Biometric payment security

The network proved the card. It never proved the person.

Nulliti binds each payment to the real cardholder with the biometric already on their phone, producing a signed record of who approved it - the evidence you need when a chargeback lands.

A cardholder approving a payment with a biometric confirmation on their phone Proof of intent

75%

of chargebacks are friendly fraud - a real cardholder disputing a purchase they made. The network can prove the card was used. It has never been able to prove the person.

Enroll once. Prove every transaction.

  1. One biometric confirmation at checkout creates a device-bound passkey. Nothing biometric leaves the phone.

Not a wallet. Not tokenization. Not a risk engine.

Not a wallet

A wallet biometric unlocks the phone. Ours binds the card to the person.

Not tokenization

Tokenization hides the number. It doesn't prove the person.

Not a risk engine

Scoring guesses at fraud. We produce evidence of the cardholder.

See the full comparison →

Built for every side of the transaction

Visa's VAMP thresholds tightened again this year.

Nulliti reduces the fraud and dispute counts that feed the VAMP ratio, and supplies the evidence to fight the disputes that remain.

See the thresholds, fees, and dates →

Questions we get asked

Why can't a merchant prove a customer authorized a purchase?

The card network confirms that a valid card and a valid credential were used. It has never had a way to confirm that the person holding them was the cardholder. That gap is where friendly fraud lives.

What is friendly fraud, and why is it so hard to fight?

A real cardholder makes a real purchase and then disputes it. Nothing about the transaction looks wrong, so fraud screening never flags it, and the merchant's only evidence is a shipping log or a terms page. Issuers routinely side with the cardholder.

What is a passkey?

The credential behind Face ID, Touch ID, and Android biometrics. A private key held in your phone's secure hardware that signs a challenge when you confirm with a fingerprint or a glance. The biometric itself never leaves the device and is never sent anywhere.

What is 3-D Secure (3DS)?

The card networks' authentication step for online payments - the challenge screen some checkouts show before a purchase completes. When it is used, liability for that transaction shifts to the issuer. It is a check at the door, though, not a record of who walked through it, and every challenge costs you conversion.

What does card-not-present (CNP) mean?

Any transaction where the card is not physically present - ecommerce, in-app, and phone orders. There is no terminal and no chip in the loop, the merchant carries the fraud liability, and card-not-present is the largest and fastest-growing category of card fraud in the US.

What is representment?

Fighting a chargeback after it has been filed. The merchant re-presents the transaction to the issuer with evidence that the charge was valid - usually a shipping log or a terms page, which is why so many representments fail. A signed record of who authorized the payment is a different class of evidence.

Does this replace my processor or gateway?

No. Nulliti sits at the front of checkout, on top of the stack you already run. Nothing about your processor, gateway, or token provider relationship changes.

Where does the biometric go?

Nowhere. The confirmation happens on the phone and stays there. What travels is a cryptographic signature, not a fingerprint or a face.

See it on your own transactions.

Twenty minutes, your portfolio, your disputes. Tell us your role, your vertical, and rough monthly volume and we'll build the walkthrough around your numbers.

Book a demo