Fraud Detection & Transaction Risk
S

SHIELD

SHIELD, trading as SHIELD AI Technologies Pte Ltd and formerly CashShield, is a Singapore headquartered device intelligence company founded by Justin Lie with roots going back to 2008. It occupies a different position from the order screening vendors it is compared against: SHIELD does not decide anything. It identifies the physical device behind an interaction and returns risk signals, and the customer's own systems make the call.

The core asset is SHIELD Device ID, a device fingerprint the company states identifies devices across app and web with over 99.9 percent accuracy even after deliberate manipulation, supported by continuous session profiling that detects emulators, virtual private networks, application cloning, application tampering and location spoofing, and by behavioural signals such as device orientation and swipe speed. More than 30 configurable risk thresholds let a customer set their own tolerances, and the company commits that all data the platform generates belongs to the customer to log, inspect or feed into their own models.

Coverage is stated at more than seven billion devices and 500 million user accounts. Delivery is through modular development kits for web, Android, iOS and React Native, server side integration, an alerting API, a unified dashboard and a Unity plugin the company describes as the first fraud prevention product on that asset store. Sector reach runs well beyond ecommerce into ride hailing, gaming, fintech, social platforms and marketplaces, with named customers including Alibaba, Razer, inDrive, Swiggy, Meesho, TrueMoney, BEAT and Buymed, and offices across Singapore, Jakarta, Bengaluru, Beijing, Berlin, London, San Francisco and Miami.

The published privacy policy names Amazon Web Services as its data storage subprocessor and addresses automated decision making by citing Article 22 of the General Data Protection Regulation directly.

Last VerifiedAugust 24, 2026
Compare SHIELD with other vendors
Founded
2008
Headquarters
Singapore
Website
shield.com
Categories
fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 8 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test is unusually clean because the product is an inference and nothing else. SHIELD Device ID exists to identify a physical device across sessions, applications and browsers, and the company states it does so with over 99.9 percent accuracy even after advanced manipulation.

That qualifier is the point: a fingerprint that survives deliberate spoofing, emulation, application cloning and virtual private network use cannot be a lookup against stored attributes, because the attributes are exactly what the adversary is changing. It has to be learned inference over a signal space.

Around it sit continuous session profiling, detection of emulators, tampering and location spoofing, and behavioural analysis of interactions as subtle as device orientation and swipe speed. The company brands the engine SHIELD AI, incorporates as SHIELD AI Technologies, and operates a Global Intelligence Network spanning a stated seven billion devices and 500 million accounts. Strip the models and there is no device identity, no session profile and no product, because unlike the guarantee sellers in this lane there is no underwriting business underneath to fall back on.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The architecture puts the decision with the customer and, unusually, the company says so in a binding document rather than a marketing page. The privacy policy states that SHIELD generates an automated risk score and that it is the merchant's own discretion to follow it and make an automated decision, citing Article 22 of the General Data Protection Regulation. So the vendor never refuses anyone; it supplies intelligence and the customer's own system acts.

Supporting that, more than 30 configurable risk thresholds across application and web let a customer set their own tolerances rather than accept vendor defaults, and the commitment that all generated data belongs to the customer means the signals behind any given verdict can be inspected after the fact. What is absent is specification of the defaults.

Nothing published describes what the thresholds are set to before a customer tunes them, what a given signal contributes to a risk verdict, or how a customer is notified when signal behaviour changes underneath their configuration. A customer holds the controls without being told where they start.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

A specific, falsifiable accuracy claim on the core capability, plus an architecture that lets a customer test it. The company states SHIELD Device ID identifies devices across application and web with over 99.9 percent accuracy even after advanced manipulation, and the adversarial qualifier is what makes the claim meaningful rather than decorative, since it names the condition under which device fingerprints normally fail.

More usefully for a model risk function, the commitment that all generated data belongs to the customer means the raw signals behind every verdict can be logged and validated against the customer's own realised outcomes over time, which is a stronger position than receiving only a score and far stronger than receiving only a verdict. More than 30 configurable thresholds make the operating point explicit and adjustable. What is missing is the documentation.

No methodology, population or measurement period accompanies the 99.9 percent figure, no false positive rate is published anywhere, and no validation report, model documentation or monitoring statement was located.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

The named customer set is the strongest asset here and it reaches markets no other vendor in this lane touches. Alibaba, Razer, inDrive, Swiggy, Meesho, TrueMoney, BEAT and Buymed span Chinese ecommerce, gaming hardware, ride hailing across emerging markets, Indian commerce and Southeast Asian payments, and several appear with attributed testimonials rather than as bare logos.

Scale is stated at more than seven billion devices and 500 million user accounts protected, and headcount is around 254 as of May 2026. One quantified outcome exists, a study with inDrive reporting 1,377 percent return on investment, which is a vendor commissioned figure and is treated as such. Two things hold this below the top grade.

Beyond that single study there are no quantified customer results, no fraud prevented figure, no false positive reduction and no approval rate movement, which the strongest records in this lane supply for several named customers each. And the funding record shows a Series B in June 2018 with nothing since, against reported totals that themselves disagree across sources at roughly 25.6 million and 31.7 million dollars, so eight years have passed without an external valuation event.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

Two published commitments here are better than the lane norm and they are separate from the privacy documentation. The first is data ownership: the company states that all data generated by the platform belongs to the customer, who may log it, inspect it, or feed it into their own models.

A signal vendor that hands over its output rather than retaining it as leverage has given up the usual lock in, and it also means a customer can audit what was produced about their users rather than taking a score on trust. The second is the permissions position: the company states it runs with a customer's existing user permissions, so deploying it does not require asking end users to grant anything new, which limits the expansion of consent that adding a fraud layer normally causes.

Against both sits the unexamined question that runs through this whole lane. The Global Intelligence Network pools device observations across a stated seven billion devices and every customer, so a device seen at one application informs the risk verdict at another, and nothing published states whether a customer can decline to contribute, how one customer's observations are separated from another's, or what the retained device record contains.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

One genuinely distinguished disclosure sits inside an otherwise ordinary document. The privacy policy addresses automated decision making by naming Article 22 of the General Data Protection Regulation directly and allocating the roles under it: the merchant is the data controller, SHIELD generates an automated risk score, and it is the merchant's own discretion whether to act on that score.

Almost nothing else in this lane engages the specific provision governing solely automated decisions about individuals, and doing so tells a buyer exactly where the obligation sits before they sign. Sections covering data sharing, data retention and transfer to third countries exist, and data subjects in the European Economic Area are given cookie controls at the point of collection. Beyond that the position is thin. No data processing addendum was located, only a privacy policy.

No supervisory authority is named. No retention period is stated in what was retrievable. No regime other than the General Data Protection Regulation is engaged, despite the company's centre of gravity being Southeast Asia and India, where Singapore, Indonesia and India all now have their own data protection statutes and none is mentioned.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Two dedicated passes located no certification, attestation, trust centre, penetration test summary or enumerated control framework held by this company. What exists is inherited rather than held: the privacy policy commits that any subprocessor must treat data to the same standards as SHIELD and comply with data protection requirements, names Amazon Web Services as the storage subprocessor, and directs the reader to that provider's compliance certifications.

Pointing at an infrastructure provider's certificates is a real disclosure about where the assurance comes from and it is not assurance about this vendor's own controls, which is what the axis asks for. Pre emptive negative finding, and an unusually important one here: searching for this vendor's security posture is actively hazardous because at least six unrelated companies trade under the name Shield, several of which do hold SOC 2 Type II and ISO 27001 and publish detailed security pages. A certification found under that name must be confirmed against the correct legal entity, SHIELD AI Technologies Pte Ltd, before it is credited to this record.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

A Singapore incorporated private company holding no financial licence, with no supervisory relationship, named regulator counterparty or regulatory approval located. The most specific regulatory engagement on the record is the treatment of Article 22 of the General Data Protection Regulation in the privacy policy, which is credited on the privacy and autonomy axes where its substance sits.

No payment card industry certification appears, which is consistent with the product not touching cardholder data directly. No named regulator appears as a customer or partner, no scheme membership or industry body affiliation was located, and the company makes no compliance claim against any Southeast Asian or Indian regulatory regime despite operating substantially in both. Nothing here counts against a technology supplier that is not expected to hold a licence, and nothing lifts the record above the floor either.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

A dedicated AI Information page exists in the site footer, which suggests the company has published something on this subject, and its contents were not retrievable in this session, so nothing in it is credited here. What was retrievable does not amount to governance. No error rate, false positive rate, confidence measure or calibration statement is published for any signal. No fairness testing, disparate impact analysis or coverage statement exists.

The exposure specific to this product is worth naming: device fingerprinting has a known and well documented tendency to misclassify shared, refurbished, rooted and older hardware, which correlates with lower income users and with particular markets, and this company operates heavily in exactly those markets across Southeast Asia and India. A device wrongly identified as manipulated does not get an explanation, and nothing published describes how such an error is detected or corrected. Nothing states who approves a model change or what validation a new signal passes before it starts affecting verdicts.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

There is no guarantee and structurally there could not be one, because this vendor never makes the decision that causes a loss. No accuracy commitment, indemnity, service level or falsifiable performance promise attaching to the signals was located, and the 99.9 percent device identification figure is a marketing claim rather than a contractual term. What lifts this above the floor is a disclosure that most vendors leave unstated.

By citing Article 22 of the General Data Protection Regulation and allocating the roles explicitly, the company tells both the merchant and, in a public document, the affected individual that the merchant is the data controller and the merchant makes the decision. That means an individual's rights under that article, including obtaining human intervention and contesting an automated decision, run against a named and reachable party rather than disappearing into a vendor chain.

It is a signpost rather than a remedy. SHIELD itself offers the affected person nothing: no notification, no visibility of the signals that flagged their device, no appeal and no correction path for a device wrongly assessed as manipulated.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

One subprocessor is named and, more unusually, the customer is given a say over future ones. The privacy policy identifies Amazon Web Services as the subprocessor engaged for data storage and points to that provider's own privacy terms and compliance certifications, so a buyer can trace where their data physically rests and assess the operator independently.

Beyond the naming, the policy states that SHIELD may appoint a subprocessor only with the approval of merchants, and that any subprocessor must handle data to the same standards and comply with data protection requirements including the General Data Protection Regulation. An approval right over supply chain changes is a governance control rather than a disclosure, and no other vendor graded in this lane offers one. What is not disclosed is the intelligence chain.

No third party data source, device intelligence provider, telemetry supplier or model provider is named for any component, and the Global Intelligence Network is described as a shared asset without any statement of what feeds it beyond the customer base itself.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Developer first and unusually wide across runtime environments, narrow across business systems. Modular development kits ship for web, Android, iOS and React Native, server side integration is supported, alerts stream over an API into a unified dashboard, and the company states integration takes minutes rather than weeks with no additional code required.

A Unity plugin extends the reach into game clients and is described as the first fraud prevention product published on that asset store, which is a genuine distribution surface rather than a claim. Availability through the Amazon Web Services marketplace gives enterprise buyers a procurement path against existing cloud commitments.

The design intent is explicitly to feed other systems, with the company positioning the output as enriching a customer's existing risk models and data engines rather than replacing them. What is absent is any connector to the business systems a fraud team actually operates: no commerce platform, payment gateway, case management or identity platform integration is named anywhere, which is the layer that separates the strongest records in this lane from this one.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Hosted software consumed through embedded development kits and an API, with no private, single tenant or on premise option located. One residency relevant fact is published and it is more than most in this lane manage: the privacy policy names Amazon Web Services as the subprocessor engaged for data storage and directs readers to that provider's own compliance certifications, so the infrastructure operator is identified rather than left implicit.

That naming is credited on the supply chain axis. What it does not supply is a residency position. No region, availability zone, data centre or country of processing is stated, no region selection is offered to customers, and while the privacy policy contains a section headed transfer of data to third countries its terms were not retrievable.

The gap matters for a company whose customers concentrate in Southeast Asia and India, where several jurisdictions now impose localisation or transfer conditions, and whose European customers need a stated mechanism rather than an inference.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

Nothing is published across two dedicated passes. No rate, tier, unit of sale, free tier or trial appears on the vendor's own surface. The Amazon Web Services marketplace listing, which is the one channel where a published price would normally be forced, is configured as a private offer routing to a sales address rather than carrying any figure. A major software marketplace records explicitly that the vendor has not provided pricing information.

There is no stated metering basis either, so a buyer cannot tell whether this is priced per device, per session, per active user, per API call or as a platform fee. One genuine commercial commitment does exist and is worth recording even though it is not a price: the company states that all data the platform generates belongs to the customer, to log, inspect or use in their own models.

That removes the lock in that usually accompanies a signal provider, since a customer leaving keeps the intelligence already produced, and it is a more meaningful commercial term than most vendors in this lane disclose. It is still not a price.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

The broadest sector and geographic reach in this lane, and it comes from selling a component rather than a decision. Because SHIELD supplies device signals rather than an order verdict, the buyer is any digital business with an application, and the named customer set reflects that: ride hailing through inDrive and BEAT, gaming through Razer and the Unity ecosystem, marketplaces and ecommerce through Alibaba, Swiggy and Meesho, payments through TrueMoney, and healthcare supply through Buymed.

Product lines extend past fraud prevention into network security, credit intelligence and identity verification. Geographic depth is genuine rather than asserted, with offices across Singapore, Jakarta, Bengaluru, Beijing, Berlin, London, San Francisco and Miami, giving Southeast Asian and Indian coverage that no competitor here demonstrates. What holds this below the top grade is that the buyer remains a consumer facing digital business.

There is no evidence of sales into banking operations, insurance, capital markets or regulatory supervision, and the credit intelligence and identity lines are named without any customer evidence behind them.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No rate, tier, free tier or trial appears on the vendor's surface, and the Amazon Web Services marketplace listing is a private offer routing to a sales contact.
Undisclosed. Neither the rate nor the metering unit is published, which is a further step back than the competitors in this lane who withhold the figure but state what they charge against. The one commercial term the company does publish is unusual and works in the buyer's favour: all data generated by the platform belongs to the customer, who may log it, inspect it or use it in their own models. For a signal provider that materially changes the commercial relationship, because the intelligence already produced remains with the customer if they leave, removing the accumulated data lock in that normally makes switching costly. The product is also positioned as complementing rather than replacing a customer's existing risk engine, so it is bought as a component alongside other spend rather than as a platform replacing it. No data processing addendum was located, only a privacy policy, but that document carries two terms an enterprise reviewer would otherwise have to negotiate for. Amazon Web Services is named as the subprocessor engaged for data storage, with a pointer to that provider's own compliance certifications, and the policy states SHIELD may appoint a subprocessor only with merchant approval and that any subprocessor must meet the same data handling standards including under the General Data Protection Regulation. The policy also addresses automated decision making directly, naming Article 22 of that regulation and allocating the merchant as data controller with sole discretion over whether to act on SHIELD's risk score. No supervisory authority is named, no retention period was retrievable, and no regime beyond the European one is engaged despite the customer base concentrating in Southeast Asia and India. Not published and not disclaimed. No setup, onboarding, integration or professional services fee appears anywhere. Integration effort is genuinely low by design, with modular development kits for web, Android, iOS and React Native, server side integration, and the company stating deployment takes minutes rather than weeks with no additional code required, so a customer's own engineering cost should be modest even though the vendor charges are unknown. A Unity plugin is distributed through that platform's asset store. Availability through the Amazon Web Services marketplace may allow some buyers to draw the spend against existing cloud commitments, though as a private offer the terms are negotiated rather than listed. Vendor Published

Two dedicated passes returned no figure of any kind. The vendor's own surface carries no rate, tier, unit of sale, free tier or trial. The Amazon Web Services marketplace listing, the one channel that normally forces a published price, is configured as a private offer directing buyers to a sales address. A major software marketplace records explicitly that this vendor has not supplied pricing information.

Unusually, not even the metering basis is disclosed, so a buyer cannot tell whether the product is charged per device, per session, per monthly active user, per API call or as a platform subscription, which makes even rough budgeting impossible before contact. Two pre emptive negative findings.

First, searching for this vendor's pricing is hazardous: at least six unrelated companies trade under the name Shield, and both a distinct fraud product called Fraud Shield and Amazon's own AWS Shield service surface with published rates that have nothing to do with this company.

Any quoted figure must be confirmed against SHIELD AI Technologies Pte Ltd. Second, the absence here is consistent rather than an oversight on one page, so discovering an unpublished rate later should not move the commercial transparency grade unless the vendor itself publishes it.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746