MEET FINGERLYA clearer picture of every session.Explore the signals
Environment integrity

Question the disguise. Know when it does not add up.

Spoofing a browser means changing what it reports, and changing it leaves marks. Fingerly reports modified browsers, anti-detect browsers that claim to be something they are not, and app environments that have been compromised.

  • Modified browsersReported facts that were changed.
  • Anti-detect browsersA claimed identity that does not fit.
  • Compromised devicesRooted and jailbroken phones.
  • InterceptionTraffic read in the middle.
Environment integrity

Every signal can be hidden. Hiding it is the finding. Automation tools and anti-detect browsers work by changing what a browser says about itself. Tampering detection looks for the changes and the contradictions they leave, which is why it catches disguises that ordinary checks read as a normal browser.

  • Browsers whose built-in behaviour has been modified
  • Anti-detect browsers claiming an identity they do not have
  • Rooted, jailbroken and instrumented devices
  • Repackaged apps and intercepted connections

Two findings for browsers.

Both belong to the browser tampering group in the console, with default weights you control.

SignalWebAndroidiOSWhat it means
Tampering888The browser or app runtime has been modified.
Anti-detect browser8n/an/aThe browser’s behaviour contradicts the browser it claims to be.

A contradiction between what a browser claims to be and how it behaves is reported at high confidence.

App and device integrity.

Native iOS and Android SDKs answer questions a browser never can. These signals exist only on the platforms that can observe them.

SignalWebAndroidiOSWhat it means
Instrumentationn/a1414A hooking or instrumentation framework is attached to the app.
Interceptionn/a1414Something is intercepting the app’s encrypted traffic.
Rooted devicen/a12n/aThe Android device is rooted.
Jailbroken devicen/an/a10The iPhone or iPad is jailbroken, including rootless jailbreaks.
Cloned appn/a9n/aThe app runs inside a cloning framework.
Tamperingn/a88The app binary or its runtime failed an integrity check.

On Android, hardware-backed attestation is verified on the server, where a compromised device cannot rewrite the answer.

Strict about what counts.

Developers tamper with their own devices all the time. The rules are tuned so that ordinary development does not read as an attack.

Debug builds are not attacks

A debug build installed from a laptop is how every team tests. On its own it is not enough to report tampering.

An unlocked bootloader is not root

Developers unlock bootloaders. That fact alone stays below the line that reports a rooted device.

Decided on the server

An app can be patched to report anything, so the server re-reads the evidence and makes the decision, and your backend should too.

Where disguises pay off.

Tampering is rarely the goal. It is how an operator gets past the checks you already have.

  1. 01Multi-accounting
  2. 02Mobile banking
  3. 03Games and rewards
01

Multi-accounting

A new identity for every account.

Anti-detect browsers exist to make one operator look like many unrelated customers. Tampering on a new account is a strong reason to hold what that account is given.

Check at
SignupPayouts
Signals
Anti-detect browserTamperingVisitor ID
New account fraud
02

Mobile banking

Money movement from compromised phones.

Instrumentation or interception during a transfer is worth stopping for, whatever the rest of the session says.

Check at
LoginTransfersChanging payees
Signals
InstrumentationInterceptionRooted device
Banking
03

Games and rewards

Modified clients, unfair advantages.

Cloned apps and instrumented devices at reward redemption are a better reason for review than a blanket ban.

Check at
Reward redemptionOnboarding
Signals
Cloned appInstrumentationTampering
iGaming

About tampering.

How tampering signals behave on browsers and on phones.

Talk to the team
What is an anti-detect browser?

A browser built to present a different identity for every account an operator runs: a different device, system and location each time. Fingerly reports one when what the browser claims to be contradicts how it actually behaves.

Can a rooted phone hide from detection?

Hiding tools exist, and the rules are ordered by what a tell costs to remove. Evidence that is hard to fake, such as hardware attestation verified on the server and contradictions between what the device reports, carries the most weight.

Why should my backend make the decision?

Anything computed on a device the visitor controls can be patched. The identify response is also stored on the server, and your backend can read it by request ID with a secret key before it acts.

[ IDENTIFY ][ UNDERSTAND ][ DECIDE ][ FINGERLY ]
Less guessing. More knowing.

Make the next connection a trusted one.

Start with the signals, keep your own decisions, and pay only for what you identify. No credit card needed.