Home  >  Companies  >  Fingerprint
Fingerprint
AI-powered device intelligence and fraud prevention platform that identifies web and mobile visitors and delivers real-time device and risk signals to stop fraud

Revenue

$50.00M

2026

Details
Headquarters
Chicago, United States
CEO
Dan Pinto
Website
Milestones
FOUNDING YEAR
2020

Revenue

Sacra estimates that Fingerprint hit $50M in annual recurring revenue (ARR) in August 2026.

Fingerprint generates revenue through usage-based subscriptions tied to successful identification API requests. Its free tier includes up to 1,000 web/iOS calls per month, while the Pro Plus plan starts at $99 per month for 20,000 calls, with overage priced at $4 per additional 1,000 calls. Enterprise contracts offer custom volume pricing, higher rate limits, extended data retention, and a 99.9% SLA. Custom pricing applies to customers requiring at least nine million annual API requests.

Revenue grows with customer traffic and product adoption. As customers deploy Fingerprint across more checkpoints, including login, signup, checkout, and refund, call volume increases without requiring a new contract. Growth in a customer's user base also increases billed identification events.

Fingerprint serves more than 6,000 companies, identifies over 7 billion unique browsers and mobile devices annually, and processes more than 80 million real-time device-intelligence API events per day. The company says it helped prevent more than $1 billion in fraud losses in the twelve months preceding September 2026.

Valuation & Funding

Fingerprint raised a $33 million Series C in October 2023 led by Nexus Venture Partners, with participation from Uncorrelated Ventures, Craft Ventures, Hack VC, Remarkable Ventures, and Entrepreneurs Roundtable Accelerator.

Before the Series C, Fingerprint raised a $32 million Series B announced in late 2021, following earlier seed and Series A rounds. The company originated as the FingerprintJS open-source project in 2012 and launched its commercial SaaS product in 2019.

Fingerprint has raised $77 million in total disclosed funding across four rounds.

Product

Fingerprint's device-intelligence API tells a website or mobile app whether it has seen a browser or device before, even when cookies have been cleared, a VPN is active, or the visitor is using incognito mode. Rather than identifying people by name or scanning biometric fingerprints, it analyzes more than 100 technical characteristics of a browser, device, and network to generate a persistent identifier called a Visitor ID.

Developers integrate Fingerprint through a lightweight JavaScript agent for websites or a native SDK for iOS, Android, React Native, or Flutter apps. At risk-sensitive moments such as account creation, login, password reset, or checkout, the agent sends collected signals to Fingerprint's cloud platform, which returns a Visitor ID, confidence score, first-seen and last-seen timestamps, and contextual fraud indicators called Smart Signals.

Smart Signals include VPN and proxy detection, browser tampering, anti-detect browsers, bot activity, incognito mode, virtual machines, Android emulators, rooted or jailbroken devices, cloned apps, location spoofing, and velocity patterns across devices and geographies. A composite Suspect Score combines these signals into a weighted risk value. Customers can adjust signal weights, disable irrelevant signals, or upload labeled fraud data to receive machine-learning-generated weight recommendations based on their fraud patterns.

Fingerprint sends device identity and risk context to the customer's backend rather than making approve-or-deny decisions. Customers combine this output with account, transaction, and behavioral data to allow, challenge, or block an action. The API can operate alongside existing fraud engines, authentication providers, payment processors, and KYC systems without replacing them.

In 2026, Fingerprint added AI-agent detection to distinguish verified agents from spoofed or malicious automation, an MCP server that lets AI assistants query device events through natural language, and expanded anti-detect-browser and mobile integrity signals. These additions extend the product beyond device identification into visitor-intent analysis for human fraud and the distinction between legitimate AI agents and adversarial bots.

Business Model

Fingerprint sells B2B through a hybrid product-led growth and enterprise sales motion. Developers discover the product through the open-source FingerprintJS library, which has more than 28,000 GitHub stars and roughly 6.3 million monthly downloads, as well as through documentation, a free plan, and a 14-day Pro Plus trial. Smaller customers self-serve on the standardized Pro Plus plan, while larger accounts negotiate enterprise contracts with custom throughput, proxy infrastructure, compliance features, and dedicated support.

The billable unit is a successfully processed client identification event. Server API retrieval, webhooks, and SDK calls do not incur additional charges, so customers pay for each instance in which Fingerprint observes a visitor rather than for downstream use of the result. Revenue scales with customer activity as customers add checkpoints, properties, platforms, and product depth.

Fingerprint's cost base includes cloud compute and storage for real-time identification, machine-learning training and inference, browser and mobile research to track OS and browser changes, security and compliance, and enterprise sales and customer success. The model should carry conventional software gross margins at scale, although each identification consumes cloud resources, and maintaining accuracy against adversarial evasion requires ongoing R&D investment.

Integration creates switching costs. Over time, the Visitor ID becomes embedded in customers' account histories, blocklists, trusted-device lists, analyst workflows, and fraud rules. Replacement requires code changes, historical-data migration, rule retuning, and accuracy revalidation, which makes deployed integrations operationally durable.

Competition

Full-stack fraud platforms

Sift processes over one trillion annual events across more than 700 brands, packaging device fingerprinting with payment protection, account defense, a decisioning engine, analyst workflows, and cross-customer network intelligence. SEON combines device intelligence with email, phone, IP, digital-footprint enrichment, AML screening, and configurable rules in a single API call.

Both can sell standalone device identification as insufficient and price their bundles against the total cost of Fingerprint plus multiple enrichment and decisioning vendors. Fingerprint competes through faster deployment, vendor neutrality, and compatibility with customers' existing risk stacks.

Incumbent identity networks

LexisNexis ThreatMetrix combines device, behavioral, and identity signals through its cross-industry Digital Identity Network, with BehavioSec adding continuous behavioral analytics. TransUnion's TruValidate bundles the former iovation device network with credit, phone, email, and fraud-consortium data, reporting over 111 billion device-reputation checks and more than 185 million confirmed fraud-evidence reports.

These incumbents have procurement credibility with banks, insurers, and government agencies, while their consortium data provides cross-client fraud histories that Fingerprint's customer-specific Visitor IDs cannot replicate. Fingerprint competes on developer experience, deployment speed, and modularity for customers that do not want a large identity-data contract.

Device-intelligence specialists and adjacent entrants

Castle is the closest developer-oriented challenger, packaging device fingerprinting with IP and email intelligence, behavioral analytics, AI scoring, rules, lists, and up to 18 months of historical analysis in a single API. SHIELD targets high-velocity mobile ecosystems with persistent IDs, behavioral biometrics, association graphs, and continuous session monitoring, claiming more than 7 billion devices profiled.

Competition increased in 2026. BioCatch launched DeviceIQ in March 2026, bringing device identification into its behavioral-biometrics platform for digital banking. Arkose Labs released an enhanced Arkose Device ID the same month, integrating deterministic and AI-powered identification into its Titan platform alongside bot management, phishing protection, and challenge-based enforcement. Cloudflare introduced Ephemeral IDs for persistent client identification, Precursor for continuous behavioral validation, and Adaptive Intelligence for attack-level historical context, bundled with its CDN, WAF, and bot management at the edge.

Authentication and payments bundling

Authentication providers such as Stytch, WorkOS Radar, Auth0, Clerk, and Descope operate at high-value checkpoints and can bundle device fingerprinting into login and signup flows without a separate integration. In payments, Forter, Riskified, Signifyd, and processors such as Stripe and Adyen embed device signals within payment guarantees and chargeback protection.

These vendors can absorb device intelligence into existing contracts, making a standalone Fingerprint line item harder to justify unless it serves use cases beyond payment fraud, including account sharing, trial abuse, paywall enforcement, and personalization.

TAM Expansion

AI-agent identity and the agentic web

Fingerprint now detects and classifies AI agents, distinguishing cryptographically verified agents from spoofed or malicious automation through Web Bot Auth. Its directory covers agents from providers including OpenAI, AWS, Browserbase, and Manus. The next step is an agent access gateway that allows websites to meter, block, or selectively authorize agents by provider, identity, and activity.

The opportunity spans self-serve AI products such as Cursor and Perplexity, which face free-tier and inference abuse that API rate limits alone cannot address, as well as publishers and marketplaces seeking to distinguish legitimate agent commerce from scraping and inventory hoarding.

Product-led abuse and non-fraud use cases

Fingerprint's device ID applies beyond payment fraud. Trial farming, referral manipulation, coupon abuse, ban evasion, SMS pumping, paywall circumvention, account sharing, and regional-pricing arbitrage all involve one operator appearing as multiple users. These use cases open budgets in product, growth, and marketing teams, rather than limiting demand to fraud departments.

Relevant customer segments include subscription media, SaaS, online education, and generative-AI vendors, which face automated account creation, shared paid accounts, and free-credit farming. Device-level recognition can address these issues below the account or API-key layer.

Financial services and geographic expansion

U.S. consumers reported approximately $16 billion in fraud losses during 2025, up roughly 25% from 2024. Rising losses may increase demand among banks, fintechs, and lenders for pre-transaction device intelligence across loan origination, account opening, money movement, and continuous session risk. Fingerprint's existing signals for emulators, rooted devices, app cloning, remote-access tools, and location spoofing apply directly to mobile-first financial services.

Geographically, Fingerprint already processes traffic from more than 250 countries and supports U.S., European, and Asia-Pacific workspace regions. In Asia-Pacific, Fingerprint's 2026 data found proxy traffic in 29.3% of events in Asia, while its Android Device Reputation Network provides an initial dataset for mobile-first economies. Europe offers financial-services, gaming, and travel opportunities but requires a privacy-conscious go-to-market approach because European and UK regulators treat device fingerprinting as a regulated storage-and-access technology, even when used for fraud prevention.

Risks

Privacy and regulatory exposure: European and UK regulators treat device fingerprinting as subject to ePrivacy rules, including for fraud-prevention purposes, and stricter interpretations or customer compliance concerns could slow adoption, limit the expansion of Fingerprint's Device Reputation Network, and create procurement friction in regulated industries.

DISCLAIMERS

This report is for information purposes only and is not to be used or considered as an offer or the solicitation of an offer to sell or to buy or subscribe for securities or other financial instruments. Nothing in this report constitutes investment, legal, accounting or tax advice or a representation that any investment or strategy is suitable or appropriate to your individual circumstances or otherwise constitutes a personal trade recommendation to you.

This research report has been prepared solely by Sacra and should not be considered a product of any person or entity that makes such report available, if any.

Information and opinions presented in the sections of the report were obtained or derived from sources Sacra believes are reliable, but Sacra makes no representation as to their accuracy or completeness. Past performance should not be taken as an indication or guarantee of future performance, and no representation or warranty, express or implied, is made regarding future performance. Information, opinions and estimates contained in this report reflect a determination at its original date of publication by Sacra and are subject to change without notice.

Sacra accepts no liability for loss arising from the use of the material presented in this report, except that this exclusion of liability does not apply to the extent that liability arises under specific statutes or regulations applicable to Sacra. Sacra may have issued, and may in the future issue, other reports that are inconsistent with, and reach different conclusions from, the information presented in this report. Those reports reflect different assumptions, views and analytical methods of the analysts who prepared them and Sacra is under no obligation to ensure that such other reports are brought to the attention of any recipient of this report.

All rights reserved. All material presented in this report, unless specifically indicated otherwise is under copyright to Sacra. Sacra reserves any and all intellectual property rights in the report. All trademarks, service marks and logos used in this report are trademarks or service marks or registered trademarks or service marks of Sacra. Any modification, copying, displaying, distributing, transmitting, publishing, licensing, creating derivative works from, or selling any report is strictly prohibited. None of the material, nor its content, nor any copy of it, may be altered in any way, transmitted to, copied or distributed to any other party, without the prior express written permission of Sacra. Any unauthorized duplication, redistribution or disclosure of this report will result in prosecution.