Signifyd
Signifyd sells ecommerce commerce protection under a financial guarantee, and unusually for this lane it sells to two buyer types rather than one. The Commerce Protection Platform serves merchants and covers Guaranteed Fraud Protection, Complete Chargeback Protection, Account Protection, Authorization Rate Optimization built on issuer integrations, Chargeback Recovery, Return Insights and Instant Refunds. A separate Payments Optimization Platform is sold to payment providers.
The guarantee is configurable rather than fixed, running from fraud only cover to a total chargeback liability shift, and the company draws an explicit distinction between that and a performance service level guarantee, arguing an approval rate promise carries no incentive to exceed the target. Decisions are made from session data covering internet protocol address, behaviour and transaction detail, with a machine learning contextual layer drawing on forensic data and more than 150 out of band identity sources, and the company states it recognises over 98 percent of online shoppers through its merchant network.
Two mechanisms sit around the automation: Expert Re-review, under which a declined order can be resubmitted with further information for review by a certified fraud analyst, and a published commitment to supply the data behind a decision. Assurance is documented rather than asserted, with an annual SOC 2 Type II available under non disclosure, a SOC 3 report downloadable without one, ISO 27001, PCI DSS Level 1 and PCI 3DS. Named privacy regimes include GDPR, CCPA, Brazil's LGPD and Mexico's federal data protection law, with a public data subject access request form. The company reports more than 6,000 brands and has been ranked first in the Digital Commerce 360 Leading Vendors to the Top 1000 Retailers report for five consecutive years.
Capability Axes
Capability grades
15 of 15 axes rated · 9 graded A or B
The commercial structure settles this before the marketing gets a say. Signifyd charges a percentage of order total only when it approves an order, charges nothing when it declines for fraud, and under Guaranteed Fraud Protection shifts the chargeback liability onto itself. A company that pays for its own false negatives cannot be running a rules engine with a model bolted on, because the guarantee would not be underwritable.
The described pipeline is consistent with that: session data covering internet protocol address, behaviour and transaction detail, then a machine learning contextual layer incorporating forensic data and more than 150 out of band identity sources, correlated into a single decision.
The network effect is the other half, with the company stating it recognises more than 98 percent of online shoppers and their purchase intent from its enterprise merchant network, which is a claim about learned identity resolution rather than about a list. Strip the models and both the recognition rate and the guarantee collapse together.
Automation is total by design, with 100 percent order automation stated as an outcome and back office fulfilment triggered directly from the guarantee decision, so orders ship without a person seeing them. What distinguishes this record from its direct competitors is that a human review path is published and staffed rather than merely implied.
Under Expert Re-review, the company states that every order gets a second chance and that a declined order can be resubmitted with additional information for a thorough review by a certified fraud expert. That is a named escalation route attached to an adverse automated decision, which is precisely what this axis asks for and which neither of the closest peers in this lane publishes.
Two further commitments support it: the company states that machine learning should not leave a buyer in the dark and that it supplies the data needed to understand decisions, and it markets complete control over protection settings as a design principle. What remains undocumented is the specification: no threshold, escalation trigger, turnaround commitment or reviewer authority is published for the re-review, so a buyer knows the path exists without knowing what it guarantees.
The architecture is described more openly than most in this lane and the performance is not measured at all. On the architecture, the company sets out the shape of the pipeline: session data covering internet protocol address, behaviour and transactional signals, then a machine learning contextual layer incorporating forensic data and more than 150 out of band identity sources, correlated to produce a decision.
A reviewer can reason about where a signal enters and what kind of inference sits on top. On performance there is nothing to review. No validation report, accuracy figure, precision or recall measure, error rate, benchmark or monitoring statement was located.
The quantified figures the company does publish, such as approval rates above 99 percent and chargeback reductions of 93 percent, are outcomes at named individual merchants rather than model performance measures, and they carry no baseline, population or methodology. Unlike a listed competitor in this lane, no audited financial line moves with model accuracy either, so there is not even an indirect published proxy.
Four named customers carry published, quantified outcomes rather than adjectives. Hot Topic is credited with a 10 million dollar revenue uplift and approval above 99 percent with fully automated processing. Cymbiotika is credited with 1.2 million dollars in savings, 93 percent fewer chargebacks and a 98 percent approval rate. Ferguson Home is credited with a 98.5 percent approval rate and zero fraud losses. Philips carries a case study on cost savings and customer satisfaction.
The company states it serves more than 6,000 brands. Third party standing is named with the specific report rather than gestured at: first place in the Digital Commerce 360 Leading Vendors to the Top 1000 Retailers report for five consecutive years, and inclusion in Fast Company's Most Innovative Companies list.
The company also publishes original market research under its State of Fraud Report, carrying figures such as fraud pressure up 33 percent year over year, account takeover up 78 percent and card testing attacks up 175 percent. What is absent, and it is the one thing separating this from a listed peer, is audited financial disclosure, since the company is privately held and no revenue, loss or retention figure is attested by anyone.
The merchant network is the competitive asset and it is disclosed as a benefit rather than governed as a boundary, which is the same pattern seen across this lane. The company describes tapping the industry's largest enterprise merchant network and states that it instantly recognises over 98 percent of online shoppers and their purchase intent, which necessarily means a shopper's conduct at one retailer shapes whether a competing retailer approves them, and that a merchant's own customer data improves decisions for rivals in its category.
Nothing published describes whether a merchant can decline to contribute to the network, how one merchant's data is walled from another's view, what the retained shopper profile contains, how long it persists, or what happens to a merchant's contributed data when it leaves. The public data subject access request form is a partial answer on the consumer side, since it gives an individual a route to ask what is held, and it is credited on the privacy axis rather than here. On the merchant side, where the reciprocity question actually sits, there is no published position at all.
Four privacy regimes are named specifically rather than gestured at, covering the General Data Protection Regulation, the California Consumer Privacy Act, Brazil's Lei Geral de Proteção de Dados and Mexico's federal law on protection of personal data held by private parties.
Naming the Brazilian and Mexican instruments is the useful part, because it tells a merchant selling into Latin America that the vendor has considered the regimes that actually bind them there rather than only the two everyone cites.
More concretely, a public data subject access request form is published at signifyd.com/dsar, which is a working mechanism a consumer can use rather than a policy paragraph describing one, and a separate California privacy notice sits alongside the main policy. The surrounding legal surface is unusually complete for this lane, with terms of service, site terms, acceptable use restrictions, a vendor ethics statement and a modern slavery statement all published. What is missing is the processor detail an enterprise reviewer needs: no data processing addendum, subprocessor list or retention schedule was located.
Five credentials are published together with the terms on which each can be obtained, and one of them is downloadable on the spot. The company states it undergoes several annual audits by independent third party auditors and lists SOC 2 Type II, completed annually and available on request after a non disclosure agreement; a SOC 3 report, which is the general use form of the same examination and is published as a downloadable document requiring no agreement at all, carrying a 2025 Type 2 designation; ISO 27001, badged to the 2022 revision; Payment Card Industry Data Security Standard at Level 1, the tier applied to the highest transaction volumes; and PCI 3DS, covering the three domain secure authentication environment.
Publishing an actual attestation report a buyer can read before contact, rather than a logo or a claim, is the strongest single artifact this axis can receive, and it is what separates this record from the rest of the lane. Two things stop it short of complete: the auditing firm is not named on the page itself, and there is no formal trust centre portal, penetration test summary or subprocessor disclosure alongside the certificates.
The company is privately held, holds no financial licence, and no supervisory relationship with any regulator was located. What exists is compliance against named schemes rather than status conferred by an authority. Payment Card Industry Data Security Standard Level 1 and PCI 3DS certification are genuine payment scheme credentials assessed by third parties, and they are credited on the security axis where the evidence for them sits.
Privacy compliance is stated against four named regimes covering the General Data Protection Regulation, the California Consumer Privacy Act, Brazil's Lei Geral de Protecao de Dados and Mexico's federal law on protection of personal data held by private parties. Authorization Rate Optimization works through card issuer integrations, which puts the product inside scheme rules without conferring any regulated status on the vendor.
No named regulator appears as a customer or counterparty, no payments directive compliance is claimed in the way European focused peers claim it, and the company files with no securities regulator, so none of the mandated public disclosure a listed competitor carries is available here.
One stated principle and no measurement behind it. The company commits that machine learning should not leave a buyer in the dark and states it provides the data needed to understand decisions and stay attuned to business performance, which is an explainability position rather than a governance programme. Beyond that the axis is empty. No error rate, false positive rate or confidence measure is published for any decision.
No fairness testing, disparate impact analysis or demographic coverage statement exists, which matters here because the product decides whether individual consumers may complete a purchase and the company states it recognises more than 98 percent of shoppers, so the two percent it does not recognise are absorbing the friction and nothing describes who they are. Nothing documents who approves a model change or what review a new model passes.
The published State of Fraud research reports aggregate market conditions such as fraud pressure and account takeover rates, which is industry analysis rather than disclosure about this vendor's own models.
The liability shift is real, configurable and explained with unusual precision. The company offers a financial guarantee against chargebacks that a merchant can set anywhere from fraud only cover to a total chargeback liability shift, charges a percentage of order total only on approved orders, and charges nothing when it declines an order for fraud, so the cost of a false negative falls on the vendor.
It then does something rare and argues against a competing structure on the record, distinguishing its guarantee from a performance service level guarantee on the grounds that a promised approval rate carries no built in incentive to exceed the target. A buyer can test that reasoning.
Two mechanisms extend recourse further than the guarantee alone: Expert Re-review gives a declined order a documented path back to a human analyst, and the public data subject access request form gives an individual consumer a statutory route to what is held about them, which is more than the closest competitors in this lane provide.
What keeps this at the same grade as its peers is that no accuracy commitment, indemnity for a wrongly declined order, or turnaround service level on re-review is published, and a shopper declined at checkout is still not told why, by whom, or on what evidence.
The count is published and the names are not, which is the same failure this axis catches elsewhere in a more sophisticated form. The company states that its machine learning layer draws on forensic data and more than 150 out of band identity sources, which tells a reviewer the breadth of the external dependency and nothing about its composition.
Not one of those 150 sources is identified, so a buyer cannot assess the quality of any of them, cannot tell whether a source they have already rejected in their own supply chain is feeding this decision, and cannot judge concentration risk if several of the 150 resolve to the same underlying data broker. No subprocessor list exists in any document, no cloud infrastructure provider is named, and no model or foundation model provider is identified for any component.
The named partners across commerce platforms, payment processors and issuers are consumers of the decision rather than suppliers to the model, so they do not answer this axis. A precise number standing where names should be is more informative than a vague adjective and still leaves the chain unauditable.
Named and enumerated across three distinct layers, which is what the axis is built to reward. Order platform connectors are pre built for Miva, BigCommerce, Adobe Commerce, Salesforce Commerce Cloud, Shopify, NetSuite, Accertify and VTEX. Payment connectors pull chargeback data automatically from Adyen, Stripe, PayPal, Square and Worldpay, which is what allows the guarantee to reconcile against the acquirer rather than only the merchant's own order record.
The developer surface offers REST APIs, webhooks, JavaScript tags, mobile software development kits and SDK libraries, with public documentation at docs.signifyd.com and a public console status page at status.signifyd.com, so both the interface and its uptime are inspectable without a sales conversation. Issuer integrations extend the reach upstream into bank authorisation decisions.
The partner network is segmented into platform partners, developer and systems integrators and financial institutions. Worth noting that Accertify appears in the connector list, meaning the vendor integrates with a direct competitor in the same category, which is a real indicator of openness rather than a claimed one.
Delivery is hosted software consumed through an API and pre built connectors, with no private, single tenant or on premise option located. A public console status page at status.signifyd.com is a genuine availability artifact and more than most peers publish, but availability is not residency.
On residency the published position is absent: no hosting provider, cloud region, data centre or country is named anywhere, and no transfer mechanism or standard contractual clause provision was located. That gap is more consequential here than for a domestic vendor, because the company explicitly claims compliance with Brazil's LGPD and Mexico's federal data protection law alongside GDPR, and both of those regimes turn on where processing happens and how data leaves the jurisdiction. Naming the regimes without naming the processing location leaves a merchant selling into those markets unable to complete its own assessment.
No percentage appears anywhere across two dedicated passes, and almost everything else does. The pricing page states the unit of sale outright: a percentage of the order total charged only when an order is approved, with no charge when an order is declined due to fraud. It then names the variables that set that percentage, being the specific products purchased, the merchant vertical, order volume and average ticket price.
It describes the quoting method, an assessment of the merchant's current operating effort, chargeback losses and order declines against desired approval rate targets. It makes a behavioural commitment a buyer can hold the vendor to, that it will not win business with a low introductory rate that rises later.
And it discloses that the guarantee itself is configurable from fraud only cover to a total chargeback liability shift, while distinguishing that from a performance service level guarantee on the grounds that an approval rate promise carries no incentive to exceed the target. That last point is a vendor explaining the weakness of a competing commercial structure in terms a buyer can check. A merchant can model the economics from all of this and still cannot learn the rate, which is what holds the grade where it is.
Two buyer types are served through separately packaged platforms, which is what lifts this above the merchant only vendors in the same lane. The Commerce Protection Platform is sold to merchants; the Payments Optimization Platform is sold to payment providers as a conversion amplifier.
Authorization Rate Optimization reaches a third party again by working through issuer integrations to lift bank authorisation rates, and financial institutions appear as their own named partner category alongside platform partners and systems integrators.
Vertical coverage is enumerated across fashion, electronics, home goods, beauty and cosmetics, sporting goods, grocery, automotive parts, airline and quick service restaurants, with more than 6,000 brands claimed and global coverage stated.
What holds this below the top grade is that the centre of gravity remains ecommerce commerce protection: this vendor does not sell into banking operations, insurance, capital markets or regulatory supervision, and the payment provider and issuer relationships extend the same decision rather than opening a different product line.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Charged as a percentage of order total on approved orders only, with no charge when an order is declined due to fraud. The percentage is quoted per merchant and no figure, floor or minimum appears.
$0 baseline
|
A percentage of order total charged only on approved orders, with declined fraud orders free. The company publishes the variables that set that percentage: the specific products purchased, the merchant vertical, order volume and average ticket price. It also publishes the quoting method, an assessment of the merchant's current operating effort, chargeback losses and order declines, worked against agreed approval rate targets. The structure makes the vendor the residual risk holder for its own decisions, because under Guaranteed Fraud Protection the chargeback liability shifts from merchant to Signifyd, and that is why no rate card can exist: each rate is an underwriting decision against that merchant's loss profile. Cover itself is configurable along a spectrum from fraud only chargebacks to a total chargeback liability shift, so the same merchant can buy different amounts of risk transfer at different rates. Additional products around the core guarantee, covering account protection, authorisation rate optimisation, chargeback recovery, return insights and instant refunds, are packaged separately and none carries a published price. | No data processing addendum or subprocessor list was located. What is published instead is a compliance surface naming four regimes specifically, the General Data Protection Regulation, the California Consumer Privacy Act, Brazil's LGPD and Mexico's federal law on protection of personal data held by private parties, alongside a separate California privacy notice and a public data subject access request form at signifyd.com/dsar that a consumer can use directly. On the security side the terms are better evidenced than the data protection terms: a SOC 3 report is downloadable without a non disclosure agreement and a SOC 2 Type II is available under one, with ISO 27001, PCI DSS Level 1 and PCI 3DS also held. A merchant therefore gets assurance evidence before contact and processing terms only after it. | Not published and not disclaimed. No setup, onboarding, integration or migration fee appears anywhere. Integration effort is genuinely low for most merchants, since pre built connectors ship for Miva, BigCommerce, Adobe Commerce, Salesforce Commerce Cloud, Shopify, NetSuite, Accertify and VTEX, payment connectors pull chargeback data automatically from Adyen, Stripe, PayPal, Square and Worldpay, and public API documentation supports a custom build. The company markets quickest time to value as a differentiator and publishes material on how to assess it, but attaches no figure, timeline commitment or professional services rate to any of it. Dedicated support is described as 24 hour online coverage from a customer success team, with no tiering or fee stated. Expert Re-review of declined orders by a certified fraud analyst is presented as included rather than chargeable. | Vendor Published |
Two dedicated passes. The finding is that this is the most disclosed commercial model located in the ecommerce fraud lane, and it still stops one step short of a number. Published on the pricing page without any contact: the unit of sale, the four variables that set the rate, the assessment method used to quote, the fact that declined fraud orders are free, the configurability of the guarantee from fraud only to total chargeback liability shift, and an explicit undertaking not to use a low introductory rate that rises later.
The company also argues on the record why its guarantee structure is preferable to a performance service level guarantee, which is a competitive argument a buyer can independently test rather than a claim they must accept. None of that yields a percentage, and the company states plainly that the percentage varies by product mix, vertical, order volume and average ticket price.
Pre emptive negative finding: a third party listing quoting a Signifyd percentage should not be treated as a published rate. The rate is an underwriting output rather than a list price, since the vendor is pricing its own expected chargeback losses for that specific merchant, so no single figure could be true across merchants and a quoted one would mislead.