A forged identity can be convincing; the device behind it, the egress point and the contact details usually are not. Krino derives these traces on every event and offers them to your rules like any other field.
A stable identifier is derived from what the browser reports about itself — screen, language, timezone, platform, plugin set. Clear the cookies, end the session, open a private tab: the same device still appears under the same trace.
The country and autonomous system of the egress point are read from an offline database. Datacenter ranges — which is where most VPN and proxy traffic exits — are flagged separately.
The domain is checked against known disposable and throwaway providers. Variants built with dots and plus-addressing collapse to one address — so ten accounts that look different count as one.
The number is normalised to international form, the country and carrier extracted, the line type determined. Virtual and VoIP numbers are flagged as their own category.
Most of these signals are sold as per-query services. Krino reads them from lists held inside your infrastructure, for three reasons.
Every outbound query tells a third party that this customer is doing this thing right now. Reading locally removes that entirely.
A decision inside a payment flow cannot wait on three external responses. Local lookups are measured in milliseconds and survive a vendor outage.
Per-query pricing makes teams trim their rules as volume grows. A flat licence removes that pressure — look at as many signals as you like.
Offline does not mean stale. A scheduled job pulls the IP and email-provider lists from their sources on a regular cadence and swaps them in when the new version is ready. The download only fetches the list — which customer matched what never leaves.
A sample of last month's transactions is enough to see how much each signal catches.