Cardvera reaches a verdict in milliseconds by combining four detection layers across the browser and the edge — and its velocity layer learns from what actually happened to each transaction.
One checkout request, start to finish: signals gathered in the browser, a verdict at the edge in milliseconds, a conditional silent step-up, a server-to-server pull before the card is charged — and the disposition flowing back to sharpen the next decision.
No layer is perfect on its own; we say so. Each one narrows the field and hands the rest to the next — which is exactly why beating one or two gets you nowhere.
Robotic cursor paths and missing micro-corrections, instant paste, uniform inter-key timing, ghost clicks, sub-human form-completion times — and scripted replays whose signals don't hang together across a session.
Automated clients identified by how they connect: headless browsers, Puppeteer / Playwright / Selenium, tampered runtimes, spoofed device fingerprints, datacenter origins, and residential-proxy networks.
Bot farms operating at scale — a silent background challenge that's free for one real customer but a real CPU cost per attempt for a farm running thousands. No CAPTCHA.
Decline bursts, low-and-slow enumeration, and coordinated probing across sessions, IPs, and devices.
L1–L3 exist to make a bad first attempt rare. L4's feedback loop is built so the second one fails: ground truth — what actually happened to the transaction — becomes the next block rule.
Your backend reports each transaction's real disposition through our Outcome API — no cardholder data required — and we mine it for confirmed-bad patterns. A mimic that slips through once trains the edge to stop the next one — automatically, without a human writing a rule.
Auth declines, $0-auth outcomes, and decline-reason codes — the earliest tells that a tested card was never going to settle.
What actually captured and shipped vs. what was immediately refunded — separating real orders from test traffic.
Confirmed fraud disputes, weeks later, that retroactively label a pattern as bad and feed the rule engine.
Your own confirmed-fraud and confirmed-good flags, weighted highest — the model adapts to your traffic, not a generic baseline.
Card testing is a volume business with thin margins per card. Our job isn't to be unbeatable — it's to make beating us cost more than it returns.
The layers are independent, so an attacker has to defeat all four simultaneously on every attempt. The moment one succeeds, its transaction resolves — and L4's feedback loop turns that success into a rule that closes the gap. The attacker isn't fighting a fixed target; they're fighting one that rewrites itself from their own failures. Against thin per-card economics, that's a losing trade.
Verdicts in milliseconds, in front of your gateway. Signed server-side, so they can't be spoofed from the browser.
Card numbers, CVVs, and expiry dates never pass through Cardvera. The browser library measures how the checkout is used, never what is typed — your PCI scope is unchanged.
A simple allow / step-up / block verdict. Call Stripe, Adyen, Checkout.com, or anything else after.
If Cardvera is ever unreachable, checkout proceeds untouched. Protection should never become the outage.
Drop the SDK on checkout, pull the verdict server-side before you charge. No rule tuning, no fraud team — built to go live in under an hour.