacent to this axis without occupying it, and the distinction should be drawn so the two are not confused.

The undertaking to take legal action where a client's processing instruction is unlawful is a commitment about the vendor's own conduct toward third parties, not a liability it accepts toward the customer. The security report request address serves due diligence. The privacy policies create data protection obligations rather than performance ones. None allocates a unit of risk arising from a wrong assessment.

The uncovered exposure is concrete: a legitimate customer away from their habitual locations, whether because they moved, travelled or left a household, can be assessed as high risk at the moment they need to transact, and nothing published states what the institution is owed, what that person is told, or how the assessment is contested.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The data supply chain carries one disclosure that matters a great deal in this category, and the model supply chain carries none. The disclosure is provenance. The company describes collecting its signals first hand through its own software development kit embedded in client applications, using device location services and motion sensors, and building its map of more than 500 million places from that network.

In the location industry specifically, where the recurring scandal has been brokers assembling and reselling movement histories bought from undisclosed application publishers, a vendor stating that it collects its own signal under its own agreements is a meaningful supply chain fact rather than a boast, and it is reinforced by the commitment not to use that data for anything beyond the service. The limits are two.

The client applications feeding the network are deliberately not identified, on stated confidentiality grounds, so the composition of the network cannot be assessed. And no model provider, family, version or technique is named for the persistent identity, spoof detection or transaction risk models anywhere.

Core Systems and Integration Depth
CC on Core Systems and Integration DepthIntegration claimed through standards or connectors with no system named and nothing to verify.
Vendor Published

Integration is evidently easy and almost none of the evidence is inspectable. The positive signals are real but indirect: reviewers on a software marketplace consistently name ease of integration and support responsiveness as the product's strengths, which is independent testimony rather than vendor claim, and the company states it has become the most downloaded fraud prevention software development kit in Europe, which implies both broad adoption and a low integration barrier.

Delivery is through mobile software development kits for the major platforms with web coverage alongside, and the transaction risk assessment is consumed as a call at the moment of login or payment. What a buying engineer cannot do is check any of it before a sales conversation.

Across two passes no public interface documentation, developer portal, sandbox, code repository, connector catalogue or cloud marketplace listing was located, and no core banking, case management, authentication or orchestration platform is named as supported. The same reviewers who praise integration name dashboard usability as the weakness, which is the part of the product a fraud team lives in daily.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

A hosted assessment service fed by an on device collector, with the residency questions unaddressed. Signals are gathered by a software development kit running inside the customer's own application and sent to the vendor for assessment against its network, so unlike an edge deployed or self hosted product the vendor necessarily holds the data.

Across two passes nothing published states which regions process or store it, whether residency can be pinned for European or Brazilian customers, what the tenancy model is, or how long location histories are retained. The company has offices in the United States and two in Brazil and claims compliance with the European, Californian and Brazilian regimes, but a compliance claim is a statement about legal basis rather than about processing location, and the two should not be read as the same thing.

The gap weighs more here than at most vendors because of what is held. Location history is among the most sensitive categories of personal data, the network spans close to a billion devices across many jurisdictions, and where those histories rest determines which authorities can compel access to them.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No rate, unit or tier is published, and two passes across the vendor's site, its industry and product pages, its research and the software marketplace listings produced nothing on how the product is charged. The published entry route is a meeting with a specialist. Two indirect signals give a buyer more than most contact sales postures offer, and both come from the company's funding material rather than from a pricing page.

The stated average of six times return on investment, and the claim of saving customers millions of dollars per contract on average, together imply a contract size in at least the high six figures, which is an order of magnitude a buyer can plan around even though it is not a price. The stated conversion of every trial also confirms that a trial exists as a route, though no trial length, scope or terms are published anywhere.

What remains entirely unknown is the basis: nothing indicates whether charging follows devices, monthly active users, assessments, transactions or seats, and for a product priced against a network of this size the unit is the question that decides everything.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

A properly built financial line inside a company whose centre of gravity sits elsewhere. The banking and fintech material is genuine product work rather than a vertical page, addressing account takeover, device authorisation at high risk events, new account fraud and transaction level risk scoring as separate jobs, and the mule account handover research is written for banks specifically.

Geographic depth is real and reaches markets this index rarely covers, with offices in the United States and two in Brazil, compliance addressed under the Brazilian data protection regime alongside the European and Californian ones, and a claim to be the most downloaded fraud prevention software development kit in Europe.

Against that, financial services is consistently listed fourth in the company's own description of itself, behind food delivery, ride hailing and marketplaces, and those adjacent verticals supply the named customers. No bank, credit union, payment institution or fintech is named anywhere, no count of financial customers is published, and nothing addresses insurance, wealth or capital markets. A buyer cannot tell from the public record how much of this network is financial.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at Incognia, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Aug 27, 2026Product / capability

Incognia launched AI Powered Browser ID, a web risk product that applies a transformer architecture to the semantic relationship between more than 200 browser metadata signals. Rather than hashing attributes into a static fingerprint, it tokenizes the metadata so an identity stays stable when the technical environment changes.

Bears on: AI CentralitySource
Our read on this change →Tracked since Aug 2026
Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing, tier or contract term appears on any vendor surface
Not published on any vendor surface. Nothing indicates whether charging follows devices, monthly active users, risk assessments, transactions, applications or seats, and the estate spans a persistent identity product, device and location intelligence, tamper and spoof detection and a transaction risk model without any statement of whether these are licensed together or separately. Indirect indications from the company's funding material, offered as context rather than as pricing: an average return on investment of six times, and stated average savings of millions of dollars per contract, alongside 200 percent net revenue retention which implies expansion within existing accounts and therefore a basis that scales with usage or coverage rather than a flat platform fee. No tiered data protection terms are published, and commitments are made uniformly across the estate. Published: separate global and United States privacy policies plus a dated archive of a superseded version, an annual attestation covering security, availability, processing integrity, confidentiality and privacy with the report available under a non disclosure agreement from a named address, annual assessments against European data protection requirements with an attestation letter offered, and stated compliance under the European, Californian and Brazilian regimes. Two commitments are specific: data collected through the software development kit is not used beyond service provision, and the company will take legal action where a client's processing instruction is identified as unlawful. Retention periods, hosting regions and subprocessors are not published. No implementation, integration or professional services fee is published. Integration effort appears low on independent evidence rather than vendor claim, with reviewers on a software marketplace consistently naming ease of integration and the responsiveness of the vendor's support team as the product's strengths, and the company stating it has become the most downloaded fraud prevention software development kit in Europe. Delivery is a software development kit embedded in the customer's own mobile application with web coverage alongside, so the work sits inside the institution's own release cycle and app store submission process, a dependency the vendor does not price or discuss. A trial exists, evidenced only by the company's claim to have converted every trial it has run, with no published length, scope or terms. The same independent reviewers name dashboard usability as the product's weakness, which bears on the operational effort a fraud team carries after implementation rather than during it. Vendor Published

Two passes across the vendor's site, its industry and product pages, its research and solution briefs and the software marketplace listings produced no rate, unit, tier or contract term. The published entry route is a meeting with a specialist. What distinguishes this from a bare contact sales posture is that the company's funding material contains two figures a buyer can reason from even though neither is a price.

An average six times return on investment, and stated savings of millions of dollars per contract on average, together bound the contract size well above small business software and into enterprise territory. The stated conversion of every trial confirms a trial route exists.

Buyers should note one structural point the pricing silence obscures: the value of this product rises with the size of the network behind it, and the network is fed by client applications the company declines to identify on confidentiality grounds, so a prospective customer cannot assess how much coverage they are actually buying in their own market or user population before contracting.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746