A continuous read on the Device behind every customer interaction.

An SDK that reads the device at the point of interaction and returns a comprehensive risk assessment: persistent device identity, integrity evaluation, remote-access detection, network and location analysis, and installed-application profiling. Real-time, per session.

JupiterNiyoPunjab & Sind BankJana Small Finance BankCSB BankLenDenClubmoneyview
SnapmintIndiaMARTBajaj FinanceKisshtOneCardSmartCoinOTO

Identities are cheap. Devices are not.

Many stolen identities funnelled through a single device

A fraudster can acquire hundreds of stolen identities for a few thousand rupees each. A fraudster cannot acquire hundreds of phones. The device is the one asset in the fraud chain that does not scale cheaply. Device Intelligence reads it as the ground truth for identity, producing a persistent fingerprint alongside a real-time assessment of whether the device, the network, and the session are genuine.

What Device Intelligence Reads

One SDK call. Every layer of the device read in parallel — identity, integrity, control, connection, and what the device reveals about the person holding it.

Shield with fingerprint beside a padlock
  • Device IDa4f9…c21e
  • PersistenceSurvives reset
  • Linked accounts3
  • Device age412 days

Device Identity and Persistence

Every other identifier can be changed. The device cannot be cheaply replaced. Device Intelligence generates a unique fingerprint from hardware-level signals that persists when everything else has been wiped or manipulated.

  • Stable across factory resets, reinstallations, and identifier changes
  • Recognises the same device across sessions, accounts, and applications
  • Multi-account linkage: all identities associated with a single device surfaced
  • Historical device risk carried forward across the device's full lifecycle
Phone showing device integrity with no threats detected
  • Root / jailbreakClean
  • EmulatorNot detected
  • App cloningNone
  • Install sourcePlay Store
  • RASPActive

App and Device Integrity

A manipulated device environment is one of the strongest indicators that the session is not genuine. This cluster evaluates whether the device and application are operating in a trustworthy state.

  • Root, jailbreak, and emulator detection
  • App cloning, hooking frameworks, and unauthorised modifications
  • Installation source verification
  • Keylogger and harmful application detection
  • Runtime application self-protection (RASP): tamper, hook, and manipulation assessment
Laptop flagging remote access with an unusual incoming session
  • Remote-access apps2 present
  • Screen mirroringActive
  • Accessibility abuseFlagged
  • InteractionCoached

Remote Access and Session Threats

In authorised-push-payment scams, the victim’s own device is used against them, controlled remotely while the fraudster guides the transaction by phone. This cluster identifies sessions where the device is under external control.

  • Remote-access application detection (presence and count)
  • Active screen mirroring identification
  • Accessibility-service abuse detection
  • Indicators of coached or externally directed interaction
Phone showing network, location and IP status over a map
  • VPN / proxyDetected
  • GPS spoofingClean
  • ISPJio · AS55836
  • SIM2 · swap 6d

Network and Location Intelligence

The network context of a session reveals what the device’s own identifiers may conceal. In the Indian market, where CGNAT renders IP-based signals unreliable across most mobile networks, this layer provides a materially more reliable read.

  • VPN, proxy, and unsecured network detection
  • GPS spoofing identification
  • IP-level intelligence: geolocation, ISP, ASN, fraud score
  • SIM data: count, swap history, eSIM detection, carrier
Application intelligence with app risk overview
  • Lending apps14
  • Finance affinityHigh
  • Premium apps6
  • Gaming affinityLow

Apographic Intelligence

The applications installed on a device carry risk, affluence, and behavioural signals that no document or bureau score contains. This cluster reads the app portfolio and derives category-level intelligence from it.

  • Category-level affinity scores: lending, finance, gaming, entertainment, productivity
  • Lending application density as a credit-seeking signal
  • Premium application presence as an affluence indicator

What Device Intelligence Returns

Real-time per session. Three consumption tiers.

Where It Applies

Four deployments, each reading the device for a different decision.

  • Fraud prevention

    Fraud prevention

    Emulator and device-farm detection, multi-accounting, fraud ring linkage, SIM-swap identification

  • Onboarding

    Onboarding

    Device integrity verification at account creation or loan application

  • Monitoring

    Monitoring

    Continuous device and session consistency across the account lifecycle

  • Scam prevention

    Scam prevention

    Remote-access detection during live sessions

Integration

The SDK sits alongside your existing stack. No change to your decisioning logic, no data migration, no replacement of systems already in production.

JupiterNiyoPunjab & Sind BankJana Small Finance BankCSB BankLenDenClubmoneyview
SnapmintIndiaMARTBajaj FinanceKisshtOneCardSmartCoinOTO

Identities are cheap. Devices are not.

A fraudster can acquire hundreds of stolen identities for a few thousand rupees each. A fraudster cannot acquire hundreds of phones. The device is the one asset in the fraud chain that does not scale cheaply. Device Intelligence reads it as the ground truth for identity, producing a persistent fingerprint alongside a real-time assessment of whether the device, the network, and the session are genuine.

Many stolen identities funnelled through a single device

What Device Intelligence Reads

One SDK call. Every layer of the device read in parallel — identity, integrity, control, connection, and what the device reveals about the person holding it.

Device Identity and Persistence

Every other identifier can be changed. The device cannot be cheaply replaced. Device Intelligence generates a unique fingerprint from hardware-level signals that persists when everything else has been wiped or manipulated.

  • Stable across factory resets, reinstallations, and identifier changes
  • Recognises the same device across sessions, accounts, and applications
  • Multi-account linkage: all identities associated with a single device surfaced
  • Historical device risk carried forward across the device's full lifecycle

App and Device Integrity

A manipulated device environment is one of the strongest indicators that the session is not genuine. This cluster evaluates whether the device and application are operating in a trustworthy state.

  • Root, jailbreak, and emulator detection
  • App cloning, hooking frameworks, and unauthorised modifications
  • Installation source verification
  • Keylogger and harmful application detection
  • Runtime application self-protection (RASP): tamper, hook, and manipulation assessment

Remote Access and Session Threats

In authorised-push-payment scams, the victim’s own device is used against them, controlled remotely while the fraudster guides the transaction by phone. This cluster identifies sessions where the device is under external control.

  • Remote-access application detection (presence and count)
  • Active screen mirroring identification
  • Accessibility-service abuse detection
  • Indicators of coached or externally directed interaction

Network and Location Intelligence

The network context of a session reveals what the device’s own identifiers may conceal. In the Indian market, where CGNAT renders IP-based signals unreliable across most mobile networks, this layer provides a materially more reliable read.

  • VPN, proxy, and unsecured network detection
  • GPS spoofing identification
  • IP-level intelligence: geolocation, ISP, ASN, fraud score
  • SIM data: count, swap history, eSIM detection, carrier

Apographic Intelligence

The applications installed on a device carry risk, affluence, and behavioural signals that no document or bureau score contains. This cluster reads the app portfolio and derives category-level intelligence from it.

  • Category-level affinity scores: lending, finance, gaming, entertainment, productivity
  • Lending application density as a credit-seeking signal
  • Premium application presence as an affluence indicator

What Device Intelligence Returns

Real-time per session. Three consumption tiers.

A device emitting individual device signals as structured data

Raw Signals

The full set of device-level attributes as structured data. Every signal is individually accessible for institutions that integrate directly into their own decisioning logic.

  • Device identifier and persistence data
  • Integrity flags and RASP indicators
  • Remote-access and session-threat markers
  • Network intelligence and SIM data
  • Appographic analysis and category affinity scores
  • Geolocation
A scorecard reading the device signals into a risk score

Pre-Built Scores

Two risk scores per session, each accompanied by the rules that fired and the factors that contributed. The verdict is transparent and auditable.

  • Device risk score (full device history across all sessions)
  • Session risk score (current session signals)
  • Applied rules with per-rule breakdown
  • Recommended action: allow, warn, or block
device signals feeding a configurable risk model

Custom Risk Models

Scoring models and rule configurations calibrated to the institution's own fraud patterns and device population. The same device signal carries different weight at a bank versus a gaming platform. Sign3 configures accordingly.

Where It Applies

Four deployments, each reading the device for a different decision.

Fraud prevention

Fraud prevention

Emulator and device-farm detection, multi-accounting, fraud ring linkage, SIM-swap identification

Onboarding

Onboarding

Device integrity verification at account creation or loan application

Monitoring

Monitoring

Continuous device and session consistency across the account lifecycle

Scam prevention

Scam prevention

Remote-access detection during live sessions

Integration

The SDK sits alongside your existing stack. No change to your decisioning logic, no data migration, no replacement of systems already in production.

SDK connecting a mobile app and a code editor

Delivery

SDK (Android, iOS, Web).

SDK footprint

Under 1MB.

Response time

Real-time, per session.

Timeline

3–4 weeks.

Compliance

Non-PII data collection. DPDP Act compliant. GDPR compliant.

Run your last week of traffic through Sign3.

We'll score it, surface the fraud patterns your current stack missed, and walk you through what we found. Your data, our scoring. No commitment, no integration, no decision required until you've seen the result.