Fingerprinting & Risk Signals SDK

Own your
device intelligence.
Don't rent it.

Fraud vendors rent you a score — built on your own customers' data, computed in their cloud, inside a binary you can't read. Burein is an on-device, zero-egress SDK for Web, iOS, and Android that hands you the 1,000+ raw device, behavioural and integrity signals with a signed report — so you own the data, train your own models, and read every line that runs in your app.

1,000+signals
0network calls
3platforms
<250mscold report
BureinReport
{
  "visitor_id": "v1_b3c1...e7",
  "confidence": 0.97,
  "signals": { ...1042 collected },
  "threats": [
    { "id": "FRIDA_HOOK_DETECTED",
      "severity": "critical",
      "confidence": 0.98 },
    { "id": "AGENTIC_COMPUTER_USE",
      "severity": "critical",
      "confidence": 0.92 }
  ],
  "risk": {
    "score": 87,
    "band": "high",
    "decision_hint": "block"
  },
  "signature": "Ed25519:..."
}
Designed for
BankingPaymentsCryptoMarketplaces iGamingIdentity / KYCHealthcareGovernment
Platform

Identity, integrity, and intent — computed where the user is.

Burein is a pure on-device library — no backend, no telemetry, no remote config channel. Your app embeds the SDK, your team gets the signal layer every fraud solution is built on, and the signed report feeds the risk pipeline you already run. Start with friction-minimised 2FA and silent continuous auth; layer the rest on your timeline.

Identity at the device

A stable visitor_id derived from 1,000+ high-entropy signals — without shipping any of them to a third party. Deterministic across sessions, resilient to reinstalls.

Web SDK →

Threats in real time

Frida, Xposed, Magisk, repackaging, emulators, screen-share scams, accessibility abuse, headless browsers, anti-detect tools, and AI agents — detected on device, with evidence.

Mobile SDK →

Privacy by architecture

Burein never sees your users' data — by construction, not promise. The signed report is returned to your code via a public SDK method; you attach it to your own APIs, over your own transport. No DPA gymnastics. GDPR / DPDP / HIPAA / PCI postures inherit from your app, not from us.

Architecture →
Own vs. rent

Stop renting a verdict built on your own customers' data.

Every fraud vendor runs the same play: collect your customers' device data, train their model on it, and rent the model back to you — while the same model serves your competitors. In the AI age, the data is the asset. Burein hands you the raw signal on-device and gets out of the way, so the intelligence you build is yours to keep.

Your data should train your models — not your vendor's.

Incumbents abstract 1,000+ raw signals down to a score you can't rebuild a model from. Burein returns the full raw feature vector on-device, with zero egress to us — so you train on data we structurally never see, and it compounds into an edge no vendor can resell.

Buy the primitive, not the platform.

Device signals are a commodity, so incumbents can't charge for them alone — they wrap them in a score, a dashboard, and a subscription you didn't ask for. Burein sells the un-bundled signal layer, and nothing you don't need.

Read every line that runs in your app.

Source-code escrow and source-audit rights are a standard commitment, not a contract you have to fight for. Your security team reads exactly what executes on your customers' devices — no opaque binary, no blind trust.

Verify the binary — don't take our word for it.

Public CI test results, SBOM, SLSA provenance, reproducible builds, and a dedicated build delivered to each bank. You can prove the binary you ship matches the source you audited.

Flagship

The first SDK that detects AI agents, not just bots.

Anthropic Computer Use. OpenAI Operator. browser-use, Cline, Skyvern, Manus, BrowserBase. These agents drive real Chrome, on residential proxies, with real cookies — and they're invisible to legacy bot detection. Burein sees them.

Vision-loop cadence

Detects the screenshot → small move → screenshot pattern characteristic of LLM-driven UI control.

Token-boundary typing

Synthetic typing with no typos, no backspaces, cadence that matches LLM token emission.

Kinematic implausibility

Mouse trajectories no human hand produces — straight lines, instant teleports, zero jitter.

Stack fingerprints

Playwright, Puppeteer-extra-stealth, CDP, browser-use, Computer Use, Operator, BrowserBase tells.

Why Burein

One SDK that does what three vendors do — and one thing none of them do.

CapabilityFingerprint.comZimperium zDefendPromon / GuardsquareBurein
Web fingerprinting
Mobile runtime integrity (RASP)
On-device only · zero egresspartialpartial✓ by design
Agentic / AI-actor detectionearly✓ first-class
Unified signal schema across Web + iOS + Android
1,000+ raw signals exposed to you
Raw data you can train your own models on
Source escrow + readable source + reproducible builds
Customer-owned data, no DPA gymnasticspartial
Built for

The teams that can't afford a third party in the loop.

Ready to own your device intelligence?

Stop renting a score built on your own data. Embed Burein, keep the raw signal on your side, and build a fraud edge that's yours to keep.