Device Intelligence - Single Tenant - US
Device Intelligence - Single Tenant - US
Capabilities
The module returns the following capabilities.Threat device score
Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.Behavioral indicators
Behavioral IndicatorsUsers seen on device
Users Seen on DeviceThreat BOT score
Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).Identity device score
Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).Days since user first seen
Days Since User First SeenIP address indicators
IP Address IndicatorsDays since device last seen
Days Since Device Last SeenTimes user seen
Times User SeenDevices seen on user
Devices Seen on UserThreat keystrokes score
Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.Bot and RAT indicators
Bot and RAT IndicatorsMalware indicators
Malware IndicatorsIdentity mouse score
Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.Threat RAT score
Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).Days since user last seen
Days Since User Last SeenInternet connection type
Internet Connection TypeThreat location score
Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).IP address geo-Location
IP Address Geo-LocationDevice language
Device LanguageLocation type
Location TypeThreat score
Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.Identity keystrokes score
Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.Device indicators
Device IndicatorsDevice model error
Device Model ErrorTime based indicators
Time Based IndicatorsTimes device seen
Times Device SeenCompromise indicators
Compromise IndicatorsThreat mouse score
Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.Location indicators
Location IndicatorsDevice OS
Device OSIdentity score
Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.Time zone offset
Time Zone OffsetIdentity location score
Location match — how consistent the location is with the user’s known mobility / location history.Time zone region
Time Zone RegionDevice type
Device TypeDevice category
Device CategoryDevice language country
Device Language CountryThreat indicators
Threat IndicatorsKeystrokes and mouse behavior
Keystrokes and Mouse BehaviorDays since device first seen
Days Since Device First SeenDefault outcomes
The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.Input payload
The following is a sample payload used to submit data to the Device Intelligence - Single Tenant - US module for processing.JSON
Sample response
The following is a sample response returned by the module.JSON
Device Intelligence - Single Tenant - AU
Device Intelligence - Single Tenant - AU
Capabilities
The module returns the following capabilities.Threat device score
Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.Behavioral indicators
Behavioral IndicatorsUsers seen on device
Users Seen on DeviceThreat BOT score
Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).Identity device score
Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).Days since user first seen
Days Since User First SeenIP address indicators
IP Address IndicatorsDays since device last seen
Days Since Device Last SeenTimes user seen
Times User SeenDevices seen on user
Devices Seen on UserThreat keystrokes score
Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.Bot and RAT indicators
Bot and RAT IndicatorsMalware indicators
Malware IndicatorsIdentity mouse score
Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.Threat RAT score
Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).Days since user last seen
Days Since User Last SeenInternet connection type
Internet Connection TypeThreat location score
Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).IP address geo-Location
IP Address Geo-LocationDevice language
Device LanguageLocation type
Location TypeThreat score
Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.Identity keystrokes score
Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.Device indicators
Device IndicatorsDevice model error
Device Model ErrorTime based indicators
Time Based IndicatorsTimes device seen
Times Device SeenCompromise indicators
Compromise IndicatorsThreat mouse score
Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.Location indicators
Location IndicatorsDevice OS
Device OSIdentity score
Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.Time zone offset
Time Zone OffsetIdentity location score
Location match — how consistent the location is with the user’s known mobility / location history.Time zone region
Time Zone RegionDevice type
Device TypeDevice category
Device CategoryDevice language country
Device Language CountryThreat indicators
Threat IndicatorsKeystrokes and mouse behavior
Keystrokes and Mouse BehaviorDays since device first seen
Days Since Device First SeenDefault outcomes
The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.Input payload
The following is a sample payload used to submit data to the Device Intelligence - Single Tenant - AU module for processing.JSON
Sample response
The following is a sample response returned by the module.JSON
Device Intelligence - Single Tenant - EU
Device Intelligence - Single Tenant - EU
Capabilities
The module returns the following capabilities.Threat device score
Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.Behavioral indicators
Behavioral IndicatorsUsers seen on device
Users Seen on DeviceThreat BOT score
Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).Identity device score
Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).Days since user first seen
Days Since User First SeenIP address indicators
IP Address IndicatorsDays since device last seen
Days Since Device Last SeenTimes user seen
Times User SeenDevices seen on user
Devices Seen on UserThreat keystrokes score
Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.Bot and RAT indicators
Bot and RAT IndicatorsMalware indicators
Malware IndicatorsIdentity mouse score
Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.Threat RAT score
Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).Days since user last seen
Days Since User Last SeenInternet connection type
Internet Connection TypeThreat location score
Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).IP address geo-Location
IP Address Geo-LocationDevice language
Device LanguageLocation type
Location TypeThreat score
Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.Identity keystrokes score
Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.Device indicators
Device IndicatorsDevice model error
Device Model ErrorTime based indicators
Time Based IndicatorsTimes device seen
Times Device SeenCompromise indicators
Compromise IndicatorsThreat mouse score
Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.Location indicators
Location IndicatorsDevice OS
Device OSIdentity score
Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.Time zone offset
Time Zone OffsetIdentity location score
Location match — how consistent the location is with the user’s known mobility / location history.Time zone region
Time Zone RegionDevice type
Device TypeDevice category
Device CategoryDevice language country
Device Language CountryThreat indicators
Threat IndicatorsKeystrokes and mouse behavior
Keystrokes and Mouse BehaviorDays since device first seen
Days Since Device First SeenDefault outcomes
The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.Input payload
The following is a sample payload used to submit data to the Device Intelligence - Single Tenant - EU module for processing.JSON
Sample response
The following is a sample response returned by the module.JSON
Device Intelligence - Consortium
Device Intelligence - Consortium
Capabilities
The module returns the following capabilities.Threat device score
Device-modality threat — likelihood the device itself carries risk signals associated with known fraud.Behavioral indicators
Behavioral IndicatorsUsers seen on device
Users Seen on DeviceThreat BOT score
Likelihood the session is driven by a bot / non-human automation (e.g. headless browser, scripted actor).Identity device score
Device-modality match — how strongly the device fingerprint matches the genuine user’s known device(s).Days since user first seen
Days Since User First SeenIP address indicators
IP Address IndicatorsDays since device last seen
Days Since Device Last SeenTimes user seen
Times User SeenDevices seen on user
Devices Seen on UserThreat keystrokes score
Keystroke-dynamics threat — likelihood the typing behaviour is anomalous / replayed rather than a genuine user.Bot and RAT indicators
Bot and RAT IndicatorsMalware indicators
Malware IndicatorsIdentity mouse score
Mouse-behaviour match — how closely the pointer dynamics match the user’s established baseline.Threat RAT score
Likelihood a remote-access tool is controlling the session (remote takeover / scam-in-progress).Days since user last seen
Days Since User Last SeenInternet connection type
Internet Connection TypeThreat location score
Location-modality threat — likelihood the location signals indicate risk (e.g. impossible travel, spoofing).IP address geo-Location
IP Address Geo-LocationDevice language
Device LanguageLocation type
Location TypeThreat score
Threat Score — an overall risk rating for the session, from 0 to 100. A higher score means stronger signs of fraud or automated/malicious activity (such as bots, remote-access tools, malware, or anonymised connections). Used to set the journey’s Risk Level: 80+ High Risk, 40–79 Medium Risk, below 40 Low / Very Low Risk.Identity keystrokes score
Keystroke-dynamics match — how closely the typing rhythm matches the user’s established baseline.Device indicators
Device IndicatorsDevice model error
Device Model ErrorTime based indicators
Time Based IndicatorsTimes device seen
Times Device SeenCompromise indicators
Compromise IndicatorsThreat mouse score
Mouse-behaviour threat — likelihood the pointer dynamics are anomalous / automated.Location indicators
Location IndicatorsDevice OS
Device OSIdentity score
Ensembled (aggregate) identity score — overall likelihood the user is who they claim to be, across all identity modalities. Second-stage gate for Very Low / Low Risk.Time zone offset
Time Zone OffsetIdentity location score
Location match — how consistent the location is with the user’s known mobility / location history.Time zone region
Time Zone RegionDevice type
Device TypeDevice category
Device CategoryDevice language country
Device Language CountryThreat indicators
Threat IndicatorsKeystrokes and mouse behavior
Keystrokes and Mouse BehaviorDays since device first seen
Days Since Device First SeenDefault outcomes
The module is pre-configured with the following default outcomes, which can be used in evaluation and routing logic within the journey designer.Input payload
The following is a sample payload used to submit data to the Device Intelligence - Consortium module for processing.JSON
Sample response
The following is a sample response returned by the module.JSON