Skip to content

Forter vs Riskified

enterprise-custom

·

usage-based · enterprise-custom

Forter wins · 175 (23 drawn)

Agentic commerce — stories about agentic commerce in this arenaAgentic commerce

Stories about agentic commerce in this arena

Agent detection

  1. ai-native userThe product distinguishes malicious bots from legitimate AI buying agents, so agent-driven purchases aren't blanket-blocked as fraud

    weight 2 · round to Forter
    Forterpartialprobed7/10

    Forter's agentic-orders docs show a dedicated orderType=AI_AGENT field that flags agent-driven purchases so Forter's risk engine can treat them distinctly rather than blanket-blocking, which directly targets this story. However, the evidence is entirely first-party documentation with no independent testing or detail on the underlying bot-vs-legitimate-agent classification logic. Missing for 10: independent/hands-on validation of accuracy, technical detail on how malicious bots are distinguished from legitimate agents beyond a merchant-set flag.

    • [claimed-docs] Set orderType to AI_AGENT
    • [claimed-docs] Set orderType to AI_AGENT ... This additional data improves Forter's risk decisions and provides the merchant better reporting on agentic tr…
    • [probe] PROBE llms.txt: HTTP 200 at https://docs.forter.com/llms.txt # docs.forter.com ## Overviews - [Agentic Orders](https://docs.forter.com/age…
    Riskifiednone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

    Agent identity

    1. developerPass verified agent identity — agentic-payment protocols, signed agent tokens, delegated spending scopes — into the risk decision as a first-class signal

      weight 2 · round to Forter
      Forterpartialclaimed5/10

      Forter's agentic-orders API lets developers set orderType to AI_AGENT so the risk engine treats agent-originated traffic differently and improves decisioning/reporting, which shows agent identity is ingested as a factor. However, the evidence only shows a coarse flag, not verified signed agent tokens, delegated spending scopes, or support for specific agentic-payment protocols (e.g., AP2/Visa/Mastercard agent tokens) as first-class structured signals. missing for 10: schema/fields for signed agent credentials or delegation scopes, explicit protocol support for agentic-payment standards, independent confirmation these fields are cryptographically verified rather than self-declared.

      • [claimed-docs] Set orderType to AI_AGENT
      • [claimed-docs] Set orderType to AI_AGENT ... This additional data improves Forter's risk decisions and provides the merchant better reporting on agentic tr…
      • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
      Riskifiednone0/10

      No evidence in the pack mentions agentic-payment protocols, signed agent tokens, or delegated spending scopes as inputs to Riskified's risk decision; the documented signals are customer/order/payment data, HMAC request auth, and Beacon session IDs, none of which represent verified agent identity as a first-class fraud signal.

      Agenticness — how well agents can access and operate the productAgenticness

      How well agents can access and operate the product

      Agent access

      1. ai-native userPoint an agent at llms.txt or agent-oriented docs

        weight 2 · round to Forter
        Forterfullprobed9/10

        Forter has a confirmed live llms.txt at docs.forter.com/llms.txt (HTTP 200, forter-probe-1) listing agent-oriented doc overviews, plus explicit agent-facing docs like the MCP getting-started guide for connecting to Claude Desktop and agentic-orders docs — all markdown-served for agent consumption. Missing for 10: independent third-party confirmation that agents successfully consume the llms.txt in practice beyond the probe check.

        • [probe] PROBE llms.txt: HTTP 200 at https://docs.forter.com/llms.txt # docs.forter.com ## Overviews - [Agentic Orders](https://docs.forter.com/age…
        • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
        • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
        Riskifiedfullprobed8/10

        A probe confirms Riskified hosts a working llms.txt at developers.riskified.com/llms.txt returning HTTP 200, and docs explicitly note pages can be fetched as markdown by appending .md — exactly the agent-oriented docs pattern. Missing for 10: no independent/third-party corroboration of an agent successfully consuming it, and no broader agent-specific documentation beyond the llms.txt index.

        • [probe] PROBE llms.txt: HTTP 200 at https://developers.riskified.com/llms.txt # Riskified documentation Documentation > Riskified Documentation Ap…
      2. ai-native userRun the product headlessly / in CI for automation

        weight 2 · round drawn
        Forterpartialprobed4/10

        Forter is a REST/webhook-based fraud API (order submission, status updates, webhooks, sandbox/test environment) which can technically be called from scripts or CI pipelines, and it offers an MCP server for programmatic/agentic access. However, there is no evidence of a CLI tool, CI/CD integration examples, headless testing harness, or automation-focused tooling explicitly designed for CI pipelines. missing for 10: dedicated CLI, CI/CD pipeline examples or GitHub Actions integration, headless test automation docs, explicit 'run in CI' guidance beyond generic sandbox API testing.

        • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
        • [claimed-docs] The main objective of the TEST site is to allow you to verify the integration prior to its deployment in the production environment.
        • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
        • [probe] official MCP server documented at https://docs.forter.com/mcp
        • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
        Riskifiedpartialclaimed4/10

        Riskified is fundamentally an API-first fraud-decision service (decide/submit/advise/chargeback endpoints, SDKs, webhook notifications) that can be called programmatically without a UI, which supports headless/automated integration into checkout pipelines. However, there is no evidence of CI/CD-specific tooling, a CLI, or documented automation-testing workflows — the docs focus on production checkout integration, not build/test automation. Missing for 10: explicit CI/CD examples, a CLI or automation-testing guide, and confirmation of headless operation outside the live transaction flow.

        • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
        • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
        • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
        • [claimed-docs] Riskified provides SDKs for several languages to simplify API integration. SDK usage is optional, and all API endpoints can also be accessed…
        • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
      3. ai-native userConnect an agent via an official MCP server

        weight 3 · round to Forter
        Forterfullprobed8/10

        Forter documents an official MCP server enabling AI agents to review decisions, manage disputes, and update policies via natural language, with a getting-started guide for connecting to Claude Desktop. missing for 10: independent/third-party corroboration of real-world MCP usage and broader client compatibility beyond Claude Desktop.

        • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
        • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
        • [probe] official MCP server documented at https://docs.forter.com/mcp
        Riskifiednone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        • ai-native userUse an official CLI

          weight 2 · round drawn
          Forternone0/10

          Evidence shows Forter offers REST APIs, webhooks, and an MCP server for conversational AI workflows, but no official CLI tool is documented anywhere in the evidence pack.

          • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
          • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
          • [probe] official MCP server documented at https://docs.forter.com/mcp
          Riskifiednone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          • ai-native userDrive the product through a documented public API

            weight 3 · round drawn
            Forterfullprobed8/10

            Forter publishes a documented public REST API (Order v3, Order Status, Evidence API, webhooks) with sandbox/production environments, giving AI-native users a clear path to drive the product programmatically; this is reinforced by an official MCP server enabling natural-language/agentic control of decisions and disputes. Missing for 10: independent/hands-on corroboration beyond vendor docs, and more detail on auth/rate limits or SDK coverage.

            • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
            • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
            • [claimed-docs] Webhooks provide a way to configure Forter to send real-time notifications to your web store server or another service (ERP/OMS) whenever ce…
            • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
            • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
            • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
            • [probe] PROBE llms.txt: HTTP 200 at https://docs.forter.com/llms.txt # docs.forter.com ## Overviews - [Agentic Orders](https://docs.forter.com/age…
            • [probe] official MCP server documented at https://docs.forter.com/mcp
            Riskifiedfullprobed8/10

            Riskified exposes a comprehensive documented REST API (decide, submit, advise, chargeback, notifications, login) with authentication (HMAC), synchronous/asynchronous flows, and optional SDKs, all directly callable via HTTP — clearly a documented public API an AI-native user could drive. The docs site also exposes an llms.txt for AI-friendly consumption, though no machine-readable OpenAPI/Swagger spec was found (404s on standard paths). Missing for 10: a discoverable OpenAPI/swagger schema and explicit rate-limit/versioning documentation.

            • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
            • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
            • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
            • [claimed-docs] Riskified provides SDKs for several languages to simplify API integration. SDK usage is optional, and all API endpoints can also be accessed…
            • [claimed-docs] X-RISKIFIED-HMAC-SHA256 | Verification hash for the Request. Generated by performing an SHA256 encryption on the request's POST body and cal…
            • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
            • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…
            • [probe] PROBE llms.txt: HTTP 200 at https://developers.riskified.com/llms.txt # Riskified documentation Documentation > Riskified Documentation Ap…
            • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…
          • ai-native userBuild against official SDKs

            weight 2 · round drawn
            Forterpartialprobed5/10

            Forter provides extensive REST API references (Order v3, Order Status, Evidence API, webhooks), a sandbox/production environment, and even a documented MCP server for agentic workflows, which together give an AI-native developer solid material to build against. However, none of the evidence explicitly names or links to official client-language SDKs (e.g., Python/Node/Java packages) — only API/reference docs and an MCP integration are shown. Missing for 10: explicit official SDK packages/libraries, versioned SDK release notes, and independent corroboration of SDK usage in production.

            • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
            • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
            • [claimed-docs] Webhooks provide a way to configure Forter to send real-time notifications to your web store server or another service (ERP/OMS) whenever ce…
            • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
            • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
            • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
            • [probe] official MCP server documented at https://docs.forter.com/mcp
            Riskifiedpartialclaimed5/10

            Riskified's docs explicitly state that SDKs are provided for several languages to simplify API integration, confirming official SDK support (riskified-docs-5). However, the evidence lacks specifics such as which languages are covered, links to SDK repositories, or independent/community corroboration of SDK quality. Missing for 10: list of supported languages, links to SDK repos/package registries, hands-on developer feedback on SDK usability.

            • [claimed-docs] Riskified provides SDKs for several languages to simplify API integration. SDK usage is optional, and all API endpoints can also be accessed…
          • ai-native userSubscribe to events via webhooks

            weight 2 · round to Forter
            Forterfullclaimed7/10

            Forter documents a dedicated webhooks system for real-time event notifications (order status, chargeback forwarding, dispute webhooks) that can be configured to notify external services, directly matching the subscribe-to-events story; this is a well-documented first-party capability. missing for 10: independent/hands-on corroboration of webhook reliability, and a comprehensive list of subscribable event types/payload schema beyond the examples shown.

            • [claimed-docs] Webhooks provide a way to configure Forter to send real-time notifications to your web store server or another service (ERP/OMS) whenever ce…
            • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
            • [claimed-docs] Webhook-based forwarding enables: - Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute h…
            • [claimed-docs] How to provide Forter access to your Stripe Dispute Webhooks.
            • [claimed-docs] Webhook-based forwarding enables: Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute han…
            Riskifiedpartialclaimed6/10

            Riskified documents a webhook-style notification mechanism: decision outcomes are pushed to a merchant-defined endpoint with retries on non-2xx and HMAC-SHA256 signature verification, which functions as an event webhook for fraud decisions and chargebacks. However, this is a fixed set of built-in notification types (order decision, chargeback) rather than a general-purpose subscribable event system with selectable event topics or a dashboard for managing webhook subscriptions. Missing for 10: a documented event catalog/subscription model letting users choose which event types to receive, and any UI/API for creating or managing multiple webhook subscriptions.

            • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
            • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined.
            • [claimed-docs] X-RISKIFIED-HMAC-SHA256 | Verification hash for the Request. Generated by performing an SHA256 encryption on the request's POST body and cal…
            • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
            • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.

          Agentic features

          1. ai-native userGet AI-generated insights and suggestions from my data inside the product

            weight 2 · round to Forter
            Forterpartialclaimed6/10

            Forter provides an AI-driven recommendation engine that suggests additional evidence to bolster dispute win rates and a 'team of Forter Agents' concept, plus MCP-enabled natural language interactions for reviewing decisions and managing disputes. This shows some AI-generated insight/suggestion capability embedded in the product, but evidence is thin on broader analytics/insights (e.g., fraud trend explanations, risk scoring rationale) beyond the dispute-evidence use case. Missing for 10: broader in-product AI insights beyond dispute evidence suggestions, independent/hands-on corroboration of the recommendation engine's quality, and detail on what other 'Forter Agents' actually surface to users.

            • [claimed-docs] our recommendation engine will suggest additional evidence to add to your dispute to bolster your win rate.
            • [claimed-docs] Once chargebacks are ingested into Forter, our recommendation engine will suggest additional evidence to add to your dispute to bolster your…
            • [claimed-docs] Meet your new team of Forter Agents, so you can spend more time on what matters most.
            • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
            • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
            Riskifiednone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            • ai-native userSet up automations that run autonomously in the background

              weight 2 · round to Forter
              Forterpartialprobed5/10

              Forter's fraud automation (webhooks, chargeback forwarding, evidence recommendation, MCP for reviewing decisions/managing disputes) provides background automation of fraud/dispute workflows, and the MCP server lets AI agents trigger actions, but this is not framed as user-configurable 'set up automations that run autonomously' in the sense of scheduled/triggered workflows the AI-native user builds themselves. missing for 10: explicit user-facing automation builder/scheduler, evidence of autonomous background runs initiated by the user rather than reactive webhook/event responses, and independent confirmation of real-world autonomous operation.

              • [claimed-docs] Webhooks provide a way to configure Forter to send real-time notifications to your web store server or another service (ERP/OMS) whenever ce…
              • [claimed-docs] Webhook-based forwarding enables: - Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute h…
              • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
              • [claimed-docs] Once chargebacks are ingested into Forter, our recommendation engine will suggest additional evidence to add to your dispute to bolster your…
              • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
              • [probe] official MCP server documented at https://docs.forter.com/mcp
              Riskifiednone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              • ai-native userDelegate tasks to a built-in AI assistant inside the product

                weight 3 · round to Forter
                Forterpartialclaimed3/10

                Forter's marketing mentions a 'team of Forter Agents' suggesting built-in AI-driven automation, but the evidence pack gives no detail on how a user interacts with or delegates tasks to such an assistant inside the product UI. The only detailed AI-interaction evidence (MCP) is about connecting external assistants like Claude Desktop to Forter, not a built-in assistant. Missing for 10: documentation of an in-product conversational assistant UI, examples of task delegation, and how 'Forter Agents' are invoked/configured.

                • [claimed-docs] Meet your new team of Forter Agents, so you can spend more time on what matters most.
                • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                Riskifiednone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                • ai-native userOperate the product with natural-language commands

                  weight 2 · round to Forter
                  Forterfullprobed8/10

                  Forter documents a first-party MCP server enabling natural-language commands to review decisions, manage disputes, and update policies, with a getting-started guide for connecting to Claude Desktop for conversational workflows. Missing for 10: independent/hands-on corroboration beyond vendor docs, and broader coverage of which actions are NL-operable vs API-only.

                  • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                  • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
                  • [probe] official MCP server documented at https://docs.forter.com/mcp
                  • [probe] PROBE llms.txt: HTTP 200 at https://docs.forter.com/llms.txt # docs.forter.com ## Overviews - [Agentic Orders](https://docs.forter.com/age…
                  Riskifiednone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                  Api quality

                  1. ai-native userExplore an interactive API reference with runnable examples

                    weight 2 · round drawn
                    Forternone0/10

                    The evidence pack shows Forter has API reference documentation (order-v3, order-status, webhooks, environments) but nothing indicates the docs are interactive with runnable/try-it examples—no mention of an embedded API console, code sandbox, or 'try it' functionality typical of interactive API references.

                      Riskifiednone0/10

                      Evidence shows only static API reference docs (endpoints, parameters, notifications) with no mention of an interactive console, runnable examples, or live API explorer; the openapi.json/swagger.json probe returned 404s, indicating no machine-readable spec to power an interactive reference.

                      • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…
                      • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                      • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…
                    • ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                      weight 2 · round drawn
                      Forternone0/10

                      Forter publishes REST API reference docs (order-v3, order-status, webhooks) but none of the evidence mentions a downloadable OpenAPI/Swagger spec or machine-readable API definition file; the llms.txt probe lists doc pages, not an API spec.

                      • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                      • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
                      • [probe] PROBE llms.txt: HTTP 200 at https://docs.forter.com/llms.txt # docs.forter.com ## Overviews - [Agentic Orders](https://docs.forter.com/age…
                      Riskifiednone0/10

                      A probe explicitly checked common OpenAPI/swagger spec locations and all returned 404, and no evidence pack item references a downloadable machine-readable API spec; only human-readable docs and an llms.txt are present.

                      • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…
                      • [probe] PROBE llms.txt: HTTP 200 at https://developers.riskified.com/llms.txt # Riskified documentation Documentation > Riskified Documentation Ap…
                    • ai-native userTest against a sandbox environment without touching production data

                      weight 1 · round to Forter
                      Forterfullclaimed8/10

                      Forter explicitly documents both production and sandbox (TEST) environments, stating the sandbox's purpose is to verify integration before production deployment, allowing testing without touching production data. Missing for 10: no independent/hands-on corroboration of sandbox behavior or details on sandbox data parity/limitations.

                      • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
                      • [claimed-docs] The main objective of the TEST site is to allow you to verify the integration prior to its deployment in the production environment.
                      Riskifiednone0/10

                      No evidence of a sandbox or test environment separate from production; docs describe live API endpoints, integration flows, and Shopify onboarding but never mention a sandbox/test mode for AI-native or developer testing.

                      • ai-native userRely on versioned APIs with a documented deprecation policy

                        weight 2 · round drawn
                        Forternone0/10

                        Evidence shows versioned API endpoints (e.g. order-v3) and sandbox/production environments, but there is no documentation of a versioning scheme, version support lifecycle, or a deprecation policy anywhere in the pack.

                        • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                        • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
                        • [claimed-docs] The main objective of the TEST site is to allow you to verify the integration prior to its deployment in the production environment.
                        Riskifiednone0/10

                        No evidence of API versioning scheme (e.g., v1/v2 paths, version headers) or any documented deprecation policy; OpenAPI spec probes all returned 404. missing for 10: versioned endpoint scheme, deprecation/sunset policy documentation, changelog or migration guides.

                        • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…

                      Automation depth — how much of the product can run unattendedAutomation depth

                      How much of the product can run unattended

                      1. ai-native userPerform bulk operations across many items at once

                        weight 2 · round drawn
                        Forternone0/10

                        Forter's docs describe per-order/per-dispute APIs (Order v3, Evidence API, webhooks, MCP natural-language actions) but no evidence of a bulk/batch endpoint or mechanism for acting across many items simultaneously. The axis is applicable (merchants would plausibly want bulk dispute/evidence submission or bulk order review), but no such capability is documented.

                        • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                        • [claimed-docs] Save time and effort by using our Evidence API endpoint to automatically send post-order evidence for chargeback disputes.
                        • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                        Riskifiednone0/10

                        Riskified's API is order-by-order (decide/submit/advise per transaction), with no evidence of a batch or bulk endpoint for processing many orders/items in a single call, nor any bulk chargeback or data-export operation.

                        • ai-native userDefine rules that trigger actions automatically on events

                          weight 3 · round to Forter
                          Forterpartialclaimed5/10

                          Forter supports event-driven automation via webhooks (real-time notifications on events like disputes/chargebacks) and configurable decision behaviors (e.g., Auto Invoice triggering capture), and its MCP interface lets an AI agent perform actions like reviewing decisions or updating policies via natural language. However, there is no evidence of a user-facing rule-definition engine (e.g., 'if X then Y' conditions) that AI-native users can author themselves. Missing for 10: explicit rule-builder/conditional logic UI or API, examples of user-defined trigger-action pairs beyond fixed webhook events and preset decision toggles.

                          • [claimed-docs] Webhooks provide a way to configure Forter to send real-time notifications to your web store server or another service (ERP/OMS) whenever ce…
                          • [claimed-docs] If the Auto Invoice option is set to YES, then the payment capture amount operation is executed and order is placed
                          • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                          • [claimed-docs] Webhook-based forwarding enables: - Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute h…
                          Riskifiedpartialclaimed3/10

                          Riskified automatically triggers fixed actions on fraud-decision events (webhook notifications, Shopify integration auto-voiding/restocking/capturing on approve/decline) but there is no evidence of a user-configurable rules engine where an AI-native user can define custom conditions/actions themselves — the automation is built-in and non-customizable rather than rule-definable. Missing for 10: a rules/condition-authoring API or UI, examples of custom trigger logic, and any AI-native/agentic rule-configuration workflow.

                          • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
                          • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined.
                          • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…
                          • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…

                        Chargeback disputes — stories about chargeback disputes in this arenaChargeback disputes

                        Stories about chargeback disputes in this arena

                        Guarantee

                        1. finance leadShift fraud liability to the vendor — a chargeback guarantee that reimburses approved-then-disputed orders, with clear coverage terms

                          weight 2 · round to Riskified
                          Forternone0/10

                          The evidence pack details dispute automation, evidence submission, webhook forwarding, and win-rate optimization tools, but none of it documents an actual chargeback guarantee, reimbursement mechanism, or liability-shift terms — the core of this finance-lead story. Missing for 10: explicit guarantee/reimbursement policy language, coverage terms, or liability-shift contract details.

                          • [claimed-docs] Webhook-based forwarding enables: - Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute h…
                          • [claimed-docs] our recommendation engine will suggest additional evidence to add to your dispute to bolster your win rate.
                          • [claimed-docs] Once chargebacks are ingested into Forter, our recommendation engine will suggest additional evidence to add to your dispute to bolster your…
                          • [claimed-docs] Save time and effort by using our Evidence API endpoint to automatically send post-order evidence for chargeback disputes.
                          • [claimed-docs] Fight fraud, increase approvals, reduce chargebacks
                          • [claimed-docs] Automate disputes, streamline operations, improve win rates
                          Riskifiedpartialclaimed5/10

                          The evidence pack documents Riskified's API decisioning, chargeback notification, and chargeback gateway integration (automating chargeback reporting/disputing) but never states explicit financial liability-shift terms, reimbursement guarantees, coverage limits, or exclusions that a finance lead would need to evaluate a chargeback guarantee. Chargeback automation is a workflow/process feature, not proof of a monetary guarantee. missing for 10: explicit guarantee/reimbursement terms, coverage scope and exclusions, contractual liability-shift language, any evidence of actual reimbursement payouts.

                          • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                          • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                          • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                          • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …

                        Outcome reporting

                        1. finance leadSee the numbers that matter — dispute rate, false-positive rate, approval-rate lift, review workload — and export them for the board

                          weight 2 · round drawn
                          Forternone0/10

                          The evidence pack covers APIs, webhooks, MCP, and dispute automation but contains no mention of a reporting dashboard, board-level metrics (dispute rate, false-positive rate, approval-rate lift, review workload), or any export/reporting feature aimed at finance leads. Only a vague reference to 'better reporting on agentic traffic' exists, which does not address the specific KPIs in the story.

                          • [claimed-docs] Set orderType to AI_AGENT ... This additional data improves Forter's risk decisions and provides the merchant better reporting on agentic tr…
                          Riskifiednone0/10

                          Evidence covers API/integration mechanics (decide, submit, chargeback automation, notifications) but nothing about a finance/reporting dashboard, KPI metrics (dispute rate, false-positive rate, approval-rate lift, review workload), or board-ready export functionality.

                          Representment

                          1. ops userChargeback responses are automated — evidence compiled from order, delivery, and session data and submitted to the issuer without manual copy-paste

                            weight 3 · round drawn
                            Forterpartialclaimed6/10

                            Forter documents automated evidence workflows: chargebacks are ingested via webhook forwarding, matched to transactions, and a recommendation engine suggests additional evidence, plus an Evidence API to 'automatically send post-order evidence for chargeback disputes' without manual copy-paste of transaction data. However, the evidence is described as 'suggested' by a recommendation engine rather than fully autonomous compilation and submission, and there's no explicit mention of session data being incorporated into evidence packages. Missing for 10: explicit confirmation that session-level data is included in compiled evidence, and independent/hands-on validation that submission is fully automatic without ops review step.

                            • [claimed-docs] Webhook-based forwarding enables: - Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute h…
                            • [claimed-docs] our recommendation engine will suggest additional evidence to add to your dispute to bolster your win rate.
                            • [claimed-docs] Once chargebacks are ingested into Forter, our recommendation engine will suggest additional evidence to add to your dispute to bolster your…
                            • [claimed-docs] Save time and effort by using our Evidence API endpoint to automatically send post-order evidence for chargeback disputes.
                            • [claimed-docs] Map Stripe's PaymentIntent ID (the value that starts with pi_) to the processorTransactionId field ... This is required to map the dispute b…
                            Riskifiedpartialclaimed6/10

                            Riskified's Chargeback Gateway Integration (CGI) is documented as automating 'end-to-end chargeback handling from chargeback reporting to the disputing process' across major gateways, implying dispute evidence submission without manual copy-paste, and Riskified already ingests order, session (Beacon), and decision data through its APIs. However, the docs don't explicitly describe compiling delivery data or detail the specific evidence package sent to issuers during disputes. Missing for 10: explicit description of delivery-data inclusion in chargeback evidence, detail on the dispute evidence package format submitted to issuers, and independent/hands-on confirmation that submission is fully automated end-to-end.

                            • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                            • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                            • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                            • [claimed-docs] Riskfied's Beacon is a JavaScript snippet that merchants embed on their website. It collects fundamental data required to decide on the legi…
                            • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…

                          Fraud agent access — stories about fraud agent access in this arenaFraud agent access

                          Stories about fraud agent access in this arena

                          Agent operations

                          1. ai-native userAn agent can read my fraud posture and manage rules and lists programmatically — propose a velocity rule, update a blocklist — with human approval gates

                            weight 3 · round to Forter
                            Forterpartialprobed5/10

                            Forter documents an official MCP server that lets an AI system 'review decisions, manage disputes, or update policies through natural language commands' and can connect to Claude Desktop for conversational workflows, which supports agentic read/manage access to fraud posture. However, there is no explicit documentation of proposing a velocity rule, updating a blocklist, or any human-in-the-loop approval gate mechanism for these programmatic changes. Missing for 10: explicit velocity-rule/blocklist management examples, documented approval-gate workflow, and independent/hands-on corroboration of MCP write actions.

                            • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                            • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
                            • [probe] official MCP server documented at https://docs.forter.com/mcp
                            Riskifiednone0/10

                            Evidence covers order review/decision APIs, notifications, chargeback automation, and Beacon data collection, but there is no mention of programmatic management of fraud rules, velocity rules, or blocklists, nor any agent-facing approval workflow for such changes.

                            Agent triage

                            1. ai-native userAn agent can work the review queue — pull flagged cases with their context, summarize the evidence, and recommend a decision for a human to confirm

                              weight 2 · round to Forter
                              Forterpartialprobed5/10

                              Forter's MCP server explicitly lets an AI agent 'perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural language commands' via Claude Desktop, showing agent access to review/decision workflows. However, there is no explicit documentation of pulling a flagged-case queue, summarizing evidence, or producing a recommendation for human confirmation as a distinct workflow. missing for 10: explicit queue-pulling UI/API for flagged cases, evidence-summarization output, human-confirm approval step.

                              • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                              • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
                              • [probe] official MCP server documented at https://docs.forter.com/mcp
                              Riskifiednone0/10

                              Riskified's evidence describes automated decisioning APIs (/decide, /submit, /advise), notifications, and merchant integrations, but nothing describes an agent-accessible review queue with case context retrieval, evidence summarization, or a human-confirm workflow. No API for pulling flagged cases with context or generating human-reviewable recommendations is documented.

                              Builtin ai

                              1. risk analystThe product ships its own AI assistant — natural-language queries over my fraud data, drafted rules, investigation summaries — built into the console

                                weight 2 · round to Forter
                                Forterpartialprobed3/10

                                Forter markets 'Forter Agents' and ships an MCP server letting external AI systems (e.g., Claude Desktop) issue natural-language commands to review decisions, manage disputes, or update policies, which gestures at the AI-assistant theme. However, the evidence never describes a native, embedded console assistant with NL querying over fraud data, rule drafting, or investigation summaries — the MCP approach is an integration layer for external AI clients rather than a first-party in-console assistant. Missing for 10: concrete documentation of a built-in console chat/assistant UI, evidence of drafted-rule generation, and investigation-summary generation features.

                                • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                                • [claimed-docs] Meet your new team of Forter Agents, so you can spend more time on what matters most.
                                • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
                                • [probe] official MCP server documented at https://docs.forter.com/mcp
                                Riskifiednone0/10

                                Evidence covers API endpoints, webhooks, chargeback automation, Beacon SDK, and integration processes, but nothing describes a built-in AI assistant, natural-language query interface, rule drafting, or investigation summaries in the console.

                                Fraud surfaces — stories about fraud surfaces in this arenaFraud surfaces

                                Stories about fraud surfaces in this arena

                                Abuse coverage

                                1. risk analystProtection extends beyond checkout — account takeover, fake account creation, promo and policy abuse are scored and managed in the same system

                                  weight 2 · round drawn
                                  Forterpartialclaimed5/10

                                  Forter's marketing copy explicitly claims to 'Stop ATO, block fake accounts, protect account integrity' alongside its checkout/fraud-decision APIs, indicating account-takeover and fake-account protection live in the same platform as order-level fraud scoring. However, there is no documentation of promo abuse or policy abuse detection/management, and no detail on how ATO/fake-account signals are scored or surfaced to analysts beyond a single marketing line. Missing for 10: dedicated docs/API for promo abuse and policy abuse detection, analyst-facing workflow/management details for ATO and fake-account cases beyond marketing claims.

                                  • [claimed-docs] Stop ATO, block fake accounts, protect account integrity
                                  • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                                  • [claimed-docs] Fight fraud, increase approvals, reduce chargebacks
                                  Riskifiedpartialclaimed5/10

                                  Riskified's Login API explicitly scores account-takeover attempts (allow/notify/challenge) alongside its core checkout fraud decisioning (decide/submit/advise) and automated chargeback handling, showing the same system spans multiple fraud surfaces beyond checkout. However, there is no documentation of fake-account-creation detection or promo/coupon abuse scoring as distinct managed surfaces. Missing for 10: explicit fake-account-creation protection, promo/policy abuse scoring, and independent confirmation these are unified in one decisioning system.

                                  • [claimed-docs] API is triggered only for customer-initiated authentication requests, e.g., user tries to login to their account... `decision` field will be…
                                  • [claimed-docs] `decision` field will be set as one of the following values: `allow`, `notify`, or `challenge`.
                                  • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                  • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                                  • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                  • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…

                                Integrations

                                1. ops userThere are maintained integrations for my commerce stack — Shopify, Salesforce Commerce, BigCommerce, and the major PSPs — not just a raw API

                                  weight 2 · round to Riskified
                                  Forterpartialclaimed5/10

                                  Evidence confirms a maintained Shopify integration (quickstart-shopify.md) and Stripe dispute webhook support, indicating some pre-built commerce/PSP connectors exist. However, there is no evidence of maintained integrations for Salesforce Commerce, BigCommerce, or other major PSPs (Adyen, Braintise, PayPal, etc.), leaving the breadth of the 'commerce stack' claim largely unsubstantiated. missing for 10: documented Salesforce Commerce Cloud integration, BigCommerce integration, coverage of additional major PSPs beyond Stripe, and any partner/marketplace integration directory confirming maintenance status.

                                  • [claimed-docs] You implement: Nothing - Forter handles everything
                                  • [claimed-docs] How to provide Forter access to your Stripe Dispute Webhooks.
                                  • [claimed-docs] Map Stripe's PaymentIntent ID (the value that starts with pi_) to the processorTransactionId field ... This is required to map the dispute b…
                                  Riskifiedpartialclaimed7/10

                                  Riskified documents maintained platform integrations beyond raw API: a dedicated Shopify app with automated order actions (docs-11,12,21,22), a Salesforce Commerce Cloud/Agentforce Commerce fraud cartridge (docs-10), and automated Chargeback Gateway Integration with major PSPs (Braintree, Stripe, Adyen, PayPal) (docs-4,16,17). However, there is no mention of a BigCommerce integration, and the PSP integrations are scoped to chargeback data only rather than full checkout/decisioning flows. Missing for 10: explicit BigCommerce integration, evidence of maintained PSP integrations beyond chargebacks (e.g., payment/checkout-time connectors), independent confirmation of integration quality/maintenance cadence.

                                  • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                  • [claimed-docs] Agentforce Commerce (formerly Salesforce Commerce Cloud / SFCC) fraud protection cartridge provides a structured integration process tailore…
                                  • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…
                                  • [claimed-docs] If we have questions about shop flows or encounter data issues, we will reach out to you for clarification... Once data validation passes, y…
                                  • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                                  • [claimed-docs] Once you have installed the Riskified app in your Shopify store, the integration process can begin. During this time, most of the “heavy lif…
                                  • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…

                                Psp coverage

                                1. developerUse the product across whatever payment stack I run — multiple PSPs, gateways, and platforms — rather than being locked to one processor's rails

                                  weight 3 · round to Riskified
                                  Forterpartialclaimed5/10

                                  Forter is payment-agnostic in principle (works off order/checkout data, not tied to a specific processor's rails), and evidence shows Stripe-specific dispute webhook integration plus a Shopify quickstart, implying multi-platform support. However there is no explicit documentation enumerating support across multiple PSPs/gateways beyond Stripe and Shopify, nor guidance for other major processors (Adyen, Braintree, PayPal, etc.). missing for 10: explicit list/documentation of supported PSPs and gateways beyond Stripe/Shopify, evidence of platform-agnostic integration guides for other processors, independent confirmation of multi-PSP deployments.

                                  • [claimed-docs] How to provide Forter access to your Stripe Dispute Webhooks.
                                  • [claimed-docs] Map Stripe's PaymentIntent ID (the value that starts with pi_) to the processorTransactionId field ... This is required to map the dispute b…
                                  • [claimed-docs] You implement: Nothing - Forter handles everything
                                  • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
                                  Riskifiedpartialclaimed6/10

                                  Riskified is gateway/platform-agnostic via its own API (/decide, /submit, /advise), with automated chargeback integrations naming specific gateways (Braintree, Stripe, Adyen, PayPal) and platform cartridges for Shopify and SFCC, indicating it can plug into multiple PSPs/platforms rather than lock a merchant into one processor. However, the evidence doesn't explicitly enumerate broad PSP/gateway compatibility beyond the four named chargeback gateways, nor discuss developer-facing flexibility across arbitrary payment stacks explicitly. missing for 10: a comprehensive list of supported PSPs/gateways beyond chargeback integrations, explicit statements about processor-agnostic architecture, and independent confirmation of multi-PSP interoperability.

                                  • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                  • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                                  • [claimed-docs] Agentforce Commerce (formerly Salesforce Commerce Cloud / SFCC) fraud protection cartridge provides a structured integration process tailore…
                                  • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…
                                  • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…

                                Model transparency — stories about model transparency in this arenaModel transparency

                                Stories about model transparency in this arena

                                Explainability

                                1. risk analystEvery score comes with its top risk factors — why this transaction looks risky — not just an opaque number

                                  weight 3 · round drawn
                                  Forternone0/10

                                  No evidence describes score explainability, reason codes, or risk-factor breakdowns accompanying Forter's fraud decisions; the evidence pack covers order submission, webhooks, disputes, and agentic order tagging but nothing about transparency into why a score was assigned.

                                    Riskifiednone0/10

                                    Evidence describes decision outcomes (approve/decline/allow/notify/challenge) and notification mechanisms, but nothing indicates that decisions are accompanied by explanatory risk factors or reason codes for analysts. No mention of feature-level explanations, contributing signals, or reason breakdowns anywhere in the docs.

                                    Model evaluation

                                    1. finance leadMeasure the model itself — precision and recall on my traffic, shadow-mode trials of new models or rules before they take over decisions

                                      weight 2 · round drawn
                                      Forternone0/10

                                      No evidence of model-level metrics (precision/recall), shadow-mode trials, or A/B testing of models/rules before rollout; evidence covers order decisioning, webhooks, disputes, and agentic orders but nothing about model performance measurement or staged rollout tooling for finance leads.

                                        Riskifiednone0/10

                                        The evidence pack only covers API endpoints, integrations, notifications, and chargeback automation — nothing about model performance metrics (precision/recall), model versioning, or shadow-mode testing of new models/rules before go-live is documented.

                                        Openness — open source, data portability, and self-hosting storiesOpenness

                                        Open source, data portability, and self-hosting stories

                                        1. ai-native userDo everything through the API that I can do in the UI

                                          weight 2 · round to Forter
                                          Forterpartialprobed6/10

                                          Forter exposes core actions via API/webhooks (order decisions, order status, evidence submission, chargeback forwarding) and an MCP server that lets AI agents review decisions, manage disputes, and update policies via natural language, suggesting broad API/agent coverage of UI functions. However, there is no explicit documentation stating full feature parity between the UI dashboard and API/MCP, and some UI-only configuration (e.g., policy setup screens, analytics dashboards) isn't shown as API-accessible. Missing for 10: explicit parity statement, evidence that every UI configuration/reporting feature is also API-exposed, independent confirmation of MCP completeness.

                                          • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                                          • [claimed-docs] Set orderType to AI_AGENT
                                          • [claimed-docs] Save time and effort by using our Evidence API endpoint to automatically send post-order evidence for chargeback disputes.
                                          • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                                          • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
                                          • [claimed-docs] Webhooks provide a way to configure Forter to send real-time notifications to your web store server or another service (ERP/OMS) whenever ce…
                                          • [probe] official MCP server documented at https://docs.forter.com/mcp
                                          Riskifiednone0/10

                                          The evidence pack documents Riskified's API endpoints (decide, submit, advise, chargeback, notifications) and SDKs, but never discusses the merchant dashboard/UI or compares what can be done there versus via API, so there's no evidence of feature parity between UI and API.

                                          Privacy posture — data-handling and privacy storiesPrivacy posture

                                          Data-handling and privacy stories

                                          1. ai-native userChoose where my data is stored (region/residency)

                                            weight 2 · round drawn
                                            Forternone0/10

                                            No evidence in the pack addresses data residency, regional storage options, or geographic controls over where customer data is held; all evidence concerns fraud decisioning, disputes, webhooks, and agentic order tagging.

                                              Riskifiednone0/10

                                              No evidence in the pack mentions data residency, region selection, or storage location options for merchant/customer data; documentation covers API endpoints, integrations, and notifications only.

                                              • ai-native userControl data retention and deletion

                                                weight 2 · round drawn
                                                Forternone0/10

                                                No evidence pack items address data retention policies, deletion controls, or user-facing privacy/data-management settings; the docs focus on fraud detection, disputes, and MCP integration.

                                                  Riskifiednone0/10

                                                  No evidence pack items address data retention policies, deletion mechanisms, or user/customer data control tools; the docs focus entirely on fraud-decision APIs and integrations with no privacy-posture or data lifecycle controls mentioned.

                                                  Residency compliance — stories about residency compliance in this arenaResidency compliance

                                                  Stories about residency compliance in this arena

                                                  Residency

                                                  1. ops userControl where fraud data lives and how long it's kept — regional residency options and retention controls that survive a privacy review

                                                    weight 2 · round drawn
                                                    Forternone0/10

                                                    No evidence pack items address data residency options, regional data storage, or retention/deletion controls; documentation covers order APIs, webhooks, disputes, PCI scope, and MCP/agent features but nothing about where fraud data is stored or how long it is kept.

                                                      Riskifiednone0/10

                                                      No evidence in the pack addresses data residency options, regional data storage, or retention/deletion controls; documentation covers API flows, integrations, and authentication only.

                                                      Sca

                                                      1. developerEuropean traffic is routed intelligently through SCA — 3DS triggered when required or risky, exemptions requested when safe — to protect both compliance and conversion

                                                        weight 2 · round to Riskified
                                                        Forternone0/10

                                                        No evidence in the pack mentions SCA, 3DS, PSD2 exemptions, or European payment authentication routing at all; Forter's docs focus on fraud decisioning, disputes, chargebacks, and agentic order tagging, none of which address SCA/3DS logic.

                                                          Riskifiedfullclaimed7/10

                                                          Riskified's /advise endpoint explicitly returns CVV/3DS recommendations and adds TRA/SCA exemption recommendations for regulated markets, directly matching the story of intelligently triggering 3DS or requesting exemptions per order. This is first-party documentation with no independent corroboration of real-world accuracy or European-specific behavior. Missing for 10: independent/hands-on validation of SCA exemption success rates, and explicit detail on how 'European traffic' specifically is distinguished/routed versus other regions.

                                                          • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                                                          • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... In addition, CVV/3DS recommendations can be prov…

                                                        Review queues — stories about review queues in this arenaReview queues

                                                        Stories about review queues in this arena

                                                        Case review

                                                        1. risk analystFlagged transactions land in a review queue that shows the full context — customer history, signals, similar cases — so I can decide quickly and consistently

                                                          weight 3 · round drawn
                                                          Forternone0/10

                                                          Evidence covers order decisioning APIs, webhooks, chargeback/dispute automation, and MCP/agentic order tagging, but there is no mention of a review queue UI showing flagged transactions with customer history, signals, or similar cases for analyst decisioning.

                                                            Riskifiednone0/10

                                                            Evidence covers Riskified's API endpoints (/decide, /submit, /advise), notifications, chargeback automation, and Beacon data collection, but nothing describes a human review-queue UI showing analyst context, customer history, or similar cases for manual decisioning — Riskified's documented flow is automated/API-driven decisioning, not analyst-facing case review tooling.

                                                            Feedback loop

                                                            1. risk analystMy review decisions and confirmed fraud outcomes feed back into the model and rules, so the system learns from every case we work

                                                              weight 2 · round to Forter
                                                              Forterpartialclaimed4/10

                                                              Forter's docs show data flowing back to Forter post-decision (order status updates including compensation granted, chargeback/dispute webhook ingestion, Evidence API) which implies outcome data reaches Forter's systems, but there is no explicit documentation that a risk analyst's manual review decisions or confirmed-fraud outcomes are used to retrain models or update rules. Missing for 10: explicit description of a feedback/learning loop tying analyst review outcomes to model or rule updates, and any mention of an analyst review queue at all.

                                                              • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
                                                              • [claimed-docs] Webhook-based forwarding enables: - Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute h…
                                                              • [claimed-docs] Webhook-based forwarding enables: Real-time claim ingestion - Faster transaction matching - Immediate eligibility assessment for dispute han…
                                                              • [claimed-docs] How to provide Forter access to your Stripe Dispute Webhooks.
                                                              • [claimed-docs] Map Stripe's PaymentIntent ID (the value that starts with pi_) to the processorTransactionId field ... This is required to map the dispute b…
                                                              • [claimed-docs] Save time and effort by using our Evidence API endpoint to automatically send post-order evidence for chargeback disputes.
                                                              Riskifiednone0/10

                                                              The evidence describes automated decisioning APIs (/decide, /submit, /advise), chargeback notification integrations, and onboarding model calibration by Riskified's own analytics team, but nothing describes an analyst-facing review queue where human review decisions or confirmed fraud outcomes are captured and fed back into the model/rules on an ongoing basis. Missing for 10: evidence of an analyst review UI, a mechanism for analysts to submit manual review/fraud confirmations, and documentation that such decisions retrain or update the fraud model/rules.

                                                              • [claimed-docs] If we have questions about shop flows or encounter data issues, we will reach out to you for clarification... Once data validation passes, y…
                                                              • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                                                              • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…

                                                            Team workflows

                                                            1. ops userReview work is a team workflow — assignment, escalation, SLAs, and a decision audit trail that shows who approved what and why

                                                              weight 2 · round drawn
                                                              Forternone0/10

                                                              The evidence pack covers order decisioning, webhooks, chargeback/dispute automation, and AI-agent/MCP integrations, but contains no mention of a human team review workflow with case assignment, escalation rules, SLAs, or an approval audit trail for ops reviewers. missing for 10: case assignment/queue management, escalation rules, SLA tracking, and a decision audit trail showing reviewer approvals and rationale.

                                                                Riskifiednone0/10

                                                                Evidence covers API decisioning, notifications, chargeback automation, and integrations, but nothing describes a human ops review workflow with case assignment, escalation, SLAs, or an audit trail of who approved what and why.

                                                                Risk scoring — stories about risk scoring in this arenaRisk scoring

                                                                Stories about risk scoring in this arena

                                                                Custom signals

                                                                1. developerFeed the model my own signals — device fingerprints, behavioral data, custom metadata — so scoring reflects my business, not just network defaults

                                                                  weight 2 · round to Forter
                                                                  Forterpartialclaimed4/10

                                                                  Forter's Order API accepts order data and metadata at checkout (forter-docs-1) and supports custom decision configuration (forter-docs-18), implying some ability to send custom signals, but there is no documented schema or capability for developers to submit their own device fingerprints, custom behavioral signals, or arbitrary metadata that directly influences scoring weights. missing for 10: explicit API fields/documentation for submitting custom device fingerprint or behavioral data, evidence that custom signals are actually weighted in scoring versus Forter's own network-derived signals, and any tuning/configuration interface for business-specific signal weighting.

                                                                  • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                                                                  • [claimed-docs] If the Auto Invoice option is set to YES, then the payment capture amount operation is executed and order is placed
                                                                  Riskifiednone0/10

                                                                  Riskified's API endpoints (/decide, /submit, /advise) and Beacon.js collect a fixed, vendor-defined set of order/behavioral data required for fraud analysis, and model calibration is explicitly handled by Riskified's own analytics team (docs-12), not the developer. There is no evidence of an API or schema allowing developers to inject custom device fingerprints, arbitrary behavioral signals, or custom metadata fields into the scoring model to tailor it to their own business logic.

                                                                  • [claimed-docs] Riskfied's Beacon is a JavaScript snippet that merchants embed on their website. It collects fundamental data required to decide on the legi…
                                                                  • [claimed-docs] If we have questions about shop flows or encounter data issues, we will reach out to you for clarification... Once data validation passes, y…
                                                                  • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
                                                                  • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…

                                                                Network effects

                                                                1. founderScoring benefits from a cross-merchant network — a card or identity seen across thousands of other businesses informs the risk decision on mine

                                                                  weight 2 · round drawn
                                                                  Forternone0/10

                                                                  The evidence pack covers order submission, webhooks, disputes, chargebacks, PCI scope, and agentic/MCP features, but none of it describes a cross-merchant network effect, shared identity/card risk signals, or network-wide fraud intelligence informing decisions. Missing for 10: any documentation or claim about network-level data sharing, identity graph across merchants, or aggregated fraud signals from other businesses.

                                                                    Riskifiednone0/10

                                                                    The evidence pack only documents Riskified's API endpoints, SDKs, and integration flows (decide, submit, advise, chargeback, notifications, Beacon, login) — none of it describes a cross-merchant data network, shared fraud signals across Riskified's merchant base, or how identity/card history from other businesses informs a given merchant's score. Without any documentation of the network-effect mechanism, this axis has no supporting evidence.

                                                                    Score actions

                                                                    1. ops userMap score ranges to actions — allow, review, block, step-up 3DS — and tune thresholds to my own risk appetite instead of a fixed cutoff

                                                                      weight 2 · round drawn
                                                                      Forternone0/10

                                                                      The evidence pack covers order decisions, webhooks, disputes, PCI scope, and agentic order tagging, but contains no mention of score-range-to-action mapping, configurable thresholds, or step-up 3DS logic that ops users could tune. Forter's docs reference binary/decision-based order outcomes (fraud/abuse decision) rather than a threshold-tuning console. Missing for 10: any documentation of score bands, adjustable thresholds, or 3DS step-up configuration UI/API.

                                                                      • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                                                                      • [claimed-docs] If the Auto Invoice option is set to YES, then the payment capture amount operation is executed and order is placed
                                                                      Riskifiednone0/10

                                                                      Riskified's docs describe its endpoints (/decide, /submit, /advise, login) returning pre-computed decisions like allow/notify/challenge or approve/decline, but there is no evidence that ops users can view underlying risk scores or configure/tune score-to-action thresholds themselves — decisioning appears to be Riskified's managed model rather than a merchant-tunable scorecard.

                                                                      • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                      • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                                                                      • [claimed-docs] API is triggered only for customer-initiated authentication requests, e.g., user tries to login to their account... `decision` field will be…
                                                                      • [claimed-docs] `decision` field will be set as one of the following values: `allow`, `notify`, or `challenge`.

                                                                    Scoring api

                                                                    1. developerGet a machine-learning risk score for a transaction in real time — synchronously, before authorization completes — through a documented API

                                                                      weight 3 · round to Riskified
                                                                      Forterpartialclaimed6/10

                                                                      Forter's Order API (order-v3) is documented as a synchronous checkout-time call returning a fraud/abuse decision, and order-status/webhooks show authorization events are tracked separately, implying the decision precedes authorization — consistent with real-time pre-auth scoring. However, the docs describe a categorical 'decision' rather than an explicit numeric ML risk score, and there's no independent/hands-on latency or scoring-format confirmation. Missing for 10: explicit documentation of a numeric/probabilistic risk score field, and independent verification of real-time performance.

                                                                      • [claimed-docs] Send order information at checkout to receive a fraud or abuse decision.
                                                                      • [claimed-docs] Inform of updates to the status of an order, including payment authorization, fulfillment, shipping details, and compensation granted.
                                                                      • [claimed-docs] Forter has both a production and a sandbox environment for your development process.
                                                                      Riskifiedfullprobed7/10

                                                                      Riskified's documented `/decide` endpoint explicitly returns a synchronous fraud decision before payment authorization completes, matching the real-time pre-auth workflow described in the story, and Riskified's own docs classify this as 'Pre-authorization Synchronous' integration. However, the docs describe a categorical decision (approve/decline) rather than an explicit numeric ML risk score, and no OpenAPI/swagger spec exists (probe returned 404s) to confirm formal API schema. missing for 10: explicit numeric risk-score field documentation, machine-readable OpenAPI spec, independent/hands-on corroboration of latency/real-time behavior.

                                                                      • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                      • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                      • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…
                                                                      • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…

                                                                    Rules engine — stories about rules engine in this arenaRules engine

                                                                    Stories about rules engine in this arena

                                                                    Backtesting

                                                                    1. risk analystBacktest a rule against my historical traffic before deploying it, seeing exactly what it would have blocked, flagged, and cost

                                                                      weight 2 · round drawn
                                                                      Forternone0/10

                                                                      No evidence of any rule backtesting, historical simulation, or cost/impact preview capability in the evidence pack — coverage is about order decisioning, webhooks, disputes, and MCP/agentic orders, none of which address testing rules against historical traffic before deployment.

                                                                        Riskifiednone0/10

                                                                        Evidence covers Riskified's fraud-decision APIs, notifications, chargeback integrations, and merchant integration flows, but nothing describes a rule backtesting capability against historical traffic showing what would have been blocked/flagged/cost before deployment.

                                                                        Lists

                                                                        1. ops userMaintain allow and block lists — emails, cards, devices, IPs — and velocity limits, managed through the dashboard and programmatically

                                                                          weight 2 · round drawn
                                                                          Forternone0/10

                                                                          The evidence pack contains no mention of allow/block lists (emails, cards, devices, IPs) or velocity limit configuration, either via dashboard or API — only order decisioning, webhooks, disputes, and agentic order APIs are documented. This is a fair capability to expect from a fraud-rules platform, but no evidence supports it.

                                                                            Riskifiednone0/10

                                                                            Evidence covers order decisioning APIs, notifications, chargebacks, and integrations, but nothing describes allow/block lists for emails, cards, devices, or IPs, nor velocity limit configuration via dashboard or API.

                                                                            Rule authoring

                                                                            1. risk analystAuthor custom rules that combine model scores, velocity counters, list matches, and transaction attributes into allow, block, or review decisions

                                                                              weight 3 · round drawn
                                                                              Forternone0/10

                                                                              The evidence pack covers order submission, webhooks, chargeback/dispute automation, and MCP/agentic order tagging, but contains no mention of a custom rules engine, rule authoring UI/API, velocity counters, list matching, or configurable allow/block/review decision logic controlled by risk analysts.

                                                                                Riskifiednone0/10

                                                                                Riskified's docs describe API endpoints (decide/submit/advise), notifications, and integrations, but there is no evidence of a user-facing custom rules authoring interface where a risk analyst can combine model scores, velocity counters, list matches, and transaction attributes into allow/block/review logic. The decisions described (allow/notify/challenge, approve/decline) are produced by Riskified's own models, not by analyst-authored rules. Missing for 10: any rule-builder UI, rule syntax/DSL, ability to combine velocity counters/list matches/model scores into custom logic, or analyst-facing rule management docs.

                                                                                • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                                • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                                                                                • [claimed-docs] API is triggered only for customer-initiated authentication requests, e.g., user tries to login to their account... `decision` field will be…
                                                                                • [claimed-docs] `decision` field will be set as one of the following values: `allow`, `notify`, or `challenge`.

                                                                              Not comparable on these axes

                                                                              1. ai-native userPlug MCP servers into this product so it can use their tools

                                                                                weight 3 · not comparable
                                                                                Fortern/a

                                                                                Forter's MCP evidence shows it exposing its own MCP server so external AI agents (e.g., Claude Desktop) can call Forter's fraud/dispute tools, not Forter itself acting as an MCP client that consumes and uses other servers' tools. As a fraud-decisioning SaaS platform, not an agent/orchestrator, the client-side 'plug in MCP servers' story is the wrong axis for this product's role.

                                                                                • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                                                                                • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
                                                                                • [probe] official MCP server documented at https://docs.forter.com/mcp
                                                                                Riskifiedn/a

                                                                                Riskified is a fraud-detection/e-commerce risk platform, not an AI agent or agent-enabling framework; plugging MCP servers into it so it can use external tools is a category mismatch for this product type, and no evidence suggests otherwise.

                                                                                • ai-native userIssue scoped/least-privilege API credentials for an agent

                                                                                  weight 2 · not comparable
                                                                                  Forternone0/10

                                                                                  Forter has API/webhook docs and even an MCP server for agent-driven actions, but no evidence describes issuing scoped or least-privilege API credentials/tokens for an agent identity. Missing for 10: any mention of API key/token scoping, permission levels, or credential issuance workflow for agents.

                                                                                  • [claimed-docs] It enables an AI system to perform real actions—such as reviewing decisions, managing disputes, or updating policies through natural languag…
                                                                                  • [claimed-docs] Connect Forter MCP to Claude Desktop app for conversational AI workflows.
                                                                                  • [probe] official MCP server documented at https://docs.forter.com/mcp
                                                                                  Riskifiedn/a

                                                                                  Riskified is a fraud-decision API/service for merchants, not an agent-facing platform; there is no concept of issuing scoped credentials for an AI agent to act on a user's behalf. Authentication uses a single HMAC token per merchant integration, not agent-scoped credentialing — this is a category mismatch, not a missing feature.

                                                                                  • ai-native userSchedule recurring jobs or workflows

                                                                                    weight 2 · not comparable
                                                                                    Forternone0/10

                                                                                    Forter is a fraud-decisioning platform with webhooks, an MCP integration, and event-driven notifications, but there is no evidence of a scheduler or ability to define recurring/cron-style jobs or workflows within Forter itself.

                                                                                      Riskifiedn/a

                                                                                      Riskified is a fraud-decisioning API/service, not an automation platform or agent framework; scheduling recurring jobs/workflows is not a relevant capability for this product category — it operates via real-time synchronous/asynchronous fraud decisions triggered by order events, not user-defined recurring schedules.

                                                                                      • ai-native userVersion, review, and roll back my automations

                                                                                        weight 1 · not comparable
                                                                                        Forternone0/10

                                                                                        No evidence of any versioning, review, or rollback mechanism for automations/workflows in Forter's docs; the MCP and agentic-order features cover fraud decisioning and dispute automation, not automation lifecycle management like version history or rollback.

                                                                                          Riskifiedn/a

                                                                                          Riskified is a fraud-decisioning API/service, not an automation-authoring tool with versionable workflows; there is no concept of user-built 'automations' to version, review, or roll back in this product category.

                                                                                          • ai-native userExport all of my data in open formats and leave

                                                                                            weight 3 · not comparable
                                                                                            Forternone0/10

                                                                                            Forter is a fraud-detection/risk B2B API platform; no evidence of any end-user data export feature or open-format data portability for merchants or consumers to 'leave' with their data. Missing for 10: any documented data export tool, open format (CSV/JSON) export capability, or account-closure data portability process.

                                                                                              Riskifiedn/a

                                                                                              Riskified is a fraud-decision API/service, not a data-storage or content-authoring product where a user's own data/documents need export in open formats; there's no concept of user-owned data corpus to 'export and leave' — this axis is a category error for this product type.

                                                                                              • ai-native userRead the product's source under an open license

                                                                                                weight 2 · not comparable
                                                                                                Forternone0/10

                                                                                                Forter is a closed, proprietary fraud-prevention SaaS; no evidence of any open-source license or public source code repository for the core product. Missing for 10: any open-source license grant, public source repository, or licensing terms permitting source inspection/modification.

                                                                                                  Riskifiedn/a

                                                                                                  Riskified is a closed, proprietary fraud-detection SaaS product; there is no source code to read and no open-license claim anywhere in the evidence. Reading source under an open license is a category error for this type of hosted commercial service.

                                                                                                  • ai-native userSelf-host the core product

                                                                                                    weight 3 · not comparable
                                                                                                    Fortern/a

                                                                                                    Forter is a SaaS fraud-prevention platform delivered as a cloud API/service; there is no evidence of a self-hostable core product, and self-hosting is not a plausible axis for this category of hosted decisioning service.

                                                                                                      Riskifiedn/a

                                                                                                      Riskified is a SaaS fraud-decisioning platform delivered via API/notifications with backend model calibration performed by Riskified's own analytics team; self-hosting the core product is not a coherent axis for this category of service.

                                                                                                      • ai-native userPrevent my data from being used to train AI models

                                                                                                        weight 3 · not comparable
                                                                                                        Forternone0/10

                                                                                                        Forter is a fraud-detection/e-commerce risk platform; the evidence pack contains no privacy policy, data-processing agreement, or opt-out mechanism addressing whether user data is used for AI model training. No documentation of a training opt-out or data-use control was found.

                                                                                                          Riskifiedn/a

                                                                                                          Riskified is a fraud-prevention/e-commerce risk API, not an AI model or AI assistant product; the story about preventing personal data being used for AI model training is not a relevant axis for this kind of product.

                                                                                                          • ai-native userOpt out of telemetry and usage tracking

                                                                                                            weight 2 · not comparable
                                                                                                            Fortern/a

                                                                                                            Forter is a fraud-detection/e-commerce risk platform, not an AI assistant or developer tool with client-side telemetry that an end user could opt out of; the privacy-posture/telemetry-opt-out axis is a category mismatch for this product type.

                                                                                                              Riskifiedn/a

                                                                                                              Riskified is a fraud-prevention/risk API platform, not an AI developer tool or agent with telemetry collected from AI-native usage; opt-out of telemetry/usage tracking is not a relevant axis for this product category.