Share:
A Marketplace Verified the Account. Incognia Wants to Know Who Is Using It Now
TL;DR: A marketplace can verify who opened an account. But that does not guarantee the same person will still be behind it months later. We spoke with Incognia about what marketplaces can look for when the identity they verified and the activity they see begin to drift apart.

A seller creates an account on an online marketplace, proves their identity, and passes the platform’s checks. At that point, the marketplace has established who was behind the account when it was verified.

But what if someone else starts using it months later?

The account could be shared with another person, rented out, sold, or taken over. The identity check at sign-up may have been completely accurate. What may have changed was the person behind the account.

For marketplaces connecting buyers with sellers, workers, drivers, or service providers, that creates a harder question: how do you know whether a trusted account is still being used by the person you originally verified?

That question is shaping how fraud prevention company Incognia thinks about recognition across devices, locations, and behavior over time.

We spoke with Eduardo Pires, Incognia’s Director of Fraud Solutions, about what happens after identity verification, when a marketplace still needs to know whether its trust in an account still holds.

When Does a Trusted Account Stop Looking Like Itself?

There is no single change that answers that question.

A user may buy a new phone. A seller may travel. Someone’s usual behavior on a platform may change. None of those events, on its own, means that a different person has taken over the account.

Pires told SaaStake that marketplaces should instead pay attention when several things begin changing together.

A new device might appear alongside a different location history. Behavior may no longer match the account’s earlier patterns. That device might also be connected to several other accounts, or the account’s transaction or content activity may suddenly change.

“A single change may be legitimate; the combination is what suggests that an account has been sold, rented, shared, or taken over,” Pires said.

That distinction changes the problem. A marketplace is not simply looking for something unusual. It is trying to determine whether the activity it sees today still fits the history and signals that made the account appear trustworthy in the first place.

For Incognia, that way of thinking about identity did not begin with marketplaces at all. It grew out of a very different use for location technology.

Incognia Arrived at This Problem From Somewhere Else Entirely

Before Incognia became a fraud prevention company, its location technology was being applied to a very different problem.

Its predecessor, In Loco, had developed precise location technology that was eventually used in a marketing business helping physical retailers understand whether advertising was bringing people into stores. When the pandemic closed those stores in 2020, that business was hit hard. Pires told SaaStake that revenue fell 95%, a figure Incognia founder André Ferraz has also publicly described.

The technology had not suddenly become less capable. What changed was the problem worth applying it to.

Security was already on In Loco’s radar. Contemporaneous reporting from March 2020 shows the company was already shifting toward authentication and security. But the collapse of the retail business accelerated that shift. Pires said the founders reassessed the technology and recognized that precise location could be a stronger fit for fraud prevention.

That pivot became Incognia. By June 2020, the company was publicly describing its new focus as using location-based behavioral signals for identity verification, authentication, and mobile fraud prevention.

The same location patterns that could show how people moved through the physical world could now help answer a different question online: does the way a device is being used fit what has previously been seen from that account?

On mobile, Incognia had relatively rich and persistent signals to help answer that. The web would take away some of that certainty.

The Web Made Recognition Less Certain

A mobile app can give Incognia relatively stable signals about a device and where it has been used. A browser gives it less to hold on to.

Pires told SaaStake that privacy controls, cookie restrictions, hidden IP addresses, and attributes that change over time make browser signals smaller and more volatile. Incognia therefore could not simply take the recognition approach it used on mobile and reproduce it on the web.

It had to change what it looked for.

Instead of relying on a few fixed identifiers, Incognia’s web approach combines hundreds of signals. These can come from the browser, user behavior, network and location, as well as signs of automation or device tampering. The system looks at how those signals fit together over time.

Incognia says its current AI-powered Browser ID analyzes more than 200 metadata signals, looking for patterns rather than requiring a browser’s individual attributes to remain unchanged.

For web sessions that remain ambiguous and appear high risk, Pires said Incognia can also connect the session with a mobile device it already recognizes as trusted.

The shift means no single browser signal has to establish recognition on its own. Incognia can instead look at whether many changing signals still form a pattern consistent with what it has seen before.

That leads to the harder question: when the pattern changes, which changes actually matter?

A New Device Is Not the Same Thing as a New Identity

The difficulty is that legitimate users do not remain static either. Their devices, locations, and behavior naturally change over time. If every departure from an old pattern were treated as evidence that an account had changed hands, recognition would create a problem of its own.

That is why the distinction between a changed signal and a changed account matters.

Incognia’s approach is to consider multiple signals before drawing a conclusion. The harder operational question is how to notice meaningful changes without treating ordinary changes in a legitimate user’s life as evidence that something is wrong.

That balance has consequences beyond whether a risky account is identified. It affects how many legitimate users are interrupted, how much work gets pushed to manual review, and how much friction a marketplace creates while trying to keep users safe.

A Low Fraud Rate Can Still Hide a Trust Problem

Catching more fraud is only one way to judge whether a marketplace’s trust systems are working.

Pires told SaaStake that teams should also watch what happens around the fraud rate. Are repeat offenders returning through multiple accounts? Are users reporting more safety incidents? Are legitimate users failing verification or being incorrectly flagged? How much activity is being sent to people for manual review?

Those outcomes can reveal problems that a fraud rate alone does not.

They can also affect the marketplace beyond its risk team. A legitimate seller who is repeatedly challenged may give up. A buyer who encounters abusive or unsafe activity may stop trusting the platform. False positives can increase manual review, while additional checks can create more friction for the people the marketplace actually wants to keep.

Quote by Edurado

That makes trust harder to reduce to a single number. A marketplace has to identify accounts that no longer appear trustworthy without making legitimate users repeatedly prove that they are.

Incognia’s path from location technology to mobile fraud prevention and then web recognition has changed how it approaches that judgment. But the underlying question has remained surprisingly simple.

Does what the marketplace sees now still give it reason to trust who is behind the account?