Sift
Sift, formerly Sift Science, sells fraud decisioning to business to consumer digital companies and takes the opposite commercial position to the chargeback guarantee vendors it competes with. Rather than assuming liability and returning a verdict, Sift returns a real time risk score on every event and leaves the decision with the customer, arguing in its own marketing that opaque outsourced decisioning creates blind spots and erodes visibility. The customer keeps chargeback liability and gets control in exchange.
Scoring runs across the whole user journey rather than checkout alone, covering account creation, login, transactions, content posting, disputes and custom events, and the company states its models draw on more than 16,000 signals and more than a trillion events annually from a network it puts at 34,000 sites and applications. Three product lines sit on that engine: Payment Protection for transaction fraud and chargebacks, Account Defense for fake accounts and account takeover, and Content Integrity for spam, scams and fraudulent reviews.
Only the first two are graded here, since content moderation for social platforms and user generated content sits outside financial services. Around the engine sit an analyst console with review queues, automated workflows, a rules builder for real time strategy changes, a benchmarking product comparing a customer's fraud metrics against the network, and the option to feed the Sift score into a customer's own risk models. Assurance is documented through a trust centre at trust.siftscience.com, carrying ISO 27001:2022 certification and a SOC 2 Type II report renewed annually, with Coalfire named as the auditor on the company's own announcement. Named customers include Twitter, McDonald's, DoorDash, Wayfair, Twilio and Alaska Airlines.
Capability Axes
Capability grades
15 of 15 axes rated · 7 graded A or B
The product is the score, so the removal test resolves immediately. Sift returns a real time risk assessment on every event across account creation, login, transaction, content posting and custom events, and the company describes an ensemble of custom predictive models rather than a shared rulebook, with per customer models trained on that customer's own outcomes alongside the network.
Scale supports the claim: more than 16,000 signals feeding scoring, more than a trillion events annually, and a stated network of 34,000 sites and applications learning from hundreds of millions of positive and suspicious events each day. The company describes transforming a single data point such as an email address into hundreds of derived signals covering similar addresses, disposable domains and address age, which is feature engineering rather than lookup.
It also positions explicitly against what it calls checkbox machine learning and reactive rules based competitors. Strip the models and nothing remains, because unlike the guarantee vendors in this lane there is no liability product underneath to fall back on and no verdict to sell.
This is the strongest oversight construction in the ecommerce fraud lane and the company sells it as the differentiator rather than burying it. The architecture keeps the decision with the customer: Sift returns a probability score and the customer decides, which the company contrasts explicitly with what it calls opaque outsourced decisioning that creates blind spots and erodes visibility. Four mechanisms sit on top of that.
An analyst console with review queues puts a human in the loop on flagged events by design rather than by exception. A rules builder lets a customer author and change risk logic in real time rather than requesting a vendor change. Automated workflows let repetitive routing be delegated deliberately, so the customer chooses what is automated. And the score can be fed into the customer's own risk models, meaning the vendor's output becomes an input to a decision the customer owns entirely.
Business logic can block, accept, or dynamically add and remove friction by risk level rather than issuing a binary verdict. Held at the same grade as the other strong records in this lane for consistency; what would move it is a published specification of what the defaults do before a customer configures anything.
The score export architecture is what earns this, and it is a structural answer rather than a documentary one. Because Sift returns a probability score that the customer can feed into their own risk models rather than a verdict they must accept, a customer's model risk function can hold the vendor's output as one input among several and validate it against their own realised outcomes over time.
That is a materially better position than a black box approve or decline, where the reviewer has nothing to test. Supporting disclosure is real if thin: an ensemble of custom predictive models is described rather than a single scorer, per customer models are stated, the signal count is given at more than 16,000, and the derivation of secondary signals from a single primary data point is explained by example. The benchmarking product supplies external comparison data.
What is absent is the documentary half entirely. No validation report, accuracy figure, precision or recall measure, error rate, benchmark result or monitoring statement was located for any model, and the signal count is a scale claim rather than a performance measure.
The customer names are as strong as any in this lane and the outcome evidence behind them is not. Twitter, McDonald's, DoorDash, Wayfair, Twilio and Alaska Airlines all appear as named customers, which is a set spanning social platforms, quick service restaurants, delivery marketplaces, home retail, communications infrastructure and aviation, and those are companies with the procurement rigour to make the reference meaningful.
Scale is stated at 34,000 sites and applications and more than a trillion events annually. An Alaska Airlines case study is published. Peer review volume is substantial, with several hundred reviews on the major software marketplaces averaging above four and a half out of five. What is missing is the quantified outcome.
No named customer result with a revenue, loss reduction, approval rate or chargeback figure attached was located, which is the evidence class that separates this from the top of the axis, and the company is privately held so no audited financial disclosure exists either. Named logos at scale, without a number behind any of them.
The global network is the asset and the reciprocity question is unanswered, which is the consistent failure across every vendor in this lane. The company describes an unrivalled global data network learning from hundreds of millions of positive and suspicious events each day across 34,000 sites and applications, which necessarily means an end user's behaviour at one customer shapes the score they receive at another, including at that customer's competitors.
It is disclosed as the central benefit and never governed as a boundary. Nothing published states whether a customer can decline to contribute events to the shared network, how one customer's data is separated from another's view, what the retained end user profile contains, how long it persists, or what happens to contributed data when a customer leaves.
The trust centre asserts strict data governance and that end user identities remain secure, which addresses confidentiality against outsiders rather than the question of what the network does with the data internally.
A structured place to look exists and its contents could not be read. The trust centre at trust.siftscience.com is built on a dedicated vendor review platform and states that everything needed to complete a security and privacy review can be found there, describing a privacy first posture with strict data governance and privacy controls intended to keep customers' end user identities secure.
That is the right architecture and it is more than a policy page, but the substantive artifacts sit behind the portal rather than in public, and across this session's retrieval no data processing addendum, subprocessor list, retention schedule, named supervisory authority or specifically named privacy regime was obtainable.
The exposure is significant enough to want them: this platform ingests behavioural, device and transactional data on end consumers across 34,000 sites and retains it as a persistent identity across that network. Graded on what a buyer can actually read before making contact, which for privacy is a claim about a portal rather than a document. A reviewer who requests portal access will likely find more.
A genuine trust centre exists at trust.siftscience.com, built on a dedicated vendor security review platform, and the company states it holds everything a buyer needs to complete a security and privacy review. Two credentials are named on it: ISO 27001:2022 certification and a SOC 2 Type II report, described as the technical proof behind a defence in depth strategy.
The credential test is cleared unusually well on the SOC 2 because the company published its original attestation announcement naming Coalfire as the third party auditor, and separately published a renewal announcement describing new controls added in the following year, so a buyer has the auditor's name, the type, and evidence of an annual cadence rather than a one time badge. Earlier disclosure also names regular third party security assessments and code review practice.
What separates this from the top of the axis is that no report is downloadable without contact, no scope statement or trust services criteria are enumerated, no penetration test summary is offered, and no payment card industry certification appears, which is a notable absence for a vendor scoring payment transactions.
Privately held, holding no financial licence, with no supervisory relationship, named regulator customer or regulatory approval located. Compliance is asserted generally rather than against named instruments: the company states it complies with data protection regulations without identifying which, and unlike European focused peers in this lane it claims no compliance with any named payments directive or transaction risk analysis exemption regime.
The credentials it does hold, ISO 27001:2022 and SOC 2 Type II, are security assurance rather than regulatory status and are credited on the security axis where their evidence sits. Availability through a major cloud provider's commercial marketplace is a procurement channel rather than a supervisory relationship. Nothing here is a deduction for a technology supplier, which is not expected to hold a licence, but nothing lifts the record above the floor either.
The architecture is more transparent than its competitors and the governance disclosure is not. Exposing a probability score rather than a verdict is itself a meaningful transparency choice, because a customer can see how confident the model is and where a decision sits relative to their own threshold, which a binary approve or decline conceals. The benchmarking product goes slightly further by letting a customer compare their own fraud metrics against aggregate network figures.
Neither is governance. No error rate, false positive rate, precision measure or confidence calibration is published for any model. No fairness testing, disparate impact analysis or coverage statement exists, which matters because the product decides whether individual consumers may open accounts, log in or transact across 34,000 sites, so a systematically mis scored population would meet friction everywhere at once. Nothing describes who approves a model change, what validation a new model passes before deployment, or how a customer is told when scoring behaviour shifts underneath them.
There is no financial guarantee and the company does not pretend otherwise, which is a deliberate commercial position rather than an omission. Sift scores and the customer decides, so chargeback liability stays with the customer, and the trade the vendor offers in return is control and visibility rather than indemnity. No accuracy commitment, indemnity, service level on decision quality or falsifiable performance promise was located anywhere.
That places this below the guarantee sellers in this lane, who put their own money behind their models. What keeps it above the floor is that the architecture leaves recourse machinery in the customer's hands: a flagged event lands in a review queue where a human can overturn it, thresholds are customer set rather than vendor imposed, and because the output is a score rather than a verdict a borderline case can be routed to friction or review instead of refused.
For the end consumer the position is the same as everywhere else in this lane. Someone scored as high risk is not told, cannot see the evidence, and has no route to the company that produced the score, though at least the decision that affected them was made by the business they were dealing with.
Counts stand where names should be, in both directions. On the input side the company states its scoring draws on more than 16,000 signals and an unrivalled global data network processing more than a trillion events annually, and identifies none of the external sources contributing to either.
No third party data supplier, identity provider, device intelligence vendor or enrichment service is named anywhere, so a buyer cannot assess the quality of any input, cannot check whether a source they have already rejected elsewhere is feeding their scores, and cannot judge concentration risk if multiple signals resolve to one underlying provider.
No subprocessor list was obtainable in public, no cloud infrastructure provider is named directly, and no model or foundation model provider is identified for any component. The one named third party in the record is Coalfire as security auditor, which sits in the assurance chain rather than the model chain. A precisely enumerated signal count with no named source behind any of it describes the scale of the dependency without making it auditable.
API led and well documented, without the enumerated connector catalogue that distinguishes the strongest records in this lane. The Sift Score API is published with documentation the company describes as clear and accessible, and the integration model is deliberately event based rather than order based, so a customer instruments account creation, login, transaction, dispute and custom events across their own journey rather than dropping a plugin at checkout.
That design reaches further into a customer's stack but requires more of them. Integrations with ecommerce platforms and payment processors are stated and specific platforms including Magento and Salesforce are named in third party listings. Availability through a major cloud provider's commercial marketplace adds a procurement and billing path that some enterprise buyers require. Score export into a customer's own models is an integration in its own right and an unusual one. What was not located is a published connector list, so a buyer cannot check before contact whether their specific commerce platform, payment gateway or case management system is supported.
Hosted software consumed through an API, with no private, single tenant or on premise option located. Availability through a major cloud provider's commercial marketplace indicates where at least part of the estate runs and gives enterprise buyers a procurement route through existing cloud commitments, which is a genuine if incidental deployment fact.
Beyond that the residency position is absent: no cloud region, data centre, country or residency commitment is published, no region selection is offered or described, and no transfer mechanism or standard contractual clause provision was located for customers outside the United States.
That gap is material for a platform whose named customers operate globally and which ingests end consumer behavioural and device data across 34,000 sites, since the customer carries the residency obligation and cannot discharge it without knowing where processing happens.
Nothing is published. Two dedicated passes found no rate, no tier structure, no unit of sale and no free tier on the vendor's own surface, with pricing described only as volume based and routed to a demo request. That is a weaker position than the guarantee sellers in this lane, who at least publish the commercial model and where the risk sits even when they withhold the number.
Third party estimates exist and disagree with each other: one procurement marketplace puts mid market annual contracts in a fifty to one hundred and fifty thousand dollar range against a base platform fee plus a per event rate that falls with volume, another puts monthly spend between one and five thousand dollars, and a third quotes a per user monthly figure that does not match a per event model at all.
Pre emptive negative finding: third party pricing aggregators are actively unreliable for this vendor because at least one of them conflates it with an unrelated organisational chart product also called SIFT, publishing plan names belonging to that other company. A quoted figure attributed to Sift should be checked against which Sift it describes before it is believed, let alone used to move this grade.
Coverage is broader than the checkout focused vendors in this lane on two dimensions. By event type, scoring runs across account creation, login, transaction, dispute, content posting and customer defined events rather than at the order alone, which means the product reaches identity and account risk as well as payment risk.
By customer type, the named base spans social platforms, marketplaces, delivery, quick service restaurants, retail, communications and aviation, with a stated 34,000 sites and applications, and the company describes serving business to consumer software teams generally rather than merchants specifically. Fintech is addressed directly, with published material on payment fraud in fintech and on crypto account cash out scams. Two things hold this below the top grade.
Part of the breadth runs outside financial services altogether through Content Integrity, which addresses spam and fraudulent reviews for user generated content platforms and is excluded from this record. And there is no evidence of sales into banking operations, insurance or capital markets, so the reach is wide across digital consumer businesses and absent across regulated financial institutions.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Described by the vendor only as volume based, with every enquiry routed to a demo request. Third party estimates suggest a base platform fee plus a per event rate falling with volume, unverified against the vendor.
$0 baseline
|
Undisclosed by the vendor. No unit of sale, tier structure, quota or seat model is published, and the only characterisation offered is volume based. Third party procurement data consistently describes a per event model with a base platform fee, priced separately by module across Payment Protection, Account Defense and Content Integrity, with the per event rate declining across volume bands and buyers negotiating below list through volume commitments and multi year terms. That shape is plausible given the architecture, since the product scores discrete events across the user journey rather than orders at checkout, but none of it is confirmed by the vendor. The commercial structure differs fundamentally from the guarantee sellers in this lane: the customer pays for scoring and retains chargeback liability, so the rate is a software price rather than an underwriting output, which is why a published rate card would be possible here in a way it is not for a guarantee vendor. None is published. | No data processing addendum, subprocessor list or published data protection terms were obtainable in public. The trust centre at trust.siftscience.com is built on a dedicated vendor security review platform and states that everything needed to complete a security and privacy review is held there, so the artifacts most likely exist and sit behind a portal access request rather than being absent. What is publicly readable is the assurance layer only: ISO 27001:2022 certification and a SOC 2 Type II report renewed annually, with Coalfire named as auditor in the company's own announcement. A buyer will get security evidence by asking and processing terms by contracting. | Not published and not disclaimed. No setup, onboarding, integration or professional services fee appears anywhere. Integration effort is likely higher than for the plugin led competitors in this lane, because the model is event based rather than order based: a customer instruments account creation, login, transaction, dispute and custom events across their own journey rather than installing a checkout connector, which is engineering work carrying an internal cost even where the vendor charges nothing for it. The company sells strategic guidance and hands on support from specialists as a named offering alongside the platform, which is professional services in substance, and no rate, engagement minimum or inclusion boundary is stated for it. Availability through a major cloud provider's commercial marketplace may let some buyers draw the spend against existing cloud commitments. | Third Party Estimated |
Two dedicated passes returned no rate, tier, unit of sale or free tier from the vendor's own surface, which describes pricing only as volume based and routes every enquiry to a demo request. This is the weakest commercial disclosure among the ecommerce fraud vendors graded so far, and the reason is worth stating precisely: the guarantee sellers in this lane publish their commercial model even while withholding the number, because the model is itself the sales argument.
Sift sells control rather than risk transfer, so it has no equivalent structural story to tell and tells nothing. Third party estimates exist and contradict each other. One procurement marketplace describes a base platform fee plus a per event rate declining with volume, with mid market annual contracts commonly between fifty and one hundred and fifty thousand dollars for Payment Protection and thirty to one hundred thousand for Content Integrity.
Another puts monthly spend between one and five thousand dollars. A third quotes a per user per month figure, which is inconsistent with a per event model. Pre emptive negative finding, and the important one: third party pricing aggregators are actively unsafe for this vendor, because at least one publishes plan names belonging to an unrelated organisational chart product also called SIFT. Any quoted Sift figure must be checked against which company it describes before it is used at all.