Ravelin
Ravelin Technology is a London fraud prevention and payments company founded in 2015 by Martin Sweeney and Leonard Austin, who built it after encountering the problem as merchants at the ride hailing company Hailo. Worldpay acquired it in February 2025 on undisclosed terms, and it continues to sell and publish under its own name from ravelin.com.
The architecture is the distinguishing feature: rather than scoring against a generic model, Ravelin trains custom machine learning models on each merchant's own historical data, arguing that purpose built models outperform generic ones, and layers graph network link analysis over that merchant's dataset to expose fraud rings and connections in real time. A separate cross merchant lookup answers whether a shopper has been seen as legitimate or fraudulent elsewhere, and the company states that database is fully anonymised.
Solutions cover payment fraud, policy and refund abuse, account takeover and multi accounting, promotion and voucher abuse, marketplace and supplier collusion, 3D Secure authentication, and transaction optimisation for acceptance and fee management, sold to online merchants and payment service providers. Ravelin Insights adds performance monitoring, transaction anomaly investigation and an artificial intelligence query builder for custom reporting.
The company publishes its annual operating figures: in 2025 it secured more than 3.5 billion transactions, served 755.2 million unique shoppers, processed over 61.5 billion dollars in orders, and supported more than 340 merchants taking payments from over 250 countries and territories. It holds ISO 27001:2022 assessed by the British Assessment Bureau alongside Payment Card Industry Data Security Standard and PCI 3DS certification, and names Ekata and Ethoca as data partners.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
Described as AI native by the company, by its acquirer and by the bank that advised the sale, and the architecture supports the label rather than decorating it. Three model classes are named and distinguished: custom machine learning trained on each individual merchant's historical data rather than a shared generic model, graph network link analysis running over that merchant's dataset in real time to expose fraud rings and connections, and behavioural analysis tracking shopper actions across the whole journey.
The company argues its own case publicly, publishing a comparison of machine learning against rules based on testing it ran both as a merchant and as a vendor, and concluding that machine learning wins. Rules exist alongside the models rather than underneath them. Strip the models and there is no per merchant model, no graph, no behavioural layer and no product. The remaining asset would be an anonymised cross merchant lookup table, which the company treats as one signal among many rather than as the proposition.
Control sits with the customer by design and the company sells that as the point, describing the platform as highly customisable and pairing machine learning with what it calls robust rules rather than presenting the models as final. Configuration is framed around the customer's own risk appetite rather than a vendor default.
Ravelin Insights supplies the monitoring layer, offering performance pulse checks, investigation of granular transaction anomalies, and an artificial intelligence query builder that generates custom reports and dashboards, so a fraud team can interrogate what the system is doing rather than only receive its output. A human layer sits alongside, with the company stating its data scientists work with customers on continuous optimisation as priorities change.
Because no chargeback guarantee is offered, the merchant retains both the decision and the loss. What is not published is any specification of defaults, escalation thresholds, or what the platform does before a customer configures it.
Good architectural disclosure and no measurement at all. The company explains its modelling approach more openly than most, distinguishing custom models trained on a merchant's own historical data from generic models and stating why it believes the former are more accurate, describing graph link analysis over the merchant's dataset, and publishing its reasoning for choosing machine learning over rules based on its own testing.
Ravelin Insights gives the customer performance monitoring, anomaly investigation and custom reporting, so a merchant can measure outcomes for itself over time. None of that is a published performance figure. No accuracy rate, precision or recall measure, false positive rate, validation report, benchmark or monitoring statement was located for any model, and unlike several competitors in this lane there is not even a headline accuracy claim to interrogate. A reviewer here can understand how the system is built and nothing about how well it works.
The company publishes its own annual operating figures in unusual detail, which almost nothing else in this lane does. For 2025 it reports securing more than 3.5 billion transactions, serving 755.2 million unique shoppers, processing over 61.5 billion dollars in orders, and supporting more than 340 merchants accepting payments from customers in over 250 countries and territories.
Those are four independent quantities describing throughput, reach, value and customer count, published together as a year in review, and they let a buyer size the platform without asking. The February 2025 acquisition by Worldpay is an externally attested transaction advised by KeyBanc Capital Markets, and the acquirer's own scale, approximately 2.5 trillion dollars in annual payments volume, is a matter of public record. What is missing is the customer layer. No merchant is named anywhere, no case study with an outcome figure was located, and no fraud prevented, chargeback reduction or approval rate improvement is attributed to any identified customer.
This record gives the best answer in the lane to the question every competitor leaves open, and it does so architecturally rather than by promise. Ravelin separates two layers explicitly. Modelling is per merchant: custom machine learning is trained on that merchant's own historical data, and graph network link analysis runs over that merchant's own dataset, so one customer's model is not built from another's transactions.
Separately, a cross merchant lookup answers whether a shopper was seen as legitimate or fraudulent elsewhere, and the company states that database is fully anonymised and compliant with the General Data Protection Regulation. That is a bounded shared layer sitting beside a private modelling layer, rather than the undifferentiated consortium most vendors here describe.
Three things remain undocumented: whether a merchant can decline to contribute to the shared database, what anonymised means technically given the lookup must still resolve a returning individual, and how long shared records persist.
Contactability and instrument specificity are both better than the lane norm. A Data Protection Officer is reachable by dedicated email address and by full postal address in London, which means an individual or a reviewer has a named function to write to rather than a general enquiry form, and a separate European Union representative is published with its own address for post Brexit purposes.
The company states its role plainly as a Data Controller within the United Kingdom, and names five instruments it operates under rather than gesturing at compliance: the General Data Protection Regulation, its United Kingdom incorporation under the Withdrawal Act, the Data Protection Act 2018, the ePrivacy Directive and the Privacy and Electronic Communications Regulations. The right to lodge a complaint with a data protection authority is stated.
Developer documentation carries a dedicated privacy and security guide. What is absent is the processor detail: no data processing addendum, subprocessor list or retention schedule was located, and no supervisory authority is named specifically.
Three certifications held, with the credential test cleared on the elements that usually fail. ISO 27001:2022 is stated with the certifying body named, the British Assessment Bureau, and the standard's 2022 revision identified, which is more than most peers in this lane manage.
Payment Card Industry Data Security Standard certification is held, and PCI 3DS certification is held with its scope described precisely as covering the 3DS Server, Access Control Server and Directory Server functions. The strongest element is external verification: the company appears on the Visa Global Registry of Service Providers, a public listing maintained by the card network rather than by the vendor, so a buyer can confirm the payment card certification without asking anyone.
What separates this from the top grade is the absence of obtainable artifacts. No service organisation control report of any type exists, no ISO Statement of Applicability is published, and there is no trust centre, penetration test summary or downloadable certificate.
The standing here comes from certified roles inside a card scheme protocol rather than from a compliance claim. Ravelin holds Payment Card Industry 3DS certification, and the scope is stated precisely: it covers the 3DS Server, Access Control Server and Directory Server functions, which are defined roles within the EMV three domain secure architecture, with the Access Control Server sitting on the issuer side and the Directory Server on the scheme side.
A vendor certified to operate those components is inside the authentication rail rather than adjacent to it. The company additionally appears on the Visa Global Registry of Service Providers, a public listing a buyer can check independently. Its 3D Secure material describes deployment as meeting local regulations and card network requirements, which is the strong customer authentication obligation without naming the directive. Ravelin holds no financial licence itself, which is correct for a technology supplier, and no regulator appears as a counterparty.
Nothing this axis asks for was located. No error rate, false positive rate, confidence measure or calibration statement is published for any model. No fairness testing, disparate impact analysis or coverage statement exists. The per merchant training architecture arguably limits one bias pathway, since a merchant's models learn from its own population rather than importing patterns from unrelated customer bases, but the company never makes that argument and never tests it, so it cannot be credited as governance.
The cross merchant anonymised lookup runs the other way, carrying a prior fraud association about an individual into a decision at a merchant that has never seen them, and nothing describes how such an association is reviewed, aged out or corrected. Nothing states who approves a model change, what validation a retrained per merchant model passes before deployment, or how a customer is notified when model behaviour shifts.
No guarantee, indemnity, accuracy service level or falsifiable commitment was located. The platform scores and the merchant decides, so chargeback liability remains with the customer, and the transaction optimisation product improves acceptance rates without underwriting the outcome. For the individual the position carries a wrinkle created by the vendor's own privacy design.
Because the cross merchant database is stated to be fully anonymised, a shopper carrying a prior fraud association into a decision at a new merchant cannot practically exercise access or rectification rights against a record that holds no identifier tying it to them, so the anonymisation that limits their privacy exposure also removes the route by which they would correct an error in it. Nothing published describes notification, evidence disclosure, an appeal path, or how a disputed association is reviewed or aged out.
Two external data partners are named and both are identifiable and assessable: Ekata and Ethoca, which supply identity verification and card issuer dispute intelligence respectively and are both Mastercard businesses, so a buyer can trace what sits behind the identity and dispute signals and can check whether those sources already appear elsewhere in their own supply chain.
The internal chain is also characterised more clearly than most, since the company states that its custom models are trained on the merchant's own historical data, which identifies the primary training input as the customer's own rather than leaving it implicit, and separately identifies the anonymised cross merchant database as a distinct lookup layer. Card networks are described as returning data through the 3D Secure flow, identifying a further inbound source.
What is not disclosed is the rest: no subprocessor list exists, no cloud infrastructure provider is named despite hosting being acknowledged, and no model or foundation model provider is identified for any component.
The distinguishing integration is into the authentication rail rather than into commerce platforms. Certified 3DS Server, Access Control Server and Directory Server functions mean the platform operates components of the three domain secure flow itself, and the company describes leveraging the data card networks return through that flow to improve its own fraud decisions, which is a two way integration rather than a one way call.
Transaction optimisation automates payment flows to maximise acceptance and minimise fees, which sits in the payment path. Software development kits are offered alongside 3D Secure, public developer documentation is served at a dedicated domain including guides written specifically for payment service providers, and Ekata and Ethoca are named as integrated data partners. Distribution through the acquirer's payments network extends reach considerably. What is absent is any enumerated commerce platform or gateway connector catalogue, so a merchant cannot check before contact whether their stack is supported.
A cloud hosted platform, described as such by the company and its acquirer, with no private, single tenant or on premise option located. On residency nothing is published: no cloud provider, region, data centre or country of processing is named, no region selection is described, and no transfer mechanism appears.
The nearest thing to an infrastructure disclosure is an environmental one, with the company stating in its sustainability material that it prioritises partnerships with cloud providers committed to net zero emissions, which confirms third party hosting without identifying the host.
The gap matters for a United Kingdom company serving merchants whose customers sit in more than 250 countries and territories, and which publishes a European Union representative precisely because cross border data questions arise, yet states nowhere where the processing happens.
Nothing is published across two dedicated passes. No rate, tier, band, entry point, free tier or trial appears on the vendor's own surface or in any third party listing, and one directory records explicitly that trial access is not offered.
More unusually, no metering unit is disclosed either, so a buyer cannot tell whether the platform charges per transaction screened, per order, on gross merchandise value, per module or on a subscription, which puts this behind the competitors in this lane that withhold the figure while naming the basis.
The silence is conspicuous against the rest of the record, since this company publishes its annual transaction counts, shopper numbers, order value, merchant count and country coverage, names its certification body, and names its data partners. It discloses a great deal about what it does and nothing at all about what it costs.
Two buyer types are addressed explicitly rather than by implication, with the company stating it serves merchants and payment service providers, and the product set reflects both: fraud decisioning and abuse prevention for the merchant side, and 3D Secure infrastructure and transaction optimisation for the payments side. Geographic reach is stated concretely, with more than 340 merchants accepting payments from customers in over 250 countries and territories.
Product coverage extends past checkout into policy abuse, refund abuse, promotion and voucher abuse, account takeover and multi accounting, and marketplace and supplier collusion, the last reaching gig economy and delivery platforms where the risk sits between the platform and its suppliers rather than at the point of sale. Distribution now runs through an acquirer processing approximately 2.5 trillion dollars annually. What holds this below the top grade is the absence of any named customer in any segment and no evidence of sales into banking, insurance or capital markets.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No rate, tier, unit of sale, free tier or trial was located on the vendor's own surface or from any third party, and one directory records that no trial access is offered.
|
Undisclosed. Neither a rate nor a metering unit is published, which is a step behind the competitors in this lane that at least name what they charge against. The product is sold to two buyer types, online merchants and payment service providers, across a range the company describes as spanning startups to enterprises, and it is packaged as several distinct solutions covering payment fraud, policy and refund abuse, account takeover, promotion abuse, marketplace and supplier collusion, 3D Secure, and transaction optimisation, so a customer's cost plausibly depends on which of those they adopt as well as on volume. Since the February 2025 Worldpay acquisition the platform is positioned as a value added solution within a payments portfolio processing approximately 2.5 trillion dollars annually, which suggests pricing is increasingly negotiated alongside processing terms rather than as a separate software line. | No standalone data processing addendum or subprocessor list was located, but the privacy position is more concrete than most in this lane. A Data Protection Officer is reachable by dedicated email and full postal address in London, a separate European Union representative is named for post Brexit purposes, controller status is stated for the United Kingdom entity, and five instruments are named specifically: the General Data Protection Regulation, its United Kingdom incorporation under the Withdrawal Act, the Data Protection Act 2018, the ePrivacy Directive and the Privacy and Electronic Communications Regulations. The cross merchant database is stated to be fully anonymised. On assurance the company holds ISO 27001:2022 assessed by the British Assessment Bureau, Payment Card Industry Data Security Standard certification, and PCI 3DS certification, and appears on the Visa Global Registry of Service Providers, which a buyer can verify independently. | Not published and not disclaimed. No setup, onboarding, integration or professional services fee appears anywhere. Two elements of the delivery model would ordinarily carry cost and neither is priced. The platform is built on custom machine learning models trained on each merchant's own historical data rather than on generic models, which requires a data onboarding and training cycle before the models are useful. And the company states that its data scientists work alongside customers on continuous optimisation as fraud patterns and business priorities change, which is an ongoing professional services relationship rather than a support desk. Both are presented as part of the proposition rather than as chargeable extras, and no rate, inclusion boundary or engagement minimum is stated for either. | Vendor Published |
Two dedicated passes returned no figure from the vendor or from any third party. No rate, tier, band, unit of sale, free tier or trial appears anywhere, and one directory records explicitly that trial access is not offered. Nothing indicates whether the platform meters on transactions screened, orders processed, gross merchandise value, modules taken or seats, so unlike several competitors in this lane that withhold the number while naming the unit, this record leaves a buyer unable to model cost shape at all.
The absence sits oddly against how much else this company publishes, since it discloses its annual transaction, shopper, order value, merchant and country figures in detail, names its data partners, and names its certification body.
Pre emptive negative finding: following the Worldpay acquisition this product is increasingly sold as a value added service attached to payment processing, so any rate a buyer is quoted is likely to be bundled against processing economics rather than priced standalone, and a standalone figure surfacing from a reseller should be treated with that in mind.