Home Platform Behavioural Detection
Fraud & Risk Intelligence

Behavioural Detection

Session and cross-journey behavioural analysis that surfaces suspicious patterns across timing, identity reuse and linked-account signals.

Built for Enterprise Integration
Behavioural Insights · Cluster C-2041Risk · High
7 journeys linked across 5 clustering factors
Open cluster view ›
Same device · 4Same IP · 3Same reference no. · 2Same PII · different face · 1Same location · 3
MR
Marcus Rivera
Device pro-m106 · IP 185.12.4.9
UNDER REVIEW
EP
Elena Petrova
Device pro-m106 · Ref #88213
REFERRED
DC
David Chen
Same PII as Rivera · different face
REJECTED
SA
Sofia Andersen
IP 185.12.4.9 · cleared by analyst
PASSED
+3 more linked journeysExport reportReview journeys
How it works

Detect coordinated activity, synthetic identities, and repeat offenders, in real time.

Behavioural Insights: 7 journeys linked across 5 clustering factors
1
Behavioral signals collected during journey
The system tracks submission timing, session cadence, field input patterns, and identity reuse signals across all steps.
2
Cross-journey clustering analysis runs
Journeys are clustered across device, reference number, PII, biometrics, and location to surface linked identities.
3
Fraud patterns flagged and scored
Multiple users from the same device, same reference number, different faces on the same ID, and same-location clusters are flagged.
4
Investigation report available for export
Compliance teams can view the bipartite cluster graph, export an investigation report, and flag all linked journeys for review simultaneously.

Why Enterprises Choose IDWise for Behavioural Detection

01
See the network, not the applicant
Cluster journeys that share devices, IPs, reference numbers or PII to reveal coordinated activity a single-journey check cannot see.
02
Catch synthetic identities
Same-PII-different-face and same-face-different-PII patterns surface manufactured identities before they are approved.
03
Prioritise investigations
Cluster factors are scored and ranked so analysts start with the highest-risk linked journeys, not a flat queue.
04
Give operations the full picture
Compliance and operations see every linked journey in one cluster view and decide the right action for each, clear, refer or reject, with an exportable investigation report.
Capabilities

Robust, enterprise-grade features built for regulated industries

Cross-Journey Clustering
Links journeys across the tenant by shared device, IP, reference number, location and PII to form suspect clusters.
Identity Reuse Signals
Same PII with a different face, same face with different PII, and repeated reference numbers across applications.
Timing & Velocity Patterns
Burst submissions, unusual session timing and repeated retries that indicate scripted or coordinated behaviour.
Investigation Workspace
Visual cluster view with ranked factors, per-journey decisions from a single screen and exportable investigation reports.
Feature detail

Everything you need for behavioural detection

Journeys sharing a device, IP, reference number, location or PII are grouped into clusters, each scored by the strength and number of shared factors.
Detects the same PII appearing with a different face, or the same face with different PII, the two clearest markers of synthetic or stolen identities.
Flags bursts of submissions, abnormal session timing and repeated retries that point to scripted or coordinated attempts.
Review the cluster visually, decide on each linked journey from one screen, and export an investigation report for compliance or referral.

Built for Enterprise Integration.

Simple API & SDK

Start with a few lines of code. Full sandbox, webhooks for every event, and docs your engineers will use.

Consistent controls across supported channels

Same fraud models, document coverage, and UX on iOS, Android, Web, React Native, and Flutter.

iOSAndroidWebReact NativeFlutterREST API
</> View documentation
integration.ts
// Start a journey with device-intelligence
const journey = await idwise.startJourney({
  flowId: 'your_flow_id',
  referenceNo: 'USR_000001'
});

// Receive result via webhook
app.get('journey/v2/get/12345667899', (req) => {
  const { decision } = req.body;
  // Passed | Refer | Rejected
});

Frequently asked questions

Shared device fingerprint, IP address, reference number, location, and PII overlap such as the same document number or name with a different face.
No. It surfaces linked journeys and ranked risk factors for review. Decisions, clear, refer or reject, are taken per journey by your compliance or operations team from the cluster view.
Yes. Each cluster can be exported as an investigation report containing the linked journeys, shared factors and evidence for compliance or law-enforcement referral.
Yes. Clustering runs across all journeys in the tenant, so a device or identity reused across different products or flows is still linked.

Talk to an IDWise Specialist about Behavioural Detection

Discuss your markets, regulatory requirements, risk controls and integration architecture with our team, and see how IDWise fits your operating model.