Fraud Detection & Transaction Risk
N

NoFraud

NoFraud sells full service ecommerce fraud screening to small and mid sized merchants, with a Shopify centred distribution model and the most testable commercial terms in its category. Orders are screened in milliseconds and returned as a binary pass or fail decision, drawing on merchant specific data, persona tracking, global blocklists, device fingerprinting, geolocation and velocity signals. Fewer than half a percent of orders are held for human review, so the analyst team handles an exception tail rather than the volume, which is the reverse of the analyst heavy competitors in this lane. Two mechanisms extend the decision past the model.

Merchants can write custom rules and overrides, which several competitors do not permit. And for a limited set of high risk orders the company operates Cardholder Verification, where an analyst contacts the cardholder directly to confirm the order is legitimate before it is refused, which is the only mechanism located anywhere in this lane that brings the affected consumer into the decision. An optional chargeback guarantee covers the full cost on passed orders, with its scope published and limited to unauthorised or fraudulent card use rather than non fraud disputes, which are handled by a separate Chargeback Management service alongside dispute representment.

Screening covers card not present orders across cards, PayPal, Apple Pay, Alipay and Amazon Pay. Commercially the company publishes a free plan for up to 100 screened orders a month, no setup fees, charging only on approved orders, and a stated threshold of 50,000 dollars of monthly revenue above which pricing becomes custom. Published customer results include Obvi at a 1.6 percent revenue lift with chargebacks down 70 percent, and Caraway halving fraud while gaining 68,000 dollars in monthly revenue.

Last VerifiedAugust 24, 2026
Compare NoFraud with other vendors
Founded
Headquarters
United States
Website
www.nofraud.com
Categories
fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The published review rate settles this and it is worth stating precisely because the marketing sounds like the analyst heavy competitor in this lane. NoFraud describes AI plus expert analysts, but it also discloses that fewer than half a percent of orders are held for analyst scrutiny, with everything else returned as a pass or fail decision in milliseconds.

The analyst team is therefore sized for an exception tail rather than for the volume, which is the opposite of the vendor here that routes every flagged order to a person and staffs more than two thousand reviewers to do it. Strip the models from NoFraud and there is no decision path for the other ninety nine and a half percent, and no human capacity anywhere close to absorbing it.

The signal set is named rather than gestured at, covering merchant specific data, persona tracking, global blocklists, device fingerprinting, geolocation and velocity detection, and machine learning is claimed explicitly alongside custom rules. Persona tracking and device fingerprinting at this latency imply learned identity resolution rather than lookup.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Three distinct oversight mechanisms are published and one of them is unique in this lane. Merchants can write custom rules and overrides governing what happens to flagged orders, which the company positions directly against competitors that do not permit rule customisation, so the buyer holds real configuration authority rather than accepting vendor defaults. Manual analyst review catches the ambiguous tail, disclosed at fewer than half a percent of orders.

And Cardholder Verification brings the affected consumer into the decision: for a limited set of high risk orders an analyst contacts the cardholder to confirm legitimacy before the order is refused. Every other vendor in this lane decides about the shopper without ever involving them, and this one asks.

Against that, the overwhelming majority of decisions are fully automated at millisecond latency with no human involvement, the output is a binary pass or fail rather than a graduated risk signal, and no specification is published for review turnaround, analyst authority, verification criteria or how often a human overturns the model.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

The signal inventory is named more openly than most and the performance is not measured at all. On disclosure, the company identifies the categories feeding its decision engine as merchant specific data, persona tracking, global blocklists, device fingerprints, geolocation and velocity detection, which lets a reviewer reason about what kind of inference sits behind a refusal, and it publishes its manual review rate at under half a percent along with millisecond decision latency.

On performance there is nothing. No accuracy figure, precision or recall measure, false positive rate, validation report, model documentation or monitoring statement was located, and unlike the analyst heavy competitor in this lane there is no contractual accuracy service level either. The two published customer outcomes describe revenue and chargeback movement at individual merchants rather than model performance, and carry no baseline, population or methodology. A reviewer here can see what goes in and has no way to assess what comes out.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Two named customer results carry real figures: Obvi reporting a 1.6 percent revenue lift with fraud chargebacks down 70 percent, and Caraway halving fraud while gaining 68,000 dollars in monthly revenue. Independent review evidence is unusually good for a vendor this size and sits on a platform the vendor does not control, with 127 reviews on the Shopify application marketplace averaging 4.8 out of 5 and 91 percent of them at five stars, alongside G2 recognition as a Leader and for Best Results and Best Usability.

One operational figure is published that most competitors withhold entirely: fewer than half a percent of orders held for manual review, which tells a buyer how much friction the service actually introduces. What is absent is scale and standing.

No transaction volume, customer count, order count or geographic footprint is stated anywhere, the two named customers are direct to consumer brands rather than enterprises, the company is privately held with no financial disclosure, and no analyst house ranking or third party market position was located.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The network question applies as it does everywhere in this lane, and one element here is more intrusive than anything its competitors do. On the network, the named signal set includes global blocklists and persona tracking alongside merchant specific data, which necessarily means shopper reputation is carried across merchants, and nothing published states whether a merchant can decline to contribute, how one merchant's data is separated from another's, or what a retained persona record contains.

On the more specific point, Cardholder Verification involves an analyst telephoning or otherwise contacting the cardholder to confirm a transaction. That is a fraud vendor initiating direct contact with a merchant's customer using contact details supplied for a purchase, and while it is plainly done to help the shopper, nothing published describes consent, script, identification, call retention, opt out, or how the shopper is meant to distinguish that call from the social engineering attack it structurally resembles.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The general data protection statement is more useful than most at this size and the rest is thin. The company states it has made significant efforts to ensure compliance with the General Data Protection Regulation for itself and its vendors, and that merchants subject to that regulation can contact support for the necessary paperwork, which acknowledges the subprocessor chain exists and that executable terms are available, without publishing either.

No processing addendum, subprocessor list, retention schedule or named supervisory authority was located. The about page carries a reference to a transatlantic transfer framework administered by the United States Department of Commerce with the European Commission and the Swiss Administration, without naming which framework, giving a certification date or stating status, and a buyer cannot tell whether the current arrangement or its invalidated predecessor is meant.

One exposure is specific to this vendor and undocumented: Cardholder Verification has analysts contact consumers directly to confirm orders, so the platform holds and uses shopper contact details for outbound contact, and nothing published governs that.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Two dedicated passes located no certification, attestation, trust centre, penetration test summary or enumerated control framework. What the about page carries are references to standards bodies rather than claims of standing under them: the Payment Card Industry Security Standards Council is described as a global forum for developing account data protection standards, and a transatlantic data transfer arrangement is described as a mechanism designed by the United States Department of Commerce with the European Commission and the Swiss Administration.

Both are descriptions of what an organisation or framework is, with no verb attaching the company to either, no compliance level, no attestation, no assessor and no date. That is the badge without a claim, which is exactly what the credential test exists to catch, and it is a step below the peers in this lane that at least assert compliance in their own voice. No SOC report of any type was located. Pre emptive negative finding: displaying the same two logos more prominently will not move this grade. A stated compliance level with an attestation of compliance, or any SOC report, is what would.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

Privately held, holding no financial licence, with no supervisory relationship, named regulator counterparty or regulatory approval located. Compliance is claimed against one named regime, the General Data Protection Regulation, with paperwork offered on request, which is the most concrete regulatory statement on the record.

Beyond it the references are to standards bodies rather than to obligations: the about page cites the Payment Card Industry Security Standards Council and a transatlantic data transfer framework, in both cases describing what the body or arrangement is rather than asserting the company's status under it. Screening card not present transactions across the major card networks and wallet providers places the product inside scheme rules without conferring any regulated standing. Nothing here counts against a technology supplier, which is not expected to hold a licence, and nothing lifts the record either.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

One genuinely useful operational disclosure and no governance behind it. Publishing that fewer than half a percent of orders are held for review is a real number about how the system behaves, and very few vendors in this lane disclose their own friction rate at all. It is not an error rate. No false positive rate, false negative rate, accuracy figure, confidence measure or calibration statement is published for any model.

No fairness testing, disparate impact analysis or coverage statement exists, which matters because the output is a binary pass or fail with no middle ground, so a systematically mis scored population is refused outright rather than routed to friction. Nothing describes who approves a model change, what validation a new model passes, or how a merchant is told when scoring behaviour shifts. The custom rules layer gives a merchant visibility into their own overrides while telling them nothing about the model those overrides sit on top of.

AI Liability and Recourse
BB on AI Liability and RecourseA published falsifiable commitment such as an accuracy figure with its method, or a real correction route for the affected person, such as step up verification instead of silent denial.
Vendor Published

The guarantee is optional rather than bundled, and its scope is published and limited in a way competitors tend to leave vague. The company covers the full cost of a chargeback on any order it passed, and states plainly that this covers chargebacks arising from unauthorised or fraudulent card use and expressly does not cover non fraud disputes such as item not received or item not as described.

Publishing the exclusion is the notable part: a merchant learns the boundary of the protection before buying rather than at the moment of a claim, and the non fraud disputes that fall outside it are handled by a separate Chargeback Management service alongside dispute representment.

For the affected consumer this record is better than anything else in this lane, because Cardholder Verification means a shopper on a high risk order may be contacted and given the chance to confirm the purchase before it is refused, which is participation rather than notification. It remains partial.

Verification applies to a limited set of orders only, a shopper refused without it is still not told and has no appeal, and no accuracy commitment or service level attaches to correcting a wrong decision.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Categories are named and suppliers are not. The company identifies what kinds of data feed its decisions, listing merchant specific data, persona tracking, global blocklists, device fingerprints, geolocation and velocity detection, which is more than several competitors offer and still stops at the level above the one that matters.

Global blocklists belong to someone, device fingerprinting is a technology usually licensed rather than built, and geolocation resolution is almost always bought, yet no provider is named for any of them. No subprocessor list is published, no cloud infrastructure provider is identified, and no model or foundation model provider is stated for any component.

The one acknowledgement that a chain exists comes in the privacy answer, where the company says it has worked on data protection compliance for itself and its vendors, confirming there are vendors without saying who they are. Naming the blocklist and device intelligence sources would be the single most useful addition here.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Narrow in platform count and unusually deep inside the one ecosystem that matters to its customers. Native paths are named for Shopify, BigCommerce, WooCommerce and Adobe Commerce, with a direct API integration for everything else, and the Shopify application is stated to install in under five minutes.

The depth is in the surrounding ecosystem rather than the platform list: the application is documented as working with Shopify Checkout, Shopify Flow, Shopify Admin, Shop Pay and PayPal, and notably with the subscription infrastructure merchants at this size actually run, including Recharge, Yotpo Subscriptions, Skio and Stay AI.

Subscription commerce is a distinct fraud problem because a single approved order generates recurring charges, and integrating with those systems specifically is a meaningful capability rather than a logo. Payment method coverage spans cards, PayPal, Apple Pay, Alipay and Amazon Pay. What is missing is the payment gateway and acquirer connector layer that lets a guarantee reconcile against the processor, which the stronger records in this lane publish and this one does not.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Hosted software consumed through a platform application or a direct API, with no private, single tenant or on premise option located. The company is stated to be based in the United States on its marketplace listing and nothing further about processing location is published: no cloud provider, region, data centre or country of processing is named, no region selection is offered, and no residency commitment appears.

A transfer framework is referenced on the about page without being named or dated, which is the closest the record comes to a residency position and does not amount to one. The gap has teeth for any merchant selling into Europe, because the company states it has worked on compliance with the General Data Protection Regulation and offers paperwork on request, yet the buyer cannot complete their own transfer assessment without knowing where the data goes or which mechanism covers it.

Commercial
Commercial Transparency
BB on Commercial TransparencyA published plan ladder, billing dimensions, or a stated commitment such as no fees, so a buyer can size the cost before making contact.
Vendor Published

The strongest position in this lane for the segment it serves, and it is strong because it is testable rather than merely readable. A merchant can install the product, screen up to 100 orders a month, and run it in production indefinitely without paying anything or speaking to a salesperson, with a 14 day trial beginning at the first screened order.

Around that free plan the company publishes no setup fees, charging only on orders it approves, starter plans that include chargeback protection, and the explicit revenue threshold of 50,000 dollars a month above which pricing becomes custom. That is the metering basis, the entry point, the segment boundary and the risk allocation, all available before contact. Two things hold it below the top grade.

The rate itself is never published on the vendor's own surface and routes to a form, with a third party reporting 1 to 1.5 percent of revenue that could not be confirmed. And the free plan excludes manual review and the guarantee, which are the two capabilities the paid tiers exist to deliver, so what is free is the screening engine rather than the service.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

One buyer type and a deliberately narrow band within it. The customer is the online merchant, and the company positions explicitly at the small and mid sized end, describing starter plans for even the smallest businesses and setting its custom pricing threshold at 50,000 dollars of monthly revenue, which is a small merchant by the standards of every other vendor in this lane.

Distribution reinforces the narrowness: the centre of gravity is the Shopify ecosystem, with named paths for BigCommerce, WooCommerce and Adobe Commerce and a direct API for everything else. Payment method coverage is genuinely broad, spanning cards, PayPal, Apple Pay, Alipay and Amazon Pay across card not present orders. What is absent is everything beyond that.

No verticals are enumerated, no geographic footprint or country count is stated, no enterprise tier is described beyond custom pricing, and there is no second buyer type: this vendor does not sell to payment providers, banks, insurers or regulators.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Free plan for up to 100 screened orders per month, free to install, with a 14 day trial from the first screened order. Paid starter plans include chargeback protection for merchants under 50,000 dollars monthly revenue; rates route to a form.
$0 baseline
Charged as a share of approved order value, with the vendor charging nothing on orders it declines, across a published three step structure. A free plan covers up to 100 screened orders a month without manual review or the guarantee. Starter plans serve merchants processing under 50,000 dollars of monthly revenue and include chargeback protection, with a third party reporting the rate at 1 to 1.5 percent of revenue varying by monthly minimum. Merchants above 50,000 dollars a month move to custom pricing. The chargeback guarantee is optional rather than bundled at every tier, and its scope is published and limited: it covers chargebacks arising from unauthorised or fraudulent card use and expressly does not cover non fraud disputes such as item not received or item not as described, which are handled by the separate Chargeback Management service. Screening covers card not present orders across credit and debit cards, PayPal, Apple Pay, Alipay and Amazon Pay. No data processing addendum or subprocessor list is published, but the position is stated more usefully than most at this size. The company says it has made significant efforts to ensure compliance with the General Data Protection Regulation for itself and its vendors, and that merchants subject to that regulation can contact support for the necessary paperwork, which acknowledges both the subprocessor chain and the existence of executable terms without publishing either. The about page additionally displays a reference to a transatlantic data transfer framework administered by the United States Department of Commerce with the European Commission and the Swiss Administration, without naming which framework, stating certification status or giving a date, which matters because the arrangement in that space was invalidated in 2020 and replaced in 2023 and a buyer cannot tell from the page which one is meant. None, stated explicitly. The company advertises simple pricing with no setup fees and charging only on approved orders. The claim is supported by the delivery model rather than merely asserted: the Shopify application installs in under five minutes, native paths exist for BigCommerce, WooCommerce and Adobe Commerce, and a direct API integration is offered for everything else, so a typical merchant needs no engineering project. Manual order review, shopper verification and dispute representment are described as part of the service rather than as chargeable professional services. Chargeback Management, which handles non fraud disputes the guarantee does not cover, is a separate offering and no rate is published for it. A referral programme paying up to 300 dollars is advertised. Third Party Estimated

Two dedicated passes, and this is the most usable commercial disclosure in the ecommerce fraud lane for the segment it targets. What the vendor itself publishes: a free plan covering up to 100 screened orders a month, a 14 day trial beginning at the first screened order, no setup fees, charging only on approved orders, starter plans that include chargeback protection for merchants under 50,000 dollars of monthly revenue, and the explicit threshold above which pricing becomes custom.

A small merchant can install the product and run it in production without paying anything or speaking to anyone, which is a stronger commercial disclosure than any published floor because it is testable rather than merely readable. What the vendor does not publish is the rate.

A third party listing reports starter pricing at 1 to 1.5 percent of revenue depending on the monthly minimum, and that figure is recorded here as third party estimate because it was not located on the vendor's own surface, where rates route to a form.

Pre emptive negative finding: the free tier's 100 order cap is the binding constraint and not the price, so a merchant above roughly three orders a day is in paid territory regardless of the headline, and the free plan excludes manual review and the guarantee, which are the two things the paid tiers are actually for.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746