Fraud scoring for SaaS accounts.

A single 0–100 risk score on a visit, an IP, or a session has to answer four different questions at once. Is this a bot? Is the identity fake? Is this another account from someone you already know? Is the behavior abusive? Those are different problems. Folding them into one number is how a legitimate customer on a shared network gets blocked, and how a second trial on a clean residential IP gets counted as growth.

Fraud scoring for a SaaS account should stay continuous and multi-dimensional. Dregs keeps four identity scores on every account (Humanity, Authenticity, Uniqueness, and Behavior) and recomputes them moments after new activity. Badges, escalations, the API, and webhooks are how those scores become a decision in your product.

What Is Fraud Scoring?

Fraud scoring is the practice of turning evidence about an account into numbers your application can act on. The account is the unit a SaaS company actually manages: the identity you bill, support, limit, or remove. A fraud score that only describes the current request leaves that account unjudged.

The score has to stay current. A signup can look ordinary and a week of usage can look like a script, a second seat, or a promo collected again. Dregs updates the four scores as events arrive, and each score opens into its observations so you can see exactly why it moved. The computation itself, analyzer by analyzer, is covered on identity scoring.

One Number Hides Which Problem You Have

Operators usually meet this as junk in the user table: fake signups, burned trials, duplicate accounts, and bots that made it past the form. A blended fraud score reports "risky" and stops there. The response you want depends on which failure it is.

Bot versus person Automation can complete a signup that looks perfectly filled in. The right control is humanity, not a ban on the email domain.
Fake identity versus real customer Disposable inboxes, keyboard-mashed names, and junk profile data are an authenticity problem. A real customer on a new laptop is not.
Another account versus a first one Multi-account abuse, ban evasion, and repeat trials show up as the same operator under a new email. That is uniqueness, not "this IP looks bad."
Bad behavior versus a normal journey A genuine person can still farm a referral, stack a promo, hammer logins, or request verification texts that nobody completes. Behavior is the dimension that watches what the account does after it exists.

Keeping the four apart is also how you hold false positives down. A household that shares a laptop can look non-unique and still be human, authentic, and well behaved. A single blended score has to punish the whole account for the one awkward signal.

An Account Score Is Not a Visit or IP Score

Search results for "fraud score" are crowded with a different product. Visit-risk scoring, traffic-quality scoring, and IP fraud scores rate a request or a network address: bot likelihood on a page view, proxy and hosting flags, reputation lists. That work belongs next to a CDN, an ad platform, or a bot wall. It answers whether this connection looks trustworthy right now.

SaaS abuse is an account problem. The same person comes back with a new email, a normal residential IP, and a browser that passed the edge check. An IP fraud score will often call that visit clean. It will also call a paying customer risky because the office NAT, the campus network, or a VPN exit sits on a noisy range. Account fraud scoring follows the identity: device, profile, relationships to other accounts, and behavior over time.

Dregs does not replace a traffic filter, and it does not replace card declining or dispute tooling. It scores the accounts those tools never see as accounts. Cutting fake signups and repeat abuse earlier can also mean fewer bad accounts reach a payment, but the fraud score here is the identity's, not the transaction's.

Four Scores, Kept Separate

Each score is a 0–100 value on the account, updated as events arrive. This is the short map. The product walkthrough, including how observations roll up and how to read them in the dashboard, is identity scoring.

Humanity

Whether a person is driving the session, or a script is. Low Humanity is bots, headless browsers, and automation that got past a signup form.

Humanity score →

Authenticity

Whether the claimed identity looks real. Low Authenticity is disposable email, mashed names, and profile data nobody would attach to themselves.

Authenticity score →

Uniqueness

Whether this is the operator's only account. Low Uniqueness is a shared device, a repeated session, or a cluster of signups that resolve to one party.

Uniqueness score →

Behavior

Whether usage looks like a customer. Low Behavior is scripted navigation, referral or promo patterns, unfinished verification texts, and activity that diverges from your real users.

Behavior score →

From Fraud Score to Action

A score that only sits on a chart does not stop abuse. Dregs routes the current scores into the same places your team and your application already make decisions, so the obvious cases need less manual review.

Badges Labels applied when an account matches a rule: a low Humanity score, a repeated trial, a suspected takeover. The label is yours. The evidence stays attached to the score.
Escalations A case for the accounts a person should look at, with status your team can work. Delivery goes to email, Slack, or a webhook. The dashboard is always there for the rest.
API and webhooks Your application reads the latest scores, or receives them as they change, and acts: hold a trial, step up a check, block a promo, or leave a clean account alone.
Custom rules and lists Built-in analyzers cover the common patterns. On the Advanced plan you add your own rules and lists, and those observations land in the same four scores.

The surrounding platform is fraud detection: device fingerprinting, behavioral analytics, and the identity graph all feed this scoring. Fraud scoring is the decision layer those signals roll up to.

Where Account Fraud Scoring Shows Up

Each pattern below is a different mix of the four scores. A blended visit score treats them as one incident. The use-case pages walk the pattern itself.

Included With Every Plan

Fraud scoring ships with every Dregs plan, billed on active identities. Plans start at $17/month. See pricing for limits, and identity scoring for how the four scores are produced.

Frequently Asked Questions

Q: What is fraud scoring?

A: Fraud scoring turns evidence about an account into numbers your product can act on. For a SaaS application, the useful unit is the account itself: the identity you bill, support, limit, or remove. Dregs keeps four continuous scores on that account (Humanity, Authenticity, Uniqueness, and Behavior) and recomputes them as events arrive, so a signup, a later login, and a week of usage can each change the read.

Q: How is an account fraud score different from an IP fraud score?

A: An IP fraud score rates a network address: reputation lists, proxy or hosting flags, and sometimes a visit's bot likelihood. That number describes the connection, not the customer. A paying user on a VPN, a campus network, or a mobile carrier can look risky on the IP while the account is fine, and a fresh residential IP can look clean while the account is the fourth trial, a fake profile, or a returning ban. Account fraud scoring judges the identity across devices, profile data, and behavior, and it keeps that judgment as the account continues.

Q: What is the difference between fraud scoring and visit or traffic-quality scoring?

A: Visit and traffic-quality scores answer a request-time question: should this page view, session, or click be trusted? They are built for ad fraud, scraping, and bot walls. SaaS fraud scoring answers an account question: is this signup a bot, a fabricated identity, another account from someone you already have, or a real person behaving badly? One visit score has to mash those together. Four account scores keep them apart, which is how you avoid false positives on legitimate users who merely share a network.

Q: Why not use a single 0–100 fraud score?

A: A single score hides which problem you have. A low number might mean automation, a disposable email, a shared device, or abusive usage, and the right response is different in each case. Blocking all of them the same way creates false positives. Dregs still gives you a current view per account, but it is four scores, each of which opens into its observations so you can see exactly why that dimension moved.

Q: How do fraud scores become an action?

A: Scores describe risk. Badges label it when an account matches a rule you set, such as a low Humanity score or a registration-bombing pattern. Escalations open a case your team can work, with delivery to email, Slack, or a webhook. The API and webhooks send the current scores back to your application so you can gate a trial, require a check, or hold a promo. Manual review stays for the ambiguous cases.

Q: Where is the full explanation of the four scores?

A: The mechanics live on the identity scoring page: how analyzers produce observations, how the four scores are aggregated, and how to read them in the dashboard. This page is the category argument. Each score also has its own page: Humanity, Authenticity, Uniqueness, and Behavior.

Score SaaS accounts for fraud before the next signup lands.

Dregs protects your user table with four continuous fraud scores on every account, then routes them to badges, escalations, and webhooks so the obvious abuse does not wait on manual review.

Schedule a Demo