Install Fraud Rules Built From Your Own Distributions

Bramble PracticeRising talentNew0 orders on this service
Mobile App Marketing · Fraud filtering rules configuration

Install fraud rules derived from your own cohort distributions, with no source blocked on fewer than roughly three hundred installs of evidence.

About this service

No rule of ours blocks a source on fewer than roughly three hundred installs of evidence. Below that, the natural variance in D1 retention between two honest publishers is wider than the gap you believe you found, and you will spend the quarter blocking clean traffic and defending the decision in a review. Most blocklists we inherit were built at forty installs a source, and when we recheck them against later data, a meaningful share of what was blocked looks indistinguishable from the median honest source. What the vendor tools see, and what they miss: Protect360, Adjust's suite and Singular's equivalent handle attribution fraud well. Click flooding shows plainly in the click-to-install time distribution. Install hijacking clusters into the final seconds before install. SDK spoofing fails signature verification, once signing is switched on and actually enforced rather than merely enabled. We configure all of it and we start there, because it is cheap and it works. What none of it sees is fraud that never touches attribution: brokered low-intent users who install, open once, and behave exactly like the poor tail of your genuine traffic. That is what survives every tool sold to you, and it is usually the larger number. The behavioral layer: So we build thresholds from your own cohorts, per sub-publisher, on measures that are expensive to fake: D1 and D7 retention, sessions before first meaningful action, revenue per thousand installs, and the ratio between them. Thresholds come from your distribution, never a benchmark deck. A pet subscription converts on a slow curve and a crypto app has a legitimately long path to first deposit, so a threshold borrowed between the two produces confident nonsense. Device attestation goes on the events that matter, App Attest on iOS and Play Integrity on Android, at signup and purchase, not sprayed across every event in the app. The claim pack: Disputes are won on evidence and lost on tone. Delivery includes the format we file in: the rule that fired, the raw records behind it, the cohort comparison against your median source, and the amount, arranged so a network's compliance team can verify it without coming back to you for anything. We file the first cycle alongside you and then hand the format over. Review cadence: Rules rot. Traffic sources change hands, a bad publisher cleans up, a clean one is sold. Every rule carries a review date and a decision log entry naming who set it, on what evidence, and what would reverse it. Anything nobody can defend at review is removed, including rules we wrote ourselves. What we do not do: We do not import another client's blocklist into yours. We do not file claims we cannot evidence record by record, because a network that catches one inflated claim discounts the next ten. We do not use fraud filtering to improve the appearance of a campaign that is simply not working: if the traffic is real and bad, that is a media decision and we will say so in those words. And we do not run this as a monthly invoice where the rules never change. Who this is not for: Apps spending under roughly fifty thousand dollars a month on acquisition, or buying only through self-attributing networks, where the exposed surface does not justify the work. Teams who want a single number for how much fraud they have; we can tell you what a rule set recovered, which is a smaller and more defensible claim. And anyone expecting incentivized or rebrokered traffic to be reclassified as fraud, when it is usually permitted by the contract you signed and the fix is the contract.

Scope

Target market
Worldwide, United States
Working language
English
Industry
Crypto and Web3, Beauty and cosmetics, Mobile apps, Pets
Engagement model
Monthly retainer
Turnaround
2 weeks
Seller type
Boutique agency

What the seller needs from you

  1. 1Ninety days of raw install and click level exports from your MMP.
  2. 2Which networks are bought on fixed price rather than self-attributing?
  3. 3Cohort retention and revenue by source over the same period.
  4. 4Is SDK signing enabled and enforced?
  5. 5Who currently decides to block a source, and how is it recorded?

Asked at checkout. Delivery time starts once you answer, not when you pay.

Reviews

No reviews on this service yet.

Reviews appear only after an order completes, and both sides review each other. Nothing here is seeded or bought.

Other sellers offering fraud filtering rules configuration

See all →

Starting at $8,500