Fraud & risk monitoring
Every transaction that reaches Target is checked against your rules and our machine-learning score before it is sent to the bank. You decide what to approve, what to challenge with 3-D Secure and what to decline — and you see why in the dashboard within seconds.
What the rules engine does
The rules engine is the part of Target you control. Combine velocity limits, geography, BIN data and device signals into rules that fit your business, test them on your last 30 days of traffic and switch them on without a deploy. Rules run before authorisation, so a declined payment never reaches the issuing bank and never counts against your approval ratio.
Velocity rules
Limit how often a card, e-mail, IP address or device can pay within a window: 3 attempts per card per hour, €2,000 per customer per day, 10 new cards per IP per week. Counters are shared across all your merchant accounts.
Geo & BIN rules
Match the card's issuing country, the customer's IP country and the shipping address. Block or challenge mismatches, restrict prepaid or corporate BINs, and treat high-risk regions differently from your home market.
Device fingerprint
A 4 KB script on your checkout builds a fingerprint from more than 40 browser and device signals. Repeat offenders are recognised even when they change the card, the e-mail and the IP address.
Machine-learning score
Every transaction gets a score from 0 to 100 built on the behaviour of millions of payments across our partner network. The model is retrained weekly on confirmed fraud and chargeback outcomes — including yours.
Blacklists / whitelists
Keep your own lists of cards, e-mails, IPs, devices and BINs. Add entries by hand, import a CSV or let a rule add a card automatically after a confirmed chargeback. Whitelists protect your best customers from false declines.
Manual review queue
Transactions that fall between approve and decline go to a review queue with every signal side by side. Your team — or ours, on Enterprise — approves or declines them within the SLA you set. 30 minutes by default.
How a transaction is scored
Scoring happens between the moment the customer presses Pay and the moment we request authorisation from the acquiring bank. The whole chain takes under 150 ms — the customer never notices it.
Capture
The checkout sends the card token, the order details and the device fingerprint. Nothing touches your servers — the data goes straight into Target's PCI DSS Level 1 environment.
Enrich
We add the BIN record (issuer, country, card type), IP geolocation, the customer's history across all your merchant accounts and the cross-network reputation of the card and the device.
Score
Your rules run first and can approve, challenge or decline outright. Everything else goes to the machine-learning model, which returns a score from 0 to 100 and the three signals that influenced it most.
Decide
Low scores are authorised instantly. Medium scores are challenged with 3-D Secure 2.2 or sent to manual review. High scores are declined before they reach the bank — and the customer sees a plain, honest message.
Authorised straight away. Where the issuer allows it, we request a 3-D Secure exemption so the customer skips the challenge altogether.
3-D Secure 2.2 challenge by default; a rule can send the transaction to the manual review queue instead.
Declined before authorisation. The card, e-mail and device are added to your greylist for 30 days.
These are the default thresholds for a new account. You can move them per country, card type, order amount or customer segment — every band is just another rule.
Fewer chargebacks.Faster answers.
A chargeback costs you the order, the goods and a €15 fee — and every one counts towards the Visa and Mastercard monitoring thresholds. Target tells you about a dispute before it becomes a chargeback, gives you the evidence to fight it and shows you the ratio you need to stay under.
- Chargeback alerts
- Within 24 h of the cardholder's dispute, through Visa and Mastercard Ethoca alerts and issuer notifications. Refund in time and the chargeback never happens.
- Evidence templates
- Pre-filled representment packs for the most common reason codes: delivery confirmation, IP and device match, 3-D Secure proof, communication history. Export as PDF or send straight from the dashboard.
- Dispute win rate
- 62% of the disputes our merchants represent are won — roughly twice the card-not-present industry average.
- Networks
- Visa Compelling Evidence 3.0 and Mastercard Ethoca are included on every plan. Verifi CDRN is available on request.
- Fee
- €15 per chargeback that actually happens. Nothing for an alert you refund in time.
Rules you can write
A rule is plain JSON: a name, a condition and an action. Write it in the dashboard editor with autocomplete, or push it through the API from your own repository. Every rule has a dry-run mode that shows what it would have done on the last 30 days of your traffic before it goes live.
Rules are evaluated top to bottom and the first match decides. Four actions cover every case: approve, challenge with 3-D Secure, send to review, decline.
Rules API referencerules.json// Evaluated top to bottom. The first matching rule decides. [ { "name": "trusted-customers", "when": { "list": "whitelist.email", "contains": "$.customer.email" }, "then": "approve" }, { "name": "velocity-card-1h", "when": { "count": "$.card.token", "window": "1h", "gt": 3 }, "then": "decline", "reason": "too_many_attempts" }, { "name": "geo-mismatch-over-250", "when": { "all": [ { "field": "$.card.bin.country", "ne": "$.customer.ip.country" }, { "field": "$.order.amount", "gte": 250, "currency": "EUR" } ] }, "then": "challenge_3ds" }, { "name": "ml-high-score", "when": { "field": "$.risk.score", "gte": 70 }, "then": "review", "queue": "night-shift", "sla": "30m", "notify": ["risk@yourshop.com"] } ]
Fields follow the transaction object from the API; the same JSON can be posted to POST /v1/risk/rules and comes back in every webhook as the risk.rule that fired.
See every decision
The risk view is part of the merchant dashboard. It shows the live approve / challenge / decline split, the rules that fired most, the score distribution and your chargeback ratio against the Visa and Mastercard thresholds.
Open any transaction to see all 40+ signals and the three that mattered, then approve, decline or refund with one click. Roles let support staff see decisions without editing rules, and every rule change is versioned with the author and the time.
Merchant dashboard- Machine-learning score and its top three drivers
- Rules that fired, in order, with the dry-run outcome
- Issuer, country and card type from the BIN
- IP country, ASN and proxy / VPN detection
- Device fingerprint and how often it was seen
- 3-D Secure result and the liability shift
- Customer history across all your accounts
- Chargeback ratio, current month, per network
- Review queue: who decided, when, and why
Switched on for every merchant from the first transaction. No per-check fee.
No. Every account starts with a default rule set tuned for its industry — e-commerce, SaaS, travel, digital goods — and the machine-learning score works from the first transaction. Most merchants add two or three rules of their own in the first month, usually a velocity limit and a whitelist. On Business and Enterprise your personal manager reviews the rule set with you every quarter.
Only if the thresholds are wrong — and you can see that in the dashboard before it costs you anything, because every rule runs in dry-run mode first. Our merchants average 88% payment conversion with fraud monitoring switched on for every one of them. Whitelists and 3-D Secure exemptions for low-risk transactions keep good customers away from friction.
It is held with an authorisation on the card, so the funds are reserved but not captured. Your team — or ours, on Enterprise — sees every signal side by side and approves or declines within the SLA you set; 30 minutes by default, and a queue rule can auto-approve or auto-decline when the SLA runs out. The customer sees a "payment is being confirmed" message on your checkout, and a webhook fires the moment the decision is made.
The rules engine, the machine-learning score, device fingerprinting and chargeback alerts are included in every plan — Start, Business and Enterprise — with no per-check fee. You pay €15 per chargeback that actually happens and nothing for an alert you refund in time. Manual review by Target's own analysts is an Enterprise option priced per reviewed transaction — see the pricing page.