Stytch
p/stytch
User infrastructure for modern applications
Lenny Rachitsky
Stytch Fraud & Risk Prevention — Stop bots, fraud, and abuse with industry-leading accuracy
Featured
36
Powerful fingerprinting technology stops bots and fraud from accessing your app. With 99.99% bot detection accuracy, it delivers risk verdicts & actions, features intelligent rate limiting, protects against reverse-engineering, and preserves user privacy.
Replies
Lenny Rachitsky
Hey Product Hunt, I’m thrilled to share Stytch’s Fraud & Risk Prevention solution with you today. I'm a huge fan of Stytch because they continue to innovate and rethink how authentication and fraud prevention can work for your product. Stytch’s new Fraud & Risk Prevention solution goes beyond basic identity verification, addressing critical issues such as programmatic fraud, compute abuse, and account takeover using advanced technology. The team is eager for your feedback as they continue to innovate in this space. Thanks for your support! 🚀
Julianna Lamb
@annaho2000 yes! We plan to continue identifying opportunities to incorporate ML into the product. Our intelligent rate limiting product does this already, identifying anomalies in traffic patterns and automatically blocking accordingly.
Tony Han
Love seeing lots of industry experts who are using this product. The way finger printing is stitched together to derive at a decision is pretty smart! congrats on the launch @jelamb and team! PS: hey Lenny!
Julianna Lamb
@tonyhanded thank you!
Julianna Lamb
Hi Product Hunt Community! I’m Julianna, founder and CTO of Stytch. We’re a team that wants to make it easier for you to scale your applications and keep them secure. We’re excited to announce today a radical new approach to protecting applications and users against fraud and abuse. 🚩The Problem: Auth alone is no longer enough While we’ve spent the last few years focused on building better authentication infrastructure for developers, we’re seeing a worrying trend where threats are becoming more sophisticated and more pervasive - thanks in no small part to AI. Even the strongest methods can fall short and leave your app susceptible to: - Free tier abuse and programmatic fraud. Your app needs a better understanding of who each user is when they log in, going way beyond self-reported attributes. - Account takeover. Your app needs to evaluate what specifically a given auth method attests to, and how it interacts with other vectors. - Account theft. Social engineering, phishing, and session hijacking are all very difficult to mitigate unless your app is collecting low-level sub-signals to understand if the user is really who they claim to be. 🚫 Limitations of Current Solutions WAF and CAPTCHA only look at parts of the problem. These solutions are either incomplete, not very accurate or use blunt force methods that ruin the user experience. They’re reasonable as a first line of defense but work at a pretty broad level (e.g, IP address range) and can’t evaluate and shape traffic at a granular level. And they’re simply not built for the sophisticated attacks we see today. 🚀 Introducing Stytch Fraud and Risk Prevention Stytch’s new solution delivers the industry's most accurate and intelligent fingerprint-based solution. It’s completely integrated with our auth platform - or can be used as a standalone security product. It offers the most accurate device fingerprint using a broad collection of standard and proprietary signals from across: - Software stack and OS version - Browser sub-signals and capabilities - Passive network TLS fingerprinting - User attributes - Hardware architecture and resources And to combat advanced fraud, we’ve released these new cutting-edge features: * Security Rules Engine: For every fingerprinted visitor, Stytch returns a clear verdict of whether that visitor should be allowed, blocked or further challenged before being granted access. These rules are further configurable via either the Stytch dashboard or programmatically via our API. * Intelligent Rate Limiting: The Stytch solution also supports fine-grained rate limiting. Unlike network-focused solutions, when Stytch identifies a potential vulnerability it can limit the specific device or set of devices that are the offenders. Whereas other bot mitigation solutions might rate limit an entire IP address range, with both good and bad actors. * ML-Powered Device Detection: While the foundation of our fingerprinting solution is deterministic and rules-based, we’ve also introduced a machine learning model to accelerate device detection and categorization, further improving zero-day threat detection and overall user experience. Stytch's Fraud and Risk solution offers industry-leading accuracy in detecting bots and bad actors, even when methods like browser automation frameworks or user agent deception are employed. Unlike other fingerprinting solutions, it is resistant to reverse engineering and tampering, natively integrates with authentication, and delivers low latency for a seamless user experience. We think we’ve created something really special here and we’re eager for feedback from the Product Hunt community!
Julianna Lamb
@antonikozelski thank you!
Robert Fenstermacher
Super excited to be a part of this launch and get to hear from customers like Replit, Pixels and Hubspot that are already using this product as critical security infrastructure for their app to protect against bots, fraud and abuse
Julianna Lamb
@bob_fenstermacher thanks Robert!
Vlastimil Vodička
With all the upcoming bots - this is actually very useful!
Adam Brzeczek
Love this. Really innovative approach to fraud prevention and a great solution for modern threats. Congrats on the launch!
Julianna Lamb
@abrez thank you!!
Andy Hwang
Thanks for sharing, Lenny! Stytch's new solution sounds promising. With online fraud becoming more sophisticated, it's great to see innovations in prevention. I'm curious about how it balances security with user experience - does it add any noticeable friction for legitimate users? Also, that 99.99% bot detection accuracy is impressive if it holds up in real-world use. Might be worth looking into for our app's security upgrade.
Julianna Lamb
@andyroamer thanks for the feedback! The 99.99% is based on real world data, it's from our experience with our early customers where we've seen hundreds of millions of fingerprints. There's no friction for users, unless you choose to introduce friction for potentially risky interactions in the rare cases you get a challenge verdict from us. But for most users, they don't need to do anything, we'll passively gather all the signals we need to generate the fingerprints.
Toshit Garg
Congratulations on launch of Stytch Fraud & Risk Prevention.....
Julianna Lamb
@toshit_garg thank you!!
Tony Carter
Hey Julianna and the Stytch team! 🌟 This new Fraud and Risk Prevention solution sounds like a monumental step forward in application security. The range of threats you’re addressing—from free tier abuse to sophisticated account takeovers and theft—is truly impressive. Your device fingerprinting approach, combining software stack insights with ML-powered detection, promises to bring unprecedented accuracy and resilience against even the most advanced attacks. The Security Rules Engine and Intelligent Rate Limiting are particularly exciting features, offering robust protection without compromising user experience. Integrating this seamlessly with your existing auth platform, or as a standalone product, is a fantastic move. Kudos on this game-changing innovation! 🚀🛡️ @jelamb
Julianna Lamb
@tony_creator thank you!!
Kevin Yao
The integration with auth processes is a smart move. Curious about how it compares to traditional methods like CAPTCHAs in terms of user experience? Would love to see some early success stories! 🚀
Julianna Lamb
@kevinyaoooooo Thanks so much! Our solution has a few major UX improvements over traditional CAPTCHAs. First, our solution can operate invisibly in the background. Visitors can be vetted and identified without any prompts. This means no more unnecessary clicks or frustrating visual challenges disrupting key user flows in your app. You can check out a customer story from Replit here: https://stytch.com/customer-stor... Second, our solution provides stable identifiers for every visitor, which means you can tailor app-specific "step-up" or "challenge" flows beyond CAPTCHAs. Our new example app showcases how to leverage Stytch to implement Adaptive Multi-Factor Authentication, prompting users for MFA only when logging in from a new or unrecognized device. It demonstrates key use cases including new user login and MFA enrollment, returning users logging in on recognized devices, and MFA prompts for unrecognized devices. And on the security side, it's no contest. Unlike traditional CAPTCHAs, which can be bypassed by AI or click farms, Stytch uses fingerprinting signals to detect bots or ensures that the same device that requested the challenge completes it.
Jackieline Cosares
The blend of advanced fingerprinting technology and intelligent rate limiting is super impressive. Your approach to tackling sophisticated threats with such precision is bound to make a huge difference in app security.
Alexander William Hawkins
This sounds like a super smart solution to a growing problem! Love how Stytch is going beyond just auth to really address sophisticated threats. Excited to see how the intelligent rate limiting and ML-powered detection works in practice. Congrats on the launch, can't wait to try it out.
Haris Gul
Launching soon!
@lenny_rachitsky Kudos on the stellar launch, Stytch Fraud & Risk Prevention team! Your advanced fingerprinting technology is revolutionizing app security with unparalleled bot detection and fraud prevention. It’s exciting to see your focus on both accuracy and user privacy. How do you anticipate your fraud prevention measures influencing user trust and retention? At InterWiz, we’re transforming the hiring landscape with AI-driven evaluations, enabling recruiters to seamlessly identify top talent, thereby fostering more robust and capable teams.
Julianna Lamb
@lenny_rachitsky @haris_gul thanks for your feedback! the implications on user trust are similar to any other fraud detection and prevention product, it's important to ensure your TOS reflects accurately what data is being collected and how you're using that data. ultimately, using Stytch fingerprinting helps to keep users' accounts secure and so is beneficial for them.
Haris Gul
Launching soon!
@lenny_rachitsky @jelamb I Love seeing your engagement and insights! If you could hover over the 'Coming Soon' badge next to my name and click 'Notify Me' on InterWiz AI, I'd appreciate your support—excited to hear your thoughts when we launch!
Mitia
This looks like a fantastic solution! One small thing...we tried it and noticed the documentation page was slow to load on mobile. It might be worth optimizing that, but otherwise, everything is spot on!
Julianna Lamb
@mitia thanks for the feedback! we'd love to better debug this, our testing on mobile and with low bandwidth connections isn't reproducing this, if you'd be willing to send a screen capture of what you're seeing to support@stytch that would be awesome
Elisa Verita
🙌 Congrats to the team on the launch!
Julianna Lamb
@elisa_verita thank you for all your work on it!!
Edwin Lim
This new fraud prevention solution feels game-changing for today's SaaS apps. It seems like innovation in authentication and identity rarely happens, but this product is a major step forward with its device detection + auth capabilities. Congrats to the team on the launch!
Julianna Lamb
@edwin_stytch thanks Edwin 🙌
Charley Ma
congrats on the launch! super smart to embed fraud + fingerprinting into auth
Julianna Lamb
@charleyma thanks Charley!
Hamad Amir
This is awesome! I was just thinking the other day, of solutions to prevent bot and fraud traffic from attacking my website. Congratulations on your new solution, I will definitely be digging deeper.