The first thing to fail at Asaas was recognition. The Brazilian fintech wanted to know when a familiar customer came back. Its device fingerprinting tool was forgetful. People who belonged there kept being asked for a one-time passcode at login, a small interruption that becomes a large expense when repeated often enough. And the obvious remedy - checking more moments in the journey with more tools - looked expensive. So Asaas tried something else: it installed Darwinium through AWS CloudFront and let the fraud system learn from the journey, not just the door.
- Darwinium sells fraud prevention software to banks, fintechs, marketplaces, ecommerce firms and gaming operators.
- Its edge deployment links signals from browsing, login, APIs and payment, then recommends or enforces a risk response.
- In Darwinium’s Asaas case study, returning-user recognition reached 97% at login and passcode use fell 46%.
- The practical lesson: measure both fraud caught and needless friction imposed on good customers.
Asaas’s reported results are the sort of numbers that make a security meeting suddenly sound like a customer experience meeting. Darwinium says 97% of returning users were recognized at login; 94% received a positive trust score; and one-time passcode use dropped 46%. Its entity-linking tools also connected 49 account-takeover attempts made across two days. These are figures from a customer case study, not a universal promise. Their interest lies in the mechanism: better memory made it possible to ask fewer innocent people to prove themselves while seeing a pattern that individual logins concealed.
The crime scene begins upstream
Darwinium’s proposition rests on a mildly embarrassing fact about many fraud systems: they arrive at the climax and ask what happened. A payment can be legitimate in form and suspicious in context. A correct password may belong to a thief. A transfer can be made by the real account holder under a scammer’s instructions. A seller account may look ordinary until its listings, devices, and neighboring accounts are considered together. One transaction is a still photograph. A journey gives you the film.
The company places its decisioning software at the network edge, where a content delivery network handles traffic before it reaches a site or app. With Cloudflare, the implementation uses Workers; with AWS CloudFront, Lambda@Edge. Darwinium also documents Akamai support, mobile profiling, and APIs. The point is coverage: signup, login, account changes, content, checkout, and the API calls between them can all supply context. Its models and rules look at network details, device attributes, behavioral signals, and how one event follows another. A risk team can permit a familiar pattern, request another check, or interrupt something that looks abusive.
That is where Darwinium differs from a tool that checks only a card payment, a login, or a bot score. It tries to carry context across the trip and make decisions close to the traffic. There are plenty of alternatives - LexisNexis Risk Solutions’ ThreatMetrix, Sift, Forter, bot-management products, and in-house risk systems. Darwinium’s specific argument is that one edge integration can collect broader signals and apply a consistent policy at more points without a separate release for each page. A buyer still has to decide whether that wider view is worth the integration and operating cost.
The people who built the earlier checkpoint
The story has a neat twist. Darwinium’s four co-founders - Alisdair Faulkner, Ben Davey, Caleb Moore and Colin Goldie - all came from ThreatMetrix. Faulkner had helped build a digital identity business. Darwinium, founded in 2021, reflects the next question: once you recognize an identity, what should you infer from its behavior? Even the company’s name carries a biographical wink. Faulkner was born in Darwin, Australia; the second half nods to the naturalist. The company’s thesis is evolutionary too: defenses have to change as the actors change.

There is a recognizable enterprise business here. Darwinium sells to fraud, security, risk and product teams at businesses with enough digital traffic and loss exposure to make the distinction matter. Named examples include Asaas, GoTyme Bank and Udemy. Its public customer page says GoTyme protects more than 100 million monthly interactions through the platform. A gaming customer, unnamed in its case study, reportedly reached 99.95% returning-user recognition while looking for repeat bonus claimants who used proxies, emulators, cleared cookies and CAPTCHA-solving tools to appear new. These are different industries with the same puzzle: when does a changed surface hide a familiar actor?
“We chose Darwinium as our strategic partner due to their ability to provide protection throughout the customer journey.”Aaron Foo, chief product officer, GoTyme Bank
Udemy offers another version of the problem. Its marketplace has learners, instructors, signups, purchases and course consumption. The company’s case study says older controls offered generic detection and limited visibility across those activities. Darwinium was deployed at the CDN edge to connect web and API signals. Udemy software architect Nik Brauer said the team could find activity across multiple accounts and journeys that it had missed before, then trace it toward resolution in minutes. That is a more interesting claim than “AI-powered security.” It tells you what an analyst could actually do on Tuesday morning.
Now the shopper may be a machine
The newer products follow the changing cast of characters online. In 2024 Darwinium introduced Digital Signatures, which compare devices and behavior by similarity instead of relying solely on a cookie or fixed fingerprint. In July 2025 it announced Beagle, which uses AI agents to simulate fraud against customer journeys, and Copilot, an assistant for investigating patterns and suggesting changes to rules. The announcement invited users to a waitlist, so its launch should be read as a product announcement, not evidence that every customer had both tools in production.

In March 2026, Darwinium launched Agent Intent Intelligence. Its premise is sound even if the market is young: an AI agent browsing for a customer and an automated attacker may both look like bots at first glance. The product validates agent identity where possible, examines behavioral and journey signals, then chooses among permit, verify, challenge and prevent. The interesting move is the refusal to treat all automation as one species. A shopping assistant reading product pages and a script trying stolen passwords require different responses.
The invoice behind the insight
Darwinium does not publish a standard contract price. Its documentation does publish something many software pitches tuck away: running risk logic in the customer’s CDN can create third-party charges. A protected request may invoke a Cloudflare Worker or an AWS edge function; lookups can use key-value storage; customer-owned event storage is another possible line item. The size of the bill depends on traffic, the protected steps, and the chosen architecture. The company says deployment can take days, but an honest trial would count engineering time, CDN usage, fraud losses, and the cost of challenges imposed on legitimate users.
Pick one journey with a measurable nuisance - repeated login passcodes, false bot blocks, or manual review. Establish a baseline. Add journey-level signals, compare recognition and fraud capture, then calculate the CDN bill per protected interaction. Expand only when the total result improves.
That test has conditions. Edge deployment needs access to the CDN and agreement from the teams that control it. A customer journey split across channels may also need mobile or API instrumentation. Similarity scores can misread unusual but honest behavior, so policies need thresholds, review and a way to reverse a bad decision. If the main problem is a narrow payment rule and there is little upstream context to use, a broad journey system may cost more than it returns. Darwinium’s own Asaas example is compelling precisely because the original failure was broad: the old tool could not reliably remember good customers, and every forgotten customer paid for it with another code.
The company raised a $10 million seed round announced in 2022 and an $18 million Series A in 2023. A February 2026 SEC filing records nearly $7 million sold in a new equity offering, without giving it a familiar venture-round name. Money buys time to pursue a larger claim. Darwinium wants fraud prevention to become a running interpretation of a digital relationship, from the first request onward. The lesson for everyone else is simpler and cheaper: when a security check is failing, inspect what happened before the alarm, and count how many innocent people the alarm interrupts.