Fraud scoring for SaaS accounts.
A single 0–100 risk score on a visit, an IP, or a session has to answer four different questions at once. Is this a bot? Is the identity fake? Is this another account from someone you already know? Is the behavior abusive? Those are different problems. Folding them into one number is how a legitimate customer on a shared network gets blocked, and how a second trial on a clean residential IP gets counted as growth.
Fraud scoring for a SaaS account should stay continuous and multi-dimensional. Dregs keeps four identity scores on every account (Humanity, Authenticity, Uniqueness, and Behavior) and recomputes them moments after new activity. Badges, escalations, the API, and webhooks are how those scores become a decision in your product.
What Is Fraud Scoring?
Fraud scoring is the practice of turning evidence about an account into numbers your application can act on. The account is the unit a SaaS company actually manages: the identity you bill, support, limit, or remove. A fraud score that only describes the current request leaves that account unjudged.
The score has to stay current. A signup can look ordinary and a week of usage can look like a script, a second seat, or a promo collected again. Dregs updates the four scores as events arrive, and each score opens into its observations so you can see exactly why it moved. The computation itself, analyzer by analyzer, is covered on identity scoring.
One Number Hides Which Problem You Have
Operators usually meet this as junk in the user table: fake signups, burned trials, duplicate accounts, and bots that made it past the form. A blended fraud score reports "risky" and stops there. The response you want depends on which failure it is.
Keeping the four apart is also how you hold false positives down. A household that shares a laptop can look non-unique and still be human, authentic, and well behaved. A single blended score has to punish the whole account for the one awkward signal.
An Account Score Is Not a Visit or IP Score
Search results for "fraud score" are crowded with a different product. Visit-risk scoring, traffic-quality scoring, and IP fraud scores rate a request or a network address: bot likelihood on a page view, proxy and hosting flags, reputation lists. That work belongs next to a CDN, an ad platform, or a bot wall. It answers whether this connection looks trustworthy right now.
SaaS abuse is an account problem. The same person comes back with a new email, a normal residential IP, and a browser that passed the edge check. An IP fraud score will often call that visit clean. It will also call a paying customer risky because the office NAT, the campus network, or a VPN exit sits on a noisy range. Account fraud scoring follows the identity: device, profile, relationships to other accounts, and behavior over time.
Dregs does not replace a traffic filter, and it does not replace card declining or dispute tooling. It scores the accounts those tools never see as accounts. Cutting fake signups and repeat abuse earlier can also mean fewer bad accounts reach a payment, but the fraud score here is the identity's, not the transaction's.
Four Scores, Kept Separate
Each score is a 0–100 value on the account, updated as events arrive. This is the short map. The product walkthrough, including how observations roll up and how to read them in the dashboard, is identity scoring.
Humanity
Whether a person is driving the session, or a script is. Low Humanity is bots, headless browsers, and automation that got past a signup form.
Authenticity
Whether the claimed identity looks real. Low Authenticity is disposable email, mashed names, and profile data nobody would attach to themselves.
Uniqueness
Whether this is the operator's only account. Low Uniqueness is a shared device, a repeated session, or a cluster of signups that resolve to one party.
Behavior
Whether usage looks like a customer. Low Behavior is scripted navigation, referral or promo patterns, unfinished verification texts, and activity that diverges from your real users.
From Fraud Score to Action
A score that only sits on a chart does not stop abuse. Dregs routes the current scores into the same places your team and your application already make decisions, so the obvious cases need less manual review.
The surrounding platform is fraud detection: device fingerprinting, behavioral analytics, and the identity graph all feed this scoring. Fraud scoring is the decision layer those signals roll up to.
Where Account Fraud Scoring Shows Up
Each pattern below is a different mix of the four scores. A blended visit score treats them as one incident. The use-case pages walk the pattern itself.
Free Trial Abuse
The same operator, a fresh email, and another trial. Uniqueness and authenticity carry it.
Fake Signups
Junk profiles and disposable inboxes, scored as authenticity at submission.
Duplicate Accounts
Several accounts, one operator. The fraud score that matters is uniqueness.
Bot Detection
Automation that passes a form still fails Humanity once the session behaves like a script.
Promo Abuse
Credits and coupons collected more than once, tied together by device and redemption behavior.
Ban Evasion
A removed account back under a new email, on a device and network you have already seen.
Referral Fraud
A referrer and the accounts they referred, when those accounts are not other people.
SMS Pumping
Verification texts requested and never completed. Behavior carries the unfinished codes.
Included With Every Plan
Fraud scoring ships with every Dregs plan, billed on active identities. Plans start at $17/month. See pricing for limits, and identity scoring for how the four scores are produced.
Frequently Asked Questions
Q: What is fraud scoring?
A: Fraud scoring turns evidence about an account into numbers your product can act on. For a SaaS application, the useful unit is the account itself: the identity you bill, support, limit, or remove. Dregs keeps four continuous scores on that account (Humanity, Authenticity, Uniqueness, and Behavior) and recomputes them as events arrive, so a signup, a later login, and a week of usage can each change the read.
Q: How is an account fraud score different from an IP fraud score?
A: An IP fraud score rates a network address: reputation lists, proxy or hosting flags, and sometimes a visit's bot likelihood. That number describes the connection, not the customer. A paying user on a VPN, a campus network, or a mobile carrier can look risky on the IP while the account is fine, and a fresh residential IP can look clean while the account is the fourth trial, a fake profile, or a returning ban. Account fraud scoring judges the identity across devices, profile data, and behavior, and it keeps that judgment as the account continues.
Q: What is the difference between fraud scoring and visit or traffic-quality scoring?
A: Visit and traffic-quality scores answer a request-time question: should this page view, session, or click be trusted? They are built for ad fraud, scraping, and bot walls. SaaS fraud scoring answers an account question: is this signup a bot, a fabricated identity, another account from someone you already have, or a real person behaving badly? One visit score has to mash those together. Four account scores keep them apart, which is how you avoid false positives on legitimate users who merely share a network.
Q: Why not use a single 0–100 fraud score?
A: A single score hides which problem you have. A low number might mean automation, a disposable email, a shared device, or abusive usage, and the right response is different in each case. Blocking all of them the same way creates false positives. Dregs still gives you a current view per account, but it is four scores, each of which opens into its observations so you can see exactly why that dimension moved.
Q: How do fraud scores become an action?
A: Scores describe risk. Badges label it when an account matches a rule you set, such as a low Humanity score or a registration-bombing pattern. Escalations open a case your team can work, with delivery to email, Slack, or a webhook. The API and webhooks send the current scores back to your application so you can gate a trial, require a check, or hold a promo. Manual review stays for the ambiguous cases.
Q: Where is the full explanation of the four scores?
A: The mechanics live on the identity scoring page: how analyzers produce observations, how the four scores are aggregated, and how to read them in the dashboard. This page is the category argument. Each score also has its own page: Humanity, Authenticity, Uniqueness, and Behavior.
Score SaaS accounts for fraud before the next signup lands.
Dregs protects your user table with four continuous fraud scores on every account, then routes them to badges, escalations, and webhooks so the obvious abuse does not wait on manual review.
Schedule a Demo