Continuous behavioural intelligence across every session, passive and frictionless.

An SDK-based module that reads how a person physically interacts with their device during a session and converts that interaction into a behavioural identity: unique to the individual, continuously refined, and impossible to replicate at scale.

JupiterNiyoPunjab & Sind BankJana Small Finance BankCSB BankLenDenClubmoneyview
SnapmintIndiaMARTBajaj FinanceKisshtOneCardSmartCoinOTO

Why it exists

Credentials and OTPs compromised while behaviour reveals the real user

Credentials verify the keys. They do not verify the person holding them. A stolen password, a compromised OTP, a phished login all produce sessions that look legitimate because the correct credentials were used. Behavioural Biometrics reads the one signal that cannot be transferred between people: how someone physically types, touches, swipes, and holds their device.

What It Does

One SDK, reading the session as it happens. Five clusters of behavioural intelligence.

Finger on a sensor with typing and touch signals
  • Typing rhythmMatch
  • Touch pressureNormal
  • Swipe curvatureConsistent
  • Handling postureTwo-handed

Typing and Touch Patterns

Every person interacts with their device in a way that is measurably unique. This cluster reads the full physical layer of that interaction, passively, with no friction to the user.

  • Typing rhythm, speed, dwell time, and flight time between keystrokes
  • Touch pressure, contact area, and tap precision
  • Swipe velocity, direction, and curvature
  • Scroll cadence and acceleration
  • Gyroscope, accelerometer, and device orientation data
  • Device handling posture: one-handed, two-handed, stationary, or in motion
User journey flow from start to submit
  • Field sequenceExpected
  • Form hesitationLow
  • Copy-pasteNone
  • Session duration1.2× typical

Navigation and Session Flow

Beyond how someone types or taps, the flow of a session carries its own signal. How a person moves through a form, which fields they pause on, and how they input data reveals whether the session is genuine, rehearsed, or externally guided.

  • Navigation sequence and field-focus patterns
  • Form-filling speed and hesitation points
  • Copy-paste and autofill detection
  • Context switching and background activity
  • Session duration relative to task complexity
Behavioural profile consistent across sessions
  • BaselineEstablished
  • Sessions learned14
  • Deviation4%
  • Cross-sessionConsistent

Behavioural Baseline

A single session produces a snapshot. Multiple sessions produce an identity. This cluster builds a unique behavioural profile for each user and refines it with every interaction, so every future session is compared against the individual's own pattern, not a generic threshold.

  • Per-user baseline established from initial sessions
  • Continuously refined with each subsequent interaction
  • Baseline belongs to the individual account, not a population average
  • Cross-session consistency tracked over the account lifecycle
Anomalous interaction flagged off a conveyor
  • Timing variationNatural
  • Touch eventsPresent
  • NavigationHuman
  • Bot probability2%

Bot and Automation Detection

Human interaction carries natural variation. Automated interaction does not. This cluster identifies sessions driven by scripts, headless browsers, or programmatic input rather than a person.

  • Uniform timing and absent touch variation flagged
  • Mechanical navigation sequences identified
  • Scripted form-filling patterns detected
  • Classified passively, with no challenge screen or interruption to genuine users
Unknown caller and a puppet figure indicating coached sessions
  • Active callNone
  • Input patternContinuous
  • Hesitation points0
  • Coaching likelihoodLow

Scam and Coercion Detection

In authorised-push-payment scams, the person on the device is real but is being guided through the transaction by a fraudster on the phone. The behaviour changes in ways that are invisible to credential checks but measurable in biometrics.

  • Hesitation at unusual points in the session
  • Segmented, coached input patterns
  • Navigation pauses inconsistent with familiarity
  • Active call detection during the session
  • Indicators that the user is following verbal instruction rather than acting independently

What Comes Out

Behavioural intelligence per session. Real-time. Three consumption tiers.

Where It Applies

Three deployments, each reading behaviour for a different decision.

  • Fraud prevention

    Fraud prevention

    Account takeover detection, bot blocking, scam and coercion identification

  • Onboarding

    Onboarding

    Assisted application detection, Bot automation

  • Monitoring

    Monitoring

    Continuous behavioural consistency across the account lifecycle

Integration

The SDK sits alongside your existing stack and runs passively during the session. No challenge screens, no added friction for genuine users, no replacement of systems already in production.

JupiterNiyoPunjab & Sind BankJana Small Finance BankCSB BankLenDenClubmoneyview
SnapmintIndiaMARTBajaj FinanceKisshtOneCardSmartCoinOTO

Why it exists

Credentials verify the keys. They do not verify the person holding them. A stolen password, a compromised OTP, a phished login all produce sessions that look legitimate because the correct credentials were used. Behavioural Biometrics reads the one signal that cannot be transferred between people: how someone physically types, touches, swipes, and holds their device.

Credentials and OTPs compromised while behaviour reveals the real user

What It Does

One SDK, reading the session as it happens. Five clusters of behavioural intelligence.

Typing and Touch Patterns

Every person interacts with their device in a way that is measurably unique. This cluster reads the full physical layer of that interaction, passively, with no friction to the user.

  • Typing rhythm, speed, dwell time, and flight time between keystrokes
  • Touch pressure, contact area, and tap precision
  • Swipe velocity, direction, and curvature
  • Scroll cadence and acceleration
  • Gyroscope, accelerometer, and device orientation data
  • Device handling posture: one-handed, two-handed, stationary, or in motion

Navigation and Session Flow

Beyond how someone types or taps, the flow of a session carries its own signal. How a person moves through a form, which fields they pause on, and how they input data reveals whether the session is genuine, rehearsed, or externally guided.

  • Navigation sequence and field-focus patterns
  • Form-filling speed and hesitation points
  • Copy-paste and autofill detection
  • Context switching and background activity
  • Session duration relative to task complexity

Behavioural Baseline

A single session produces a snapshot. Multiple sessions produce an identity. This cluster builds a unique behavioural profile for each user and refines it with every interaction, so every future session is compared against the individual's own pattern, not a generic threshold.

  • Per-user baseline established from initial sessions
  • Continuously refined with each subsequent interaction
  • Baseline belongs to the individual account, not a population average
  • Cross-session consistency tracked over the account lifecycle

Bot and Automation Detection

Human interaction carries natural variation. Automated interaction does not. This cluster identifies sessions driven by scripts, headless browsers, or programmatic input rather than a person.

  • Uniform timing and absent touch variation flagged
  • Mechanical navigation sequences identified
  • Scripted form-filling patterns detected
  • Classified passively, with no challenge screen or interruption to genuine users

Scam and Coercion Detection

In authorised-push-payment scams, the person on the device is real but is being guided through the transaction by a fraudster on the phone. The behaviour changes in ways that are invisible to credential checks but measurable in biometrics.

  • Hesitation at unusual points in the session
  • Segmented, coached input patterns
  • Navigation pauses inconsistent with familiarity
  • Active call detection during the session
  • Indicators that the user is following verbal instruction rather than acting independently

What Comes Out

Behavioural intelligence per session. Real-time. Three consumption tiers.

A device emitting individual behavioural signals as structured data

Raw Signals

The full set of behavioural attributes per session as structured data. For institutions that integrate directly into their own fraud models or authentication logic.

  • Typing, touch, swipe, and scroll metrics
  • Navigation and form-filling patterns
  • Sensor and device-handling data
  • Anomaly indicators and deviation measurements
A scorecard reading the behavioural signals into a risk score

Pre-Built Scores

Decision-ready output, each score accompanied by contributing factors.

  • Behavioural risk score (deviation from individual baseline)
  • Session anomaly score (current session signals)
  • Bot probability classification
  • Coaching likelihood indicator
behavioural signals feeding a configurable risk model

Custom Risk Models

Behavioural scoring calibrated to the institution's own user population. Normal behaviour at a trading platform differs from normal behaviour at a lending application. Sign3 tunes the baseline sensitivity and thresholds accordingly.

Where It Applies

Three deployments, each reading behaviour for a different decision.

Fraud prevention

Fraud prevention

Account takeover detection, bot blocking, scam and coercion identification

Onboarding

Onboarding

Assisted application detection, Bot automation

Monitoring

Monitoring

Continuous behavioural consistency across the account lifecycle

Integration

The SDK sits alongside your existing stack and runs passively during the session. No challenge screens, no added friction for genuine users, no replacement of systems already in production.

SDK connecting a mobile app and a code editor

Delivery

SDK (Android, iOS, Web). Same SDK as Device Intelligence.

SDK footprint

Under 1MB (shared with Device Intelligence).

Response time

Real-time, continuous during session.

Timeline

3–4 weeks.

Compliance

Non-PII data collection. DPDP Act compliant. GDPR compliant. Zero friction to the user.

Run your last week of traffic through Sign3.

We'll score it, surface the fraud patterns your current stack missed, and walk you through what we found. Your data, our scoring. No commitment, no integration, no decision required until you've seen the result.