Built for

Fraud scoring for SaaS

Alex MugoFounder, Kaidn
3 min readRevised

Also called: software as a service · B2B SaaS · developer tools · API products

Why SaaS abuse is a cost problem rather than a theft problem, which events are worth scoring when nothing gets withdrawn, and when to fix packaging instead.

How the money moves

Customers pay a subscription and you serve them at a cost that used to be near zero and increasingly is not. Nothing gets withdrawn, so abuse shows up as a bigger infrastructure bill and numbers that quietly stop meaning anything. That is why it usually gets noticed late.

Where it leaves

  • arrow_outwardCompute and model inference on free tiers and trials. For anything touching a model this is the biggest line, and it grows with usage rather than headcount.
  • arrow_outwardBandwidth, storage and transcoding served to accounts that will never pay.
  • arrow_outwardPer-seat fees your own vendors charge you for users who are not real.
  • arrow_outwardYour email deliverability, when bulk fake signups poison your list and your real transactional mail starts landing in spam.
  • arrow_outwardSupport and onboarding time spent on accounts that come back forever and buy never.

What to score, and why these

Scoring everything is expensive and scoring the signup alone misses most of it. These are the events that carry the loss in SaaS.

The trial or free-tier signup

The gate on everything downstream, and the cheapest place to act. What matters is not whether the identity is valid but whether it resolves to somebody you have already served: plus-tagged variants, catch-all domains, and the same device coming back from a previous trial.

Crossing a usage threshold

The event most SaaS companies never send, and the most valuable one here. An account hammering your expensive endpoints in its first hours behaves nothing like an evaluator, and this signal keeps working no matter how many new identities they create, because it reflects what they want rather than who they say they are.

Login

For paid accounts, takeover is the real risk. A B2B account holds a customer's data and their integration credentials. Losing one is a security incident, not a fraud loss.

Creating or rotating an API key

Where a compromised account turns into permanent access. A key created from a device first seen four minutes ago is a very different thing from one created in a two-year-old session.

The patterns you will see

When we are not the answer

  • blockIf your product is expensive, sales-led, and every account is onboarded by hand, you do not have a volume abuse problem and you should not buy a scoring API for it.
  • blockIf your free tier is deliberately generous as a growth strategy, the abuse might be the strategy working. Measure what it costs before calling it a problem.
  • blockIf your losses are failed payments and cancelled cards, that is billing and dunning, not fraud scoring.
  • blockIf you need SOC 2 evidence or access reviews, that is compliance tooling. We do not produce it.

SaaS is the vertical where we most often tell people they do not need us yet, and the reason is structural. Nothing gets withdrawn. Nobody cashes out.

The loss shows up in an infrastructure bill and in numbers that quietly stop meaning anything. That is a slower and more forgiving failure than money leaving a wallet.

It changes the honest advice. In rewards the money is gone the moment a payout clears, so detection pays for itself immediately. Here you usually have time to ask whether the problem is worth solving at all.

Work out the unit cost first#

One question decides everything: what does one abusive account actually cost you to serve?

For a project-management tool it might be pennies. The right response is to fix your reporting so the numbers are honest, and otherwise ignore it.

For anything running model inference, rendering, or heavy bandwidth, the same account can cost real money in an afternoon, and the case for acting is immediate.

This is not a rhetorical exercise. The answer moves the decision by a factor of a hundred, and it is the first thing we would ask before selling you anything.

Packaging usually beats detection#

If the same person keeps cycling trials, the most reliable fix is often not to catch them. It is to remove the reason.

A trial that hands over the entire product's value in fourteen days will get cycled. A real free tier that is generous on cheap things and firm on expensive ones turns that person from an adversary into a funnel entry. A usage cap on the costly endpoint makes the abuse limit itself, no matter how many identities they create.

Those are product changes. They cost no vendor spend and they hold permanently. Detection is the layer for what is left, and it works much better when what is left is small.

The signal that survives a change of identity#

Everything a trial cycler shows you is disposable. The email, the name, often the card. So detection built on identity is always one step behind.

The usage curve is not disposable. A real evaluator starts slowly, explores, brings in a colleague, and leaves gaps because they have another job. A cycler front-loads, goes straight to the expensive endpoint, and stops dead when they have what they came for.

Sending us a custom event when an account crosses a meaningful usage threshold is the single highest value integration in this vertical, and it is the one most teams skip, because it is not the signup.

Do not ban the second person from a company#

The worst false positive in SaaS has a specific shape. A second evaluator at a company that was already considering you, sharing an office network and maybe a laptop, refused because they look like a duplicate.

The abuse cost you some compute. The false positive cost you the deal.

So the right outcome here is almost always to withhold the trial rather than block the account, and to treat several signups from one company domain as a sales signal rather than an abuse signal. Ten free webmail addresses is a pattern. Ten addresses at one company is a team evaluating you.

The two calls that carry a SaaS funnel#

The trial start, and the point where a free account starts costing you real money:

app/api/trial/route.ts
const r = await kaidn.score({
  event: "trial_start",
  user_id: user.id,
  ip: req.ip,
  email: user.email,
  device_id: body.kaidn_device_id,
});

const repeat = r.reasons.includes("device_reuse") || r.reasons.includes("email_reuse");

// withhold the TRIAL, not the account
if (repeat || r.verdict !== "allow") return createAccountOnFreeTier(user, r.event_id);

return startTrial(user);
lib/quota.ts
// the second call belongs where cost begins, not where the account begins
export async function onThresholdCrossed(user, usage) {
  const r = await kaidn.score({
    event: "usage_threshold",
    user_id: user.id,
    ip: usage.lastIp,
    email: user.email,
    device_id: usage.lastDeviceId,
  });

  if (r.verdict === "block") return requirePaymentMethod(user, r.reason_text);
  if (r.verdict === "review") return requireVerifiedEmail(user);
}

Do not let a shared office network convict anybody#

The most common false positive in B2B is two colleagues. The field that prevents it is already on the response:

corroborate before you act
// three accounts on one device across three networks is a shared laptop or a
// coworking space. Three on the SAME network is a stronger claim, not a weaker one,
// but in B2B it is also just an office.
const shared = r.device?.account_count ?? 0;
const sameNetwork = r.device?.account_count_same_network ?? 0;

const looksLikeAnOffice = sameNetwork > 1 && !r.reasons.includes("email_reuse");
if (looksLikeAnOffice) return allow();

email_reuse is what separates the two cases, because a colleague has their own mailbox and a farmer does not.

Where we sit#

We score signup, login, key creation and any custom event you send, using what the email resolves to, whether the device has been here before, IP and network reputation, and how fast things are repeating. Verdicts come back with the checks that fired and what each one counted for.

We are not billing software, we do not chase failed payments, and we produce no compliance evidence. If your problem is cancelled cards or SOC 2, those are different purchases entirely.

Frequently asked questions

Is trial abuse worth stopping for a SaaS product?

Work out the unit cost before you buy anything. If a trial costs you a fraction of a cent in compute, a farm of trials is an annoyance and your engineering time is better spent elsewhere. If a trial carries real cost (GPU inference, outbound mail, per-seat licences you pay for) the maths changes fast and so does the answer.

Does packaging beat detection?

Often, and it is worth trying first because it costs nothing to run. Move the expensive capability behind a verified email, a card on file, or a usage threshold, and you remove the reason to abuse it rather than fighting the abuse. Detection is for what is left once the free tier is shaped so that abusing it is not worth the effort.

What survives when an abuser changes identity?

The device and the real mailbox. Names, addresses and company domains are cheap to change. The browser and the inbox that actually receives the confirmation email are not. That is why device_reuse and email_reuse carry this pattern rather than any field-level check on your signup form.

How do I avoid banning the second person from a real company?

Do not treat a shared domain or a shared office network as evidence. Two accounts from one company on one office IP is the normal case, not the abusive one. Weigh the resolved mailbox and the device, read account_count_same_network before acting on a device match, and prefer withholding the trial to banning the account.

Should I score logins as well as signups?

Score them if account takeover would actually cost you, which it does once your product holds anything worth stealing. For pure trial abuse, the signup and the usage-threshold crossing carry nearly all the signal, and adding login scoring mostly adds volume.

Run it on your own traffic

10,000 events a month free, no card. Every verdict returns the checks that fired and their weights, so you can see which signal caught it.

Other business types