What the system can act on
Four layers of signal:
- Network — IP, IP range, ASN, ISP, proxy, VPN, Tor, data centre
- Device — user agent, fingerprint, OS, browser, bot signatures
- Supply — SSP, publisher, source, domain, app, placement, referrer
- Behavioral — click frequency, repeated IDs, session patterns, spikes, device/format mismatch
Specific anomalies it looks for include fingerprint collisions and abnormal session loops, proxy and VPN exit nodes, hosting ranges and ASN-level concentration, click bursts and time-of-day anomalies.
The four action levels
Each level has its own confidence threshold, which you set.
| Level | Action | Effect |
|---|---|---|
| 1 | Monitor | Watch the source and collect more signal. No campaign impact. |
| 2 | Review | Queue for admin attention with the full evidence trail. |
| 3 | Restrict | Throttle bids, cap frequency or limit placements automatically. |
| 4 | Block | Add to the active blocklist and stop spending immediately. |
You are in control. You decide which risk scores trigger which response, and you can manually override any decision.
Tuning advice
Start conservative — high thresholds for Block, generous use of Review — and tighten as you learn what your supply mix actually looks like. Blocking aggressively on day one, before you know your baseline, is the fastest way to lose good traffic and not realise it.
Related: How AI-powered fraud detection works · Reporting protection to your clients