Skip to main content

Risk, Fraud, and Adaptive Access

Nevis ID assesses every login in real time with its risk engine: device recognition, device fingerprint, IP address, IP reputation, geolocation, and geo-velocity signals feed a weighted risk score, with predefined balanced and strict profiles, custom weights, and an event-based mode. Rising risk drives the response: low-risk logins pass without friction, medium risk notifies the user, high risk requires a second factor, and users without an established pattern step up until the engine has learned it. Credential intelligence checks passwords against known breach data (Have I Been Pwned) at registration and sign-in, and a suspicious login triggers a notification email with a one-click link that lets the user distrust the session or the device and terminate it. Operators investigate risk events, high-risk users, and geographic attack patterns in the Threat Intelligence dashboard, with the same risk and session data also available over the REST APIs for correlation in your own fraud or risk platform; by design, Nevis ID collects no behavioral biometrics.

Also known as

risk-adaptive authentication, continuous authentication, adaptive access, fraud detection, FRIP integrations, bot management, compromised-credential intelligence.

At a glance

CapabilityDetails
Risk-adaptive authenticationEvery login is assessed in real time: device recognition, device fingerprint, IP address, IP reputation, geolocation, and geo-velocity signals produce a weighted risk score with low, medium, and high levels
Adaptive responsesLow risk passes without friction; medium risk notifies the user; high risk requires a second factor; users without an established pattern step up until the engine has learned it
Risk profilesPredefined balanced and strict weight profiles, custom weights, and an event-based mode that reacts to specific risk events instead of the score
Impossible travel and location riskGeo-velocity flags logins from locations physically too far apart to reach since the last login; suspicious-country lists and IP reputation add location-based risk
Device recognition and trustDevices are recognized by a persistent cookie and a browser fingerprint; established devices lower risk and shared devices raise it; users and administrators remove devices and remember-me tokens in the self-service app and over the APIs
Compromised-credential intelligencePasswords are checked against the Have I Been Pwned breach corpus at registration and sign-in, with the password change forced or optional by configuration
Suspicious-login responseA notification email carries the login details and a one-click link to distrust the session or the device and terminate it
Account takeover protectionUnknown-device and unknown-location step-up, shared-device detection, breached-credential checks, and session termination combine against ATO; see also Authentication, MFA, and Passwordless
Threat analyticsRisk events, high-risk users with contributing factors, a risk heat map, and browser distribution in the console's Threat Intelligence dashboard; see also Reporting, Analytics, and Audit
Fraud platform integrationRisk event history, session history, and device data are available over the REST APIs for correlation in an external fraud or risk intelligence platform (FRIP)
Bot managementAutomated and bot traffic is filtered before it reaches Nevis ID: every instance sits behind Cloudflare's best-in-class bot protection, DDoS mitigation, and WAF at the platform edge; application-level signals such as failed-attempt tracking and browser distribution in Threat Intelligence surface anything that gets through; see also Deployment, Architecture, and Data Residency

Concepts

  • Administration APIs: the operator side of the risk data: sessions, devices, and observations for any user

How-to Guides

References