Every fraud check WHA Shield runs produces individual signals, such as a VPN detection, a DNSBL listing, or a disposable-email match. Rather than adding these up as one flat number, the risk engine groups them into categories, each with its own point cap, so no single detector can dominate the final score.
The default categories are IP Reputation, Infrastructure, Threat Intelligence, and Geo/IP. An administrator can adjust which signals belong to which category, each category weight, and the overall score thresholds that map to APPROVE, REVIEW, and DECLINE, from Admin -> Settings.
You can experiment with this live using the Scoring Simulation tool in the admin portal, which lets you toggle individual signals on and off and see the resulting category breakdown and final score before it affects real traffic.