Risk, Fraud, and Adaptive Access
Nevis ID assesses every login in real time with its risk engine: device recognition, device fingerprint, IP address, IP reputation, geolocation, and geo-velocity signals feed a weighted risk score, with predefined balanced and strict profiles, custom weights, and an event-based mode. Rising risk drives the response: low-risk logins pass without friction, medium risk notifies the user, high risk requires a second factor, and users without an established pattern step up until the engine has learned it. Credential intelligence checks passwords against known breach data (Have I Been Pwned) at registration and sign-in, and a suspicious login triggers a notification email with a one-click link that lets the user distrust the session or the device and terminate it. Operators investigate risk events, high-risk users, and geographic attack patterns in the Threat Intelligence dashboard, with the same risk and session data also available over the REST APIs for correlation in your own fraud or risk platform; by design, Nevis ID collects no behavioral biometrics.
Also known as
risk-adaptive authentication, continuous authentication, adaptive access, fraud detection, FRIP integrations, bot management, compromised-credential intelligence.
At a glance
| Capability | Details |
|---|---|
| Risk-adaptive authentication | Every login is assessed in real time: device recognition, device fingerprint, IP address, IP reputation, geolocation, and geo-velocity signals produce a weighted risk score with low, medium, and high levels |
| Adaptive responses | Low risk passes without friction; medium risk notifies the user; high risk requires a second factor; users without an established pattern step up until the engine has learned it |
| Risk profiles | Predefined balanced and strict weight profiles, custom weights, and an event-based mode that reacts to specific risk events instead of the score |
| Impossible travel and location risk | Geo-velocity flags logins from locations physically too far apart to reach since the last login; suspicious-country lists and IP reputation add location-based risk |
| Device recognition and trust | Devices are recognized by a persistent cookie and a browser fingerprint; established devices lower risk and shared devices raise it; users and administrators remove devices and remember-me tokens in the self-service app and over the APIs |
| Compromised-credential intelligence | Passwords are checked against the Have I Been Pwned breach corpus at registration and sign-in, with the password change forced or optional by configuration |
| Suspicious-login response | A notification email carries the login details and a one-click link to distrust the session or the device and terminate it |
| Account takeover protection | Unknown-device and unknown-location step-up, shared-device detection, breached-credential checks, and session termination combine against ATO; see also Authentication, MFA, and Passwordless |
| Threat analytics | Risk events, high-risk users with contributing factors, a risk heat map, and browser distribution in the console's Threat Intelligence dashboard; see also Reporting, Analytics, and Audit |
| Fraud platform integration | Risk event history, session history, and device data are available over the REST APIs for correlation in an external fraud or risk intelligence platform (FRIP) |
| Bot management | Automated and bot traffic is filtered before it reaches Nevis ID: every instance sits behind Cloudflare's best-in-class bot protection, DDoS mitigation, and WAF at the platform edge; application-level signals such as failed-attempt tracking and browser distribution in Threat Intelligence surface anything that gets through; see also Deployment, Architecture, and Data Residency |
Concepts
- Administration APIs: the operator side of the risk data: sessions, devices, and observations for any user
How-to Guides
- Adaptive authentication: the low, medium, and high risk ladder in the Example Project
- Threat Intelligence: investigating risk events, high-risk users, and geographic attack patterns
- Credential intelligence: checking passwords against breach data at registration and sign-in
- Additional authentication factors: registering the second factor that high-risk logins require
- Self-service profile management: reviewing devices and sessions and removing suspicious ones
References
- Adaptive access patterns: nevisAdapt Authentication Connector, risk events, custom risk score weights, feedback configuration, suspicious-login notification, and Credential Intelligence
- Risk and session APIs: Risk event history, Apply feedback, Terminate sessions, Session management
- Data model: the nevisAdapt user and admin roles of an instance