IP, email, phone, domain, device and behavioral intelligence with a real-time 0-100 fraud risk engine — deployed on your own infrastructure, with every detection module independently configurable.
Illustrative — try a real lookup in the Playground
Most fraud detection tools focus on a single signal — IP reputation, email validation, device fingerprinting, or phone intelligence — and return isolated results, leaving you to connect the dots yourself.
WHA Shield brings the complete picture together. It combines IP & network intelligence, email, phone, domain, device, and behavioral signals into a single real-time 0–100 fraud score, complete with human-readable reasons explaining why a transaction or user was flagged.
Behind the score is a configurable weighted risk engine that lets you tune individual modules, adjust sensitivity levels, and control how each signal contributes to the final decision.
And instead of relying on a black-box score you simply have to trust, WHA Shield can use your confirmed fraud outcomes to continuously refine your scoring strategy — helping your fraud detection become more aligned with your actual business patterns over time.
One platform. Multiple signals. Explainable decisions. A fraud score you can control.
Each use case below is a real combination of the detection modules on this platform — not a separate product.
IP reputation, device fingerprinting, and login-velocity checks flag credential-stuffing and session-hijack attempts at sign-in.
Combine IP, email, phone and domain checks with the risk engine to score a transaction before it settles.
Disposable email/phone detection and device fingerprinting catch bulk fake registrations before they reach your database.
Bot signature matching, DNS-verified crawler identity, and mouse/keystroke timing analysis separate humans from scripts.
URL and domain scanning against blacklist feeds (Spamhaus, URLhaus) stops malicious links before they're shared.
Built-in geo-fencing and privacy tooling (retention, anonymization, export) support region-restricted and GDPR/CCPA workflows.
GeoIP, ASN/hosting detection, VPN/proxy/TOR flags and DNSBL blocklist checks with a pluggable provider architecture.
Disposable-domain, MX, VOIP and role-account detection, plus domain/URL blacklist and phishing checks.
Browser device fingerprinting, headless/automation detection, and mouse/keystroke interaction timing.
Admin-tunable 0-100 fraud score with confidence and human-readable reasons, trainable from your own confirmed-fraud outcomes.
Blacklists/whitelists across IP, CIDR, ASN, email, domain and device, plus a programmatic abuse-report queue.
Per-scope, per-key rate limits with daily/monthly quotas, full request logging, and usage analytics.
Every check returns a 0-100 fraud score with human-readable reasons. Your risk thresholds map that score to a decision — the ranges below are an example configuration, not a fixed default; every threshold is admin-configurable per instance.
| Score range (example) | Risk level | Recommended action |
|---|---|---|
| 0 – 24 | Low risk | APPROVE — let it through |
| 25 – 54 | Elevated risk | REVIEW — needs a human look |
| 55 – 79 | High risk | CHALLENGE — add step-up verification |
| 80 – 100 | Critical risk | BLOCK — reject outright |
Every real-time check flows through the same weighted risk engine — each stage below is a real detection module, not a marketing simplification.
Sign up and land in the Customer Portal — every account starts on a real, enforced free tier.
Pick exactly which checks a key can call — your plan caps which scopes are available.
Get a real-time 0-100 fraud score with reasons back on every request — see the full API reference.
Illustrative preview of the real Customer Portal dashboard — sample data, same layout every account gets.
Get started with 1,000 free fraud validations to evaluate WHA Shield before upgrading.
Protect transactions with multi-signal fraud detection and real-time risk scoring.
Create and customize fraud rules to match your business requirements and risk policies.