Fraud Rules Engine

Fraud detection system that adapts to your business. Define metrics, set signals, adjust thresholds, and make every fraud decision from the dashboard, no code required. Any threat model, any industry.
Start for Free
Fraud detection
Signal
Signal

Fraud Decision Engine You Control

You define what to measure, what counts as suspicious, how to classify the threat, and when to block. Every fraud rule adjustable per project, per fraud class, per fraud pattern your business actually faces.

Define your metrics

Set your signals

Control your thresholds

Update without code

shield
300M+
BotBye:\Requests Analyzed Daily
1M+
BotBye:\Bots Detected Every Day
10+
BotBye:\Attack Types Protected Against

How Rule-Based Fraud Detection Works

Step 1

Event

Send any user action — login, registration, transaction, or custom event. You choose which actions to score.
IDIP AddressEventDate
country-TUR203.0.113.164login16:44:3312.08.2026
country-IND198.51.100.123register16:44:2112.08.2026
country-CHN192.0.2.246reset_password16:44:1912.08.2026
country-DEU203.0.113.114withdrawal16:44:1812.08.2026
Step 2

Metrics

The engine builds a real-time behavioral profile for every account, IP, and device. You always know what’s being measured and why.
events_1hMetric
ip_24hMetric
devices_1hMetric
Step 3

Signals

Tune the thresholds to fit your risk model. Multiple signals fire at once, each adding a weighted score to its fraud class. A weak signal alone won’t block a real user, but together they catch attacks with fewer false positives.
multi_accountingSignal
account_sharingSignal
Step 4

Decision

One response, ready to enforce: ALLOW, CHALLENGE, or BLOCK — with full breakdown of scores and triggered signals.
botFraud class
Block0.9
Challenge0.7

Why Risk Scoring Works Better

Adaptive Fraud Detection

Metrics, signals, fraud classes, thresholds – everything is configured per project. Different products can run entirely different risk profiles suited to their specific threat model.
iGaming
Allowed38.01K
Declined27
Total38.04K
E-Commerce
Allowed12.31K
Declined168
Total12.48K

Real-Time Metrics

Risk profiles update with every event. The engine always reflects the current state — enabling sub-second detection of attacks as they happen.

Dynamic Configuration

Create, update, or delete any metric or signal: changes take effect immediately. No redeployment, no engineering tickets, no downtime.
ip_velocity
Signal
geo_distance
System Metric
asn_reputation
Signal

Built-in + Custom Rules

Battle-tested signals for common attacks work out of the box. As you learn your traffic, add custom metrics and signals for any threat specific to your business.
Built-in
brute_force
impossible_travel
credential_stuffing
multi_accounting
CustomAdd
non_legal_ip
trouble_stuffing
ip_duplicate
promo_abuse
same_users

Weighted Risk Scoring

Each signal adds a score you define to its fraud class. Example: Brute force adds 0.4 to ATO score. Credential stuffing adds 0.35. Combined ATO score: 0.75 → exceeds block threshold (0.7) → BLOCK.
multi_accountingSignal
account_sharingSignal
excessive_usageSignal
SUMMING...

Custom Fraud Classes

Three built-in classes Bot, ATO, and Abuse work out of the box. Need more? Create any fraud class that fits your business logic, name it however you want, and assign its own thresholds and signals.
botFraud class
Block0.9
Challenge0.7
reportedFraud class
Block0.6
Challenge0.3
unfilteredFraud class
Block0.8
Challenge0.7

Computed Metrics

Some fraud patterns can't be captured by counters alone. Computed metrics combine stored data with the current request in real time to detect complex patterns like impossible travel.
impossible travel
800km15min

Self-Learning Scoring

Every request the engine evaluates also updates its metrics. One integration, two outcomes: real-time protection and continuously improving accuracy.

See the Fraud Rules Engine in Action

Book a live demo — we'll walk you through metrics, signals, and scoring on real data.

Easy for developers to integrate

Developers can get started quickly with our robust developer features including intuitive APIs and extensive documentation.

Client-side integration

Add bot protection to your frontend with a single NPM package.
Read the docs

Server-side integration

SDKs for Java, Node.js, Kotlin, PHP, and more. Validate tokens and enforce decisions with a few lines of code.
Read the docs

Protection for Every Threat

Keep your websites, apps, and APIs secure with instant protection from day one and full control as you scale.
From SpamStopping automated junk submissions through forms.
Multi-AccountingDetecting users operating multiple linked accounts.
API AbuseBlocking excessive and unauthorized API requests.
Brute Force AttackBlocking fake user registrations attempts.
Account TakeoverPreventing unauthorized logins with stolen credentials.
Data ScrapingBlocking bots that harvest your content.
Coupon FraudPreventing abuse of promo codes and discounts.
Account SharingDetecting credentials shared across many users.
Fake AccountBlocking automated credential attacks.

FAQ

How does a risk scoring engine differ from traditional rule-based fraud detection?
Traditional systems use binary logic: a rule either fires or it doesn't. BotBye Risk Scoring Engine uses weighted score accumulation across multiple signals and fraud classes. A single weak signal won't block a legitimate user, but multiple signals converging on the same fraud class will catch the attack. The result is fewer false positives and more accurate detection.
Can I configure metrics and signals without writing code?
Yes. All metrics, signals, fraud classes, and thresholds are configured from the dashboard. Changes take effect immediately, with no engineering involvement or redeployments.
What fraud types does the engine detect out of the box?
Every project ships with built-in signals for brute force, credential stuffing, impossible travel, IP velocity, multi-accounting, account sharing, and excessive usage, mapped to three fraud classes: Bot, ATO, and Abuse.
How does score accumulation reduce false positives?
Instead of blocking on a single rule match, the engine sums scores from multiple signals within each fraud class, capped at 1.0. A mild brute force signal (0.2) alone won't trigger a block. But if credential stuffing (0.35) and impossible travel (0.5) also fire, the combined ATO score crosses the threshold. Only genuinely suspicious behavior gets blocked.
What is a composite key and why does it matter?
A composite key combines device fingerprint and IP address into a single aggregation dimension. This prevents a common evasion technique: attackers spoofing device fingerprints are still caught because the composite key requires both dimensions to match.
How quickly can I integrate the risk scoring engine?
Integration takes minutes. The engine is built into every BotBye project. Add the client-side integration and the server-side SDK. We support all major frameworks and languages. Don't see your stack? Contact us, and we'll find a way to make it work.
Does the engine work with custom event types?
Yes. Send any event type — login, registration, transaction, password reset, or any custom event. You can also pass arbitrary custom fields and create metrics that filter or aggregate by those values.
What is the pricing for the risk scoring engine?
The Risk Scoring Engine is included in all BotBye plans, starting with a free tier. Paid plans start at $10/month and scale with your traffic.

Start Detecting Fraud in Real Time

Free tier available. Built-in metrics and signals active from day one. No credit card required.
Start for Free