Riskified
Riskified is an ecommerce fraud and risk intelligence company founded in 2013 by chief executive Eido Gal and his co-founder, incorporated in Israel as Riskified Ltd. and listed on the New York Stock Exchange under RSKD. The commercial arrangement is what distinguishes it: under the flagship Chargeback Guarantee, Riskified returns an approve or decline decision on each order in under a second, the merchant is charged only on approved orders, and Riskified reimburses the merchant in full for any fraud chargeback on an order it approved.
The company therefore carries the cost of its own model errors on its own balance sheet, audited and reported to the Securities and Exchange Commission. Around the guarantee sit Adaptive Checkout, which replaces binary approve and decline with checkout flows graduated to each order's risk rather than blocking outright; Account Secure, covering account takeover prevention, fake account prevention and account recovery, described as fully automated; Policy Protect, launched in 2024 for refund and return abuse; and Dispute Resolve for chargeback representment.
Decisions draw on machine learning models with custom engineered features and identity and linkage intelligence, fed by the merchant's own data and by a cross merchant network. Delivery is a REST and webhook API with software development kits for PHP, Java and .NET, device intelligence kits for iOS, Android, React Native and Unity, and native connectors for Shopify including headless, Adobe Commerce, Salesforce Commerce Cloud, SAP Commerce, commercetools, VTEX, Adyen, Braintree, PayPal and Stripe.
The 2025 annual report on Form 20-F records revenue of 344.6 million dollars, up five percent, and a net loss of 27.6 million dollars, narrowed from the prior year, and names Maxmind, Ekata and Emailage as third party data sources feeding the models.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
The removal test resolves against the balance sheet rather than the marketing, which is unusual and decisive. Riskified charges only on orders it approves and reimburses the merchant in full for any fraud chargeback on an approved order, so every false negative is paid for out of its own revenue. A business structured that way cannot be a rules engine with a model attached, because the underwriting would not hold.
The 20-F confirms it from the other direction: model performance appears throughout the risk factors as a principal business risk, covering the efficiency and accuracy of the machine learning models, their continued proper operation, their behaviour in down cycle economic conditions, and the effect on model accuracy when merchant or third party training data degrades.
Product material describes machine learning models with custom engineered features plus identity and linkage intelligence returning decisions in sub second analysis, and the company states it employs hundreds of researchers, developers and data scientists. Strip the models and there is no product and no insurable proposition behind it.
Full automation is not a side effect here, it is the product. The proposition is the removal of manual review: decisions return in under a second on every order, and the company states that all three Account Secure components, covering account takeover prevention, fake account prevention and account recovery, are fully automated so that a team spends no time setting rules or responding to alerts. Two things point the other way and both are real.
The company states it provides context for every decision made by its models and builds dashboards for teams to manage fraud and customer interactions, which is a published per decision explanation commitment rather than a black box.
And Adaptive Checkout is a genuine design level mitigation, moving away from what the company itself calls the traditional binary approve or decline toward graduated friction applied selectively to higher risk orders, so a borderline shopper meets a step up rather than a wall. What is absent is control. Nothing published describes a merchant override, a configurable threshold, a review queue, or any path by which a decision is reconsidered before it takes effect. Explanation after the fact is not oversight.
The structural disclosure here is stronger than the documentary disclosure, and it is worth more than it first appears. Because the company reimburses chargebacks on orders its models approved, model accuracy converts directly into cost of revenue, and the resulting gross profit and cost to benefit ratio are reported in audited filings every quarter.
A model risk reviewer therefore has a continuously published, externally attested proxy for how the models are performing, which is something no privately held peer in this lane offers at any price. The 20-F reinforces it by treating model efficiency, accuracy and continued proper operation as principal risks and by naming the conditions under which they degrade. Third party data dependencies are named. What is missing is the documentary half.
No validation report, error rate, precision or recall figure, benchmark, model card or monitoring statement was located, and the published performance claims of two to three times stronger detection and up to 20 percent higher approval rates carry no methodology, baseline or population, so they cannot be checked. A proxy that moves with accuracy is not the same as a measurement of it.
Audited financial statements filed with the Securities and Exchange Commission are the strongest evidence this axis can receive, and they exist here because the company is listed on the New York Stock Exchange as RSKD. The annual report on Form 20-F for the year ended 31 December 2025 records revenue of 344.6 million dollars, up five percent from 327.5 million, and a net loss of 27.6 million dollars, narrowed from 34.9 million.
Those figures are attested rather than asserted, and the same filing discloses the countervailing facts a buyer needs, naming merchant concentration, dependence on ecommerce transaction volumes and reliance on continued use of fraud prone payment methods as risks to that revenue.
Commercial evidence is named: Finish Line and Lastminute.com appear as customers with published outcomes, a merchant reports authorisation rates reaching about 95 percent with fewer than ten chargebacks across six months, and the company reported a 100 percent renewal rate among its top contracts in the first quarter of 2025 with a majority of new clients that quarter based outside the United States. Vendor performance claims of up to 20 percent higher approval rates and two to three times stronger fraud and abuse detection carry no published methodology and are treated here as marketing.
The cross merchant network is the whole competitive advantage and it is disclosed as a benefit rather than governed as a boundary. The company states that Adaptive Checkout draws on hundreds of millions of data touchpoints from its global merchant network, and that the Account Secure models are supplied with a user's transaction history both at the merchant's own store and across that network.
The arrangement means a shopper's behaviour at one retailer shapes whether a competing retailer approves them, and that a merchant's own customer data improves decisions for other merchants including rivals in its category. That may well be the right design for a shared fraud utility, and the network effect is precisely why the guarantee is underwritable. Nothing published governs it.
No statement describes whether a merchant can decline to contribute, how one merchant's data is walled from another's view, what a consumer's linkage record contains, how long it persists, or what happens to it when a merchant leaves. The 20-F acknowledges dependence on merchant data for model accuracy without addressing the reciprocal question.
The exposure is large and the published position is thin. This platform ingests consumer identity, device, behavioural and purchase history at the point of checkout, links it to a persistent identity, and carries that linkage across a network of merchants, which is a richer consumer profile than most vendors in this index assemble. Against that, no data processing addendum, subprocessor list, retention schedule or named supervisory authority was located.
What does exist comes from the filing rather than from a privacy page: the 20-F names the ability to comply with evolving data protection, privacy and security laws, and the ability to protect the information of merchants and consumers, among its principal risk factors, and it names Maxmind, Ekata and Emailage as third party sources feeding the models, which at least identifies where some consumer data originates.
A listed company carries mandated disclosure obligations a private peer does not, and that is worth something, but risk factors written for investors are not processing terms a compliance officer can review before signing.
Two dedicated passes located no certification, attestation, trust centre, penetration test summary or enumerated control framework. No SOC 2 report, ISO 27001 certificate or Payment Card Industry attestation was found published or referenced, which is a conspicuous absence for a vendor sitting inline in the checkout path at enterprise merchants, since those merchants carry their own card industry obligations and will have imposed assurance requirements on this supplier as a condition of integration.
The assessments therefore almost certainly exist and are not published. What partly offsets the silence is a regulatory floor a private peer does not have: as a listed registrant the company must disclose material cybersecurity risk management and governance in its annual report, and the 20-F names cybersecurity threats and cloud provider reliance among its principal risks. That is mandated disclosure about exposure, not evidence of controls.
Pre emptive negative finding: a security page describing encryption and access control in prose would not move this grade. A named auditor with a scope statement, or a published attestation, is what would.
Standing rests on securities regulation and on one named payments instrument. As a foreign private issuer listed on the New York Stock Exchange, Riskified Ltd. is a Securities and Exchange Commission registrant filing an annual report on Form 20-F with audited consolidated financial statements, which is a supervisory relationship with real consequences for what it may claim in public.
On the product side the company builds explicitly against the second Payment Services Directive, stating that its platform performs frictionless transaction risk analysis on every order and is compliant with the six regulatory requirements governing that exemption from strong customer authentication, and it guarantees liability on exempted, reclaimed and out of scope volume.
Naming the specific exemption regime rather than gesturing at compliance is the useful part, because a European merchant can check it. The 20-F additionally names compliance with lending regulation and oversight and the development of regulatory frameworks for machine learning and artificial intelligence among its risk factors. The company holds no financial licence, which is correct for a technology supplier, and no supervisory authority approves the models themselves.
The filing contains more candour about model failure than most vendors ever publish, and it still is not governance. The 20-F names specific mechanisms by which the models go wrong: that inaccurate information supplied by a merchant may cause the company to inaccurately link a legitimate order with other fraudulent orders, that headless commerce fragments consumer data points across sources in a way that may affect model accuracy, that the models may fail to detect fraud accurately in down cycle economic conditions, and that inaccurate third party training data degrades them.
The false linkage admission is the important one, because it names a harm that lands on an innocent shopper rather than on the merchant. But these are risk factors written for investors about earnings exposure, not a governance programme written for buyers. No error rate, false positive rate or confidence measure is published. No fairness testing, disparate impact analysis or demographic coverage statement exists. Nothing describes who approves a model change, what review a new model passes, or how a wrongly linked shopper is unlinked.
The liability question is answered financially rather than contractually. Under the Chargeback Guarantee, when a model approves an order that turns out to be fraudulent, Riskified reimburses the merchant the full amount, and the company states that the merchant pays only on approved orders and that it guarantees approval rates and covers any chargebacks. The cost of every false negative therefore lands on the vendor's own profit and loss rather than the buyer's.
A merchant describes the claim process as routine, submitting documentation through the platform and being reimbursed, and Dispute Resolve extends the same posture into representment. One feature distinguishes this from other guarantee sellers and is recorded here rather than priced into the grade: because the company is a Securities and Exchange Commission registrant, the losses absorbed under the guarantee flow into audited financial statements, so a buyer can verify that the vendor actually pays rather than relying on the promise that it will.
That is a real difference in checkability from a privately held guarantee vendor. It is held at B for consistency with how the chargeback guarantee model is graded elsewhere in the ecommerce merchant lane; if the lane is ever rescoped so that externally attested liability outranks contractual liability, this is the record that moves first. The gap that keeps it off the top grade regardless is who is covered. The guarantee runs to the merchant and nothing runs to the shopper.
A legitimate customer falsely declined, or wrongly linked to fraudulent orders through the mechanism the 20-F itself describes, is not told, cannot see the evidence, has no appeal route and cannot reach the company that decided. Adaptive Checkout softens that by substituting graduated friction for a hard block on some orders, which reduces the harm without creating a remedy.
Three external data suppliers are named, and they are named in a document filed with the Securities and Exchange Commission rather than on a marketing page: Maxmind, Ekata and Emailage are identified as third party data sources whose data feeds the machine learning models, including for evaluating transactions for potential fraud.
Naming suppliers in a filing carries liability for the accuracy of the statement, which makes it the most reliable form this disclosure takes, and it lets a buyer trace what sits behind an identity signal. The filing goes further than most by disclosing the dependency risk explicitly, stating that if access to those sources is disrupted the ability to evaluate transactions and verify consumer data would be compromised, and that inaccurate third party training data degrades the models.
The merchant network is identified as the other major input. What is not disclosed is the rest of the chain. No cloud infrastructure provider is named despite reliance on major cloud providers being a stated risk factor, no subprocessor list exists in any document, and no model or foundation model provider is identified for any component. Use of open source software is disclosed as a risk without any inventory attached.
This is an enumerated connector catalogue rather than a partner logo strip, and it covers both halves of the merchant stack. The developer surface at developers.riskified.com publishes seven APIs over REST and webhooks with HMAC-SHA256 request authentication, spanning pre authorisation and post authorisation order review, strong customer authentication and PSD2 optimisation, account integrity events covering login, password reset and customer create and update, claim adjudication for refund and return abuse, and a one time password service.
Official software development kits ship for PHP, Java and .NET, with Beacon device intelligence kits for iOS, Android, React Native and Unity. Commerce platform connectors are native for Shopify including headless deployments, Magento and Adobe Commerce, Salesforce Commerce Cloud, SAP Commerce and Hybris, commercetools and VTEX.
Separately, Chargeback Gateway Integration connectors reach the payment layer at Adyen, Braintree, PayPal, Shopify Payments and Stripe, which is what allows the guarantee to reconcile against the acquirer rather than only against the merchant's order record. Depth on both the commerce side and the payments side, named and documented, is what earns the top grade.
Delivery is hosted software only, consumed as a sub second API call in the checkout path, and no private, single tenant or on premise option was located. On residency the published position is essentially absent. The 20-F names third party providers of cloud based infrastructure and reliance on major cloud providers among its risk factors, which confirms the dependency exists without identifying the provider, the regions or the failover arrangement.
No data centre, country, region selection or residency commitment appears anywhere, and no transfer mechanism is described for European consumer data despite the company selling explicitly into the European regime through its PSD2 transaction risk analysis product.
A vendor whose decision sits inline in the checkout path, processing European consumer identity and device data under an instrument it names by number, has a clear reason to publish where that processing happens and has not done so.
No rate card, percentage or list price appears anywhere across two dedicated passes. What is published instead is the thing most vendors in this lane hide, which is the commercial model and where the risk sits: the merchant pays only on orders Riskified approves, Riskified guarantees approval rates, and Riskified absorbs the chargeback on any approved order that turns out to be fraudulent.
A buyer therefore knows the unit of sale, knows the fee is contingent on a decision going their way, and knows the vendor loses money when its own model is wrong, all before contact. Being a public company adds a second route: revenue and the cost to benefit ratio are disclosed in the 20-F, so an effective blended take rate against gross merchandise volume is derivable from filings rather than guessed at.
The filing also lists limited experience with respect to pricing and changes to prices and pricing structure among its own risk factors, which is a candid admission that the model is still moving. Derivable is not published, and that is what holds this below the top grade.
The buyer is one type, the enterprise online merchant, and the coverage within it is broad without ever leaving it. Named verticals and customers span athletic and footwear retail through Finish Line and travel through Lastminute.com, with fashion, luxury, tickets, digital goods, money transfer and marketplaces described across the material. Payment method coverage extends past cards to ACH, open invoices and digital wallets, which matters because guarantee economics differ by rail.
Platform reach is wide through native connectors for Shopify including headless deployments, Adobe Commerce, Salesforce Commerce Cloud, SAP Commerce, commercetools and VTEX. Geographic expansion is evidenced rather than claimed, with a majority of new first quarter 2025 clients based outside the United States and stated movement into Asia Pacific and the Americas beyond the US. What caps this is that the segment is singular in a way the axis is built to penalise.
This vendor does not sell to banks, insurers, regulators or capital markets firms, and the 20-F names merchant concentration as a live risk, so breadth of vertical inside one buyer type sits alongside dependency on that same buyer type. Graded to match the ecommerce merchant lane rather than the multi segment vendors above it.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Priced as a percentage of approved order value under a performance model in which the merchant pays only on orders Riskified approves and Riskified reimburses fraud chargebacks on those orders. No percentage, floor, minimum or tier is published.
$0 baseline
|
Performance based and contingent on the decision. The merchant is charged only on orders Riskified approves, so a declined order generates no fee, and the company guarantees approval rates and reimburses the merchant in full for fraud chargebacks on any order it approved. That structure makes the vendor the residual risk holder for its own model errors rather than the merchant, and it is the reason the pricing is negotiated per merchant: the rate has to be underwritten against that merchant's category, average order value, geography, payment mix and fraud profile. The unit of sale is therefore a percentage of approved order value rather than seats, API calls or transactions screened, and no rate card can exist because each rate is an underwriting decision. Cross selling runs through separately packaged products around the guarantee, none carrying a published price. | No data processing addendum, subprocessor list or published data protection terms were located. This is the notable gap in an otherwise unusually disclosed commercial position, because the platform sits inline in the checkout path ingesting consumer identity, device, behavioural and purchase data and carrying the resulting linkage across a cross merchant network. What exists instead is regulatory disclosure rather than contractual terms: the annual report on Form 20-F names compliance with evolving data protection, privacy and security laws and protection of merchant and consumer information among principal risk factors, and names Maxmind, Ekata and Emailage as third party data sources feeding the models. A European merchant buying the PSD2 transaction risk analysis product will be negotiating processing terms and transfer mechanisms from scratch, since none is published. | Not published and not disclaimed. No setup, onboarding, integration or migration fee appears anywhere. The integration burden is genuinely low by design, since native connectors ship for Shopify including headless, Adobe Commerce, Salesforce Commerce Cloud, SAP Commerce, commercetools and VTEX, official software development kits ship for PHP, Java and .NET, and Chargeback Gateway Integration connectors reach Adyen, Braintree, PayPal, Shopify Payments and Stripe, so most merchants connect through an existing platform rather than a custom build. Dispute Resolve, Policy Protect, Account Secure and Adaptive Checkout are packaged as separate products around the Chargeback Guarantee and no incremental pricing is stated for any of them. | Vendor Published |
Two dedicated passes returned no rate from the vendor or from any third party listing. The finding is that the commercial model is disclosed with unusual precision while the number is not disclosed at all, which is the reverse of the usual pattern and materially more useful to a buyer than a contact form.
A prospective merchant knows before any contact that the fee attaches only to approved orders, that approval rates are guaranteed, and that the vendor absorbs the chargeback when its own model wrongly approves, which tells them where the risk sits and how the incentive is aligned. Two further routes narrow the gap.
As a listed registrant the company reports revenue and its cost to benefit ratio in audited filings, so an effective blended take rate against gross merchandise volume is derivable rather than guessed. And the 20-F candidly lists limited experience with respect to pricing and changes to prices and pricing structure among its own risk factors, which tells a buyer the model is still moving and that negotiated terms are likely.
Pre emptive negative finding: a third party review site quoting a Riskified percentage should not be treated as a published rate, since pricing is negotiated per merchant against risk profile, category and volume, and no single figure would be true across merchants.