ThreatMark
ThreatMark builds a behavioural baseline for each individual banking customer and watches for departures from it. The platform profiles how a person physically uses a device, keystroke rhythm, navigation habit, touch and pointer movement, session pattern, and combines that with device and threat signals and transaction context into one continuously updated view. The company calls the result behavioural intelligence and positions it against what it characterises as the traditional approach, a single backward looking check rather than constant monitoring of the present session.
The stated design premise is that the fraud that matters has moved off the bank's platform. Where a criminal once attacked the session directly, they now manipulate the customer into authorising the payment themselves, which defeats controls built to detect unauthorised access. The vendor's own research puts social engineering in most fraud at 55 percent of surveyed institutions, and its product line follows that: dedicated material for authorised push payment scams, instant payment scams, investment scams, romance scams, purchase scams and peer to peer fraud, alongside the older categories of account takeover, remote access attacks, session hijacking, subscriber module swap, financial malware, money mules and new account fraud.
Five components are published. The Behavioral Intelligence Platform carries the profiling, threat detection and transaction risk analysis. ScamFlag is a generative agent built into the banking app that reads a screenshot or photo a customer submits from any channel, extracts and interprets the content, checks links and account numbers against public sources and an internal database, and returns a scam assessment with recommended actions. Smart Insights supports analyst decisions. The Cyber Fraud Fusion Center runs phishing and malware disruption. FraudIntel handles cross border scheme detection and intelligence sharing.
Behavioural signal is also sold as the inherence element for European strong customer authentication, and transaction risk analysis supports the associated exemptions, so the product sits inside a named regulatory mechanism rather than beside it. The company reports more than 40 million users protected. Founded 2015 in Brno, ThreatMark now lists its head office in Charlotte, North Carolina, with offices in Brno and London.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
The removal test has no residue here, because the product's central claim cannot be expressed as a rule. A rule can say that a payment over a threshold to a new beneficiary is risky. It cannot say that this particular person is typing, scrolling and holding their phone unlike themselves, because there is no fixed definition of themselves to write down: the baseline is learned per individual and is different for every customer.
That per user normative profile, built from keystroke dynamics, navigation preference, session habit and device interaction and continuously updated, is the product. The vendor states the platform learns from new behaviours and adapts rather than only matching known patterns, which is the distinction between a model and a signature list.
The newer scam component is explicitly generative, described as an agent trained on a large corpus of scam samples that reads an image, extracts and interprets text, assesses graphical artefacts and reasons about context. Even the platform's name is the claim. Strip the models and what remains is device fingerprinting and threshold rules, which is the thing the company sells against.
The human stays in the decision at every point the vendor describes, and where the machine does act the bank sets the rule. The platform scores and surfaces; fraud analysts investigate, and the vendor's own framing throughout is supporting the people who fight fraud rather than replacing them, with one component sold specifically to improve analyst decisions.
The scam component is advisory by construction: it returns an assessment and recommended actions to the customer, who chooses, which is an unusually well placed intervention because it informs the person being manipulated rather than overriding them. Transaction risk analysis is where machine action does occur, adaptively applying stronger authentication or authorising a payment, but the risk policy is the bank's and the vendor supplies the signal into it.
Nothing published describes automatic closure of alerts, autonomous filing or an agent disposing of a case. What is missing is a stated boundary. The position is inferred from product shape rather than committed to, and nothing describes what a customer is told or can do when transaction risk analysis blocks a legitimate payment.
Detection figures published, the counterpart figure absent, and one honest caveat worth crediting. On the published side: the scam component is put at approximately 99 percent detection accuracy, a named customer reports 70 percent better detection than competitors in a comparative test, and another reports detection time falling from 16 hours to 20 minutes.
The caveat is that the scam accuracy figure is explicitly conditioned on the quality of the evidence submitted, which is a real methodological qualification rather than a bare number. What is missing is the false positive rate, and its absence matters more here than at most vendors in this index because of what a false positive does.
The failure mode of behavioural profiling is not a wasted analyst hour, it is a legitimate customer locked out or a payment blocked, and the vendor markets false positive reduction as a benefit in two places without publishing a rate anywhere. Also absent across two passes: validation methodology, sample and observation period, drift and retraining disclosure, and model documentation of the kind a bank's own risk function must hold on a vendor model.
The deepest named reference base encountered in this sweep, and unusually it is named on both sides. Ten institutions appear with a named individual and their job title attached, spanning three separate subsidiaries of one large European banking group, a subsidiary of a second European banking group, two further Czech banks, a United States credit union, a United States community bank, an Ecuadorian cooperative and a betting operator.
The strongest single item is competitive rather than testimonial: a named chief information security officer states the solution identified threats in all test cases and detected 70 percent better than the other vendors tested, which is a bake off result attributed to the person who ran it.
Other quantified claims carry named attribution too: account takeover damage to customers reduced by more than 90 percent, sophisticated fraud detection time cut from 16 hours to 20 minutes with investigation ten times faster, and a stated 40 million users protected. Independent standing is current, with a 2026 analyst matrix placing the company as a leader in this category, and the vendor publishes original survey research picked up by trade press. Figures remain vendor published and one testimonial claims zero losses absolutely.
Two genuinely creditable practices and one unexamined data flow. The creditable practices are small but real. The scam component publishes an honest limitation, stating that its detection efficacy depends on the quality of the evidence a customer submits, which is a vendor telling a buyer where its own product gets worse and is rarer here than it should be.
And a dedicated security contact address is published, which gives a researcher a route to report a vulnerability rather than leaving disclosure to chance. The unexamined flow is intelligence sharing. One published component detects cross border fraud schemes and shares intelligence to expose mule networks, and the disruption strategy the company markets rests on connecting signal across institutions.
That necessarily means something derived from one bank's customers informs another bank's defences, and nothing published describes what crosses that boundary, in what form, whether it is aggregated or identifiable, or whether behavioural profiles and customer outcomes train models used for other customers. Across two passes no red team result, evaluation methodology, model card or incident disclosure was located.
European baseline documents published, and the question the product itself raises left untouched. Published and reachable: a privacy policy, a cookie policy, a versioned code of conduct as a document, and a whistleblower protection page, the last two being governance artefacts most vendors in this segment do not publish at all.
One specific retention commitment appears, on the scam component, where submitted images are stated to be securely stored and automatically deleted after a set period. The untouched question is the central one. This product continuously collects how an individual physically interacts with a device, which in European law is a strong candidate for biometric data attracting heightened protection, and it collects it throughout a session rather than at a consent moment.
Nothing published describes the legal basis relied on, what the bank's customer is told, whether they can object, how long a behavioural profile is retained or what happens to it when they close the account. The Gramm Leach Bliley Act appears nowhere despite a United States head office and United States customers.
Better evidenced than most of this segment, and still short of readable scope. The credentials are asserted in prose rather than left as decoration, with the site stating in text that the company holds both an information security management certification and a service organisation control attestation, displayed alongside the marks of the relevant standards body and professional institute.
Around that sit governance documents a buyer can actually open: a versioned code of conduct published as a document, a whistleblower protection page, and a privacy and cookie policy. A dedicated security contact address is published, which is a working vulnerability disclosure route rather than a claim about security. Three deductions.
No trust centre, downloadable certificate, attestation report or penetration test summary is obtainable, so the scope of either credential, and specifically whether the behavioural collection pipeline sits inside it, cannot be read from outside. No revision year is given for the certification. And the attestation is described as a certification, where that framework produces an independent report rather than a certificate, with neither the type nor the observation period stated.
Unregulated, correctly so, with unusually concrete regulatory engagement and one conspicuous silence. The engagement is specific rather than thematic: behavioural signal is sold as the inherence element for European strong customer authentication, and transaction risk analysis is positioned against the associated exemption mechanism, so the product is built to a named regulation's specific requirements rather than described as helping with compliance generally.
Supervisory contact is evidenced through a customer rather than asserted, with a named director of digital banking stating that central bank auditors responded positively on learning the solution was in use, which is second hand but attributed. The silence is current and material.
An information technology supplier of this kind, embedded in the fraud controls of multiple European banks, sits squarely within the European Union operational resilience regime for critical third party providers, with obligations around contractual terms, exit planning, incident reporting and register entries that its customers must satisfy through it. Across two passes no published position on that regime was located, and none on the European artificial intelligence regulation either.
The exposure here is sharper than in most of this index because of who the false positive lands on. A model that flags departures from how a person normally holds, taps and types will flag a hand tremor, a new medication, arthritis, a stroke, failing eyesight, a switch to assistive technology, or a carer helping an elderly parent bank.
At the signal level none of that is distinguishable from a criminal operating the session, and the vendor's own description of detecting deviations from normative profiles offers no mechanism that would separate them. The population most likely to generate those deviations is elderly and disabled customers, which is precisely the population the scam products exist to protect and the one for whom a wrongly blocked payment or a locked account causes the most harm.
The directory this vendor sits in asks exactly this question of every member. Across two passes no false positive breakdown by age or impairment, accessibility statement, fairness testing, model card, governance page or artificial intelligence regulation position was located.
No commercial instrument of any kind is published. Across two passes the site carries a privacy policy, a cookie policy, a code of conduct and a whistleblower protection page, and no terms of service, master agreement, warranty, indemnity, liability cap, service level or uptime commitment was located anywhere.
The governance documents that are published are worth noting precisely so they are not mistaken for what this axis measures: a code of conduct binds the vendor's own staff, a whistleblower channel protects people raising concerns internally, and a security contact serves researchers. None of them is recourse for a customer, and none allocates a single unit of risk. The exposure they leave uncovered is specific.
This product decides, in effect, whether a bank's customer is who they claim to be, and when it is wrong in the direction that matters the customer is locked out of their money or has a legitimate payment blocked. Nothing published states what the bank is owed, what the customer is told, or who bears the consequence.
More disclosed about the generative component than most vendors manage, and the one question its own design raises left open. On the disclosed side, the scam component is described plainly as a generative agent trained on a large number of scam samples, and its data dependencies are named in outline: it checks extracted links and bank account numbers against public sources and against the company's own internal intelligence database.
Stating that a capability is generative and describing what it was trained on is more than several larger vendors in this index offer. What is never named is any model provider, family or version, and here that omission has a concrete consequence rather than an abstract one.
The product asks a bank's customer to upload a screenshot of a private conversation, which may be a message thread with a family member, an intimate exchange in a romance scam, or a photograph containing other personal detail. Whether that image is processed inside the vendor's own environment or passed to a third party model, and under whose terms, is not stated anywhere.
The weakest axis on this record, and the gap is documentation rather than capability. What the product must do technically is clear enough from the material: behavioural signal has to be captured inside the bank's own web and mobile channels, so a software development kit or equivalent embed is unavoidable, the scam component is described as integrating into existing banking applications without requiring a separate download and is offered through an interface as well, and card payment authorisation work implies a hook into the three domain secure flow.
A partners page exists. What a buyer cannot do is inspect any of it. Across two passes no public interface documentation, developer portal, software development kit reference, sandbox, code repository, connector catalogue or marketplace listing was located, and no core banking, case management or authentication platform is named as supported.
The practical consequence is that an engineering team cannot scope the work, and a bank cannot check whether its own digital banking platform is already supported, without entering a sales process first. Vendors of comparable size in this index publish all of it.
Not addressed on the public surface, in a segment where the question is unavoidable. Across two passes nothing published states whether the platform is delivered as multi tenant hosted software, single tenant, private cloud or installed in the bank's own environment, which hyperscaler or region it runs in, or what residency commitments are available.
The company lists offices in the United States, Czech Republic and United Kingdom, which describes where its people are rather than where data rests, and those should not be conflated. Two things make the silence weigh more than it would elsewhere. The data in question is continuous behavioural observation of named retail banking customers, which several of the vendor's own European customers must be able to account for to their supervisors down to processing location.
And a published component performs cross border scheme detection, which implies data moving between jurisdictions by design rather than incidentally, with nothing published about where that processing happens or under what safeguards. The scam component's stated automatic deletion after a set period is the only related commitment located.
Two passes across the vendor's own site, its solution and platform pages, its newsroom and the software aggregator listings produced no price, tier, unit of billing or contract term on any vendor surface. The published entry route is a contact form.
The only characterisation of the commercial model located anywhere is on an analyst peer platform, which describes it as subscription based and tailored to the scale of the user base or transactions, and that is a third party summary rather than a vendor statement, so it is recorded here as an indication rather than as disclosure.
The distinction matters because the two bases it names would produce very different bills for the same bank: charging on protected users scales with the customer book regardless of activity, while charging on transactions scales with usage, and a buyer choosing between vendors cannot model either without knowing which applies.
The vendor does publish product boundaries clearly, with five named components described separately, so a buyer can at least tell what they would be buying even though nothing indicates whether the components are licensed together or apart.
Real institutional spread across market types that rarely appear together, with a ceiling at the top end. Named customers include three subsidiaries of a large European banking group operating in different countries, a subsidiary of a second European group, two further Czech banks, a United States credit union, a United States community bank and an Ecuadorian police cooperative, which covers universal banks, challenger banks, mutuals and community institutions rather than one institution type repeated.
Offices in the United States, Czech Republic and United Kingdom support the stated geography. Buyer coverage is developed by function as well as by institution, with separate published material addressed to security, risk and compliance, digital channels and fraud departments, which is persona depth most vendors here do not attempt. What is absent is the top of the market and the breadth beyond banking.
No global systemically important bank is named and no institutional count is published, the concentration is visibly central and eastern European with United States expansion still early, and nothing addresses insurance, wealth, capital markets or payment institutions as segments.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No price, tier, unit of billing or contract term appears on any vendor surface
|
Not published on any vendor surface. Five product components are described separately, covering the behavioural platform, the generative scam detection tool, an analyst insight layer, a phishing and malware disruption operation and a cross border intelligence capability, with no indication of whether they are licensed as one platform or acquired individually. An analyst peer platform characterises the model as subscription based, tailored to the scale of the user base or transactions; that is a third party summary and not a vendor statement. The vendor does publish one scale figure that a buyer could use as context rather than as pricing, stating more than 40 million users protected across its customer base. | No tiered data protection terms are published. Commitments are uniform and thin: a privacy policy, a cookie policy, a versioned code of conduct and a whistleblower protection channel, plus one specific retention term on the scam component, where submitted images are stated to be securely stored and automatically deleted after a set period. Nothing published addresses the legal basis for continuous behavioural collection on bank customers, retention of behavioural profiles, or what crosses institutional boundaries in the cross border intelligence sharing component. No data processing agreement, subprocessor list or hosting location was located without contact. | No implementation, integration, onboarding or professional services fee is published, and no statement describes whether deployment is a chargeable engagement or included. The effort involved is not trivial and the material implies as much without pricing it: behavioural signal must be captured inside the bank's own web and mobile channels, which requires an embed in the institution's applications, and the scam component is described as integrating into existing banking applications without a separate customer download, which again means work inside the bank's own release cycle. One customer testimonial praises sales, onboarding and support responsiveness, and another describes the vendor's team walking their analysts through attacker methods, which suggests a substantial human delivery and enablement component, none of it priced publicly. A published operations capability, the fusion centre handling phishing and malware disruption, reads as an ongoing managed service rather than software alone, and whether it is bundled or charged separately is not stated. | Third Party Estimated |
Two passes across the vendor's own site, its solution and platform pages, its newsroom and resources, and the software aggregator listings produced no price, tier, unit or term. The published entry route is a contact form addressed to the sales team. The only description of the commercial model located anywhere sits on an analyst peer platform and is recorded here as a third party indication rather than as vendor disclosure.
That indication is worth flagging for a specific reason: the two bases it names, protected users and transactions, are not interchangeable. Charging on the protected user base tracks the size of a bank's retail book whether those customers transact or not, which suits an institution with low activity per account and penalises one with a large dormant book; charging on transactions tracks usage and moves the cost with volume.
A bank cannot model either, or compare this vendor against an alternative, without knowing which applies. Nothing published indicates whether the five named components are licensed together or separately, which is the second question a buyer would ask.