Sift Science

Sift Science

Sift is a digital trust and safety platform for fraud prevention. Scripts collect device intelligence, browser fingerprints, and behavioral telemetry to detect and prevent account fraud, payment fraud, and content abuse in real time on e-commerce and financial services websites.

Overview

Sift Science (operating as Sift) is a digital trust and safety platform founded in 2011 and headquartered in San Francisco. It provides real-time fraud detection and prevention for e-commerce, marketplaces, financial services, and consumer applications. Sift's machine learning models process hundreds of behavioural and device signals per event to assign dynamic risk scores, enabling organisations to distinguish legitimate users from fraudsters attempting account takeover (ATO), payment fraud, promo abuse, and content spam. Major clients include Twitter, Airbnb, Twilio, and McDonald's. Sift processes over 1 trillion events per year across its customer network.

What This Script Does

The Sift JavaScript snippet loads from cdn.sift.com and initialises the Sift beacon on the page. It begins collecting device intelligence and behavioural telemetry immediately on page load, with no user interaction required.

Device intelligence collected:

  • Browser fingerprint components: user agent string, screen resolution, colour depth, timezone offset, language settings, installed plugins (where accessible), canvas fingerprint hash, WebGL renderer identifier
  • Hardware signals: device memory estimate, CPU core count, touch support, battery status (where API is available)
  • Network metadata: connection type (4G, WiFi, broadband), IP address processed server-side
  • JavaScript environment: headless browser detection signals, automation framework indicators (Selenium, Puppeteer, Playwright signatures), browser consistency checks

Behavioural biometrics:

  • Keystroke timing dynamics within form fields (dwell time, flight time between keystrokes)
  • Mouse movement velocity, acceleration, and trajectory patterns
  • Scroll behaviour and page interaction cadence
  • Copy-paste detection in sensitive fields (password, credit card)
  • Form field focus and blur timing

Cookies and storage:

  • sift_session — Session-scoped token linking telemetry events to the current page interaction; transmitted to Sift's scoring API with each event; expires at session end.
  • sift_js_id — Device recognition cookie set to maintain device-level continuity for repeat fraud detection; expiry 1 year. Used to identify whether a device has been associated with fraudulent behaviour in previous sessions.
  • Local storage key _sift — Stores device-level signals for correlation with server-side risk models; cleared per session or on explicit cache clearing.

Script filenames and CDN: sift.js or beacon.js loaded from cdn.sift.com. Events POST to api3.siftscience.com/v205/events with the host organisation's JavaScript snippet key. Risk score responses are returned synchronously for real-time decisioning.

Risk score model inputs: In addition to device and behavioural signals, Sift aggregates cross-network signals from its entire client base — meaning a device or IP that has committed fraud on one Sift customer's platform contributes to risk scoring on other platforms. This consortium-level intelligence is a core feature of Sift's fraud detection accuracy.

Consent & Compliance

Sift is classified under the essential category. Its function is security-critical fraud detection protecting the platform and its legitimate users from account takeover, payment fraud, and automated abuse. Under GDPR Recital 47, fraud prevention constitutes a legitimate interest of the data controller, and GDPR Article 6(1)(f) provides the lawful basis for this processing. The ePrivacy Directive's strictly necessary exemption applies to security measures that protect the integrity of a service explicitly requested by the user. While Sift collects device fingerprints and behavioural data, this processing is bounded to fraud risk scoring and is not used for advertising profiling or cross-site behavioural marketing. Sift participates in the EU-US Data Privacy Framework for compliant transatlantic data transfers and maintains SCCs for EU deployments.

Should You Block This Without Consent?

No. Sift is a security tool that protects against payment fraud, account takeover, and automated abuse. Blocking it degrades fraud protection. It should load as an essential script without requiring user consent.

Is Sift Science GDPR compliant?

Sift Science's trackers are classified as essential (strictly necessary), so they are generally exempt from prior consent under the GDPR. You should still list them in your cookie policy and privacy notice so visitors know they are there.

Visit website

Consent Categories

Also Known As

SiftSift Sciencefraud detection privacydevice fingerprinting consentaccount takeover preventionpayment fraud script

Industries

Computer SecurityComputers Electronics and Technology

Tracked Domains (2)

Sift Science's trackers are rarely seen, seen on a small share of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

sift.comEssential

sift.com is an essential domain operated by Sift Science, used to keep the site working, including security, load balancing, and sessions. Seen on a small share of scanned sites.

siftscience.comEssential

siftscience.com is an essential domain operated by Sift Science, used to keep the site working, including security, load balancing, and sessions. Seen on a small share of scanned sites.

Cookies Sift Science Sets (1)

_sift

Sift fraud-detection device-fingerprint token.

Frequently Asked Questions

Related Vendors

DataDome
DataDome
Bot detection and protection platform that operates as a client-side signal collector. The DataDome script runs behavioral checks in the browser — mouse movement patterns, keystroke timing, JS environment fingerprinting — and submits signals to DataDome's servers to classify traffic as human or automated in real time.
sourcedefense
sourcedefense
Consent management and source defense platform that monitors and controls third-party scripts running on websites. SourceDefense scripts detect unauthorized pixel injections and data leakage from compromised or rogue third-party tags in the browser.
CacheNetworks
CacheNetworks
CacheNetworks provides CDN and distributed caching infrastructure. Asset delivery from CacheNetworks hostnames indicates content distribution at the network level without client-side tracking or advertising functionality.
IAB Europe
IAB Europe
IAB Europe is the trade association for digital advertising in Europe. The IAB Transparency & Consent Framework (TCF) script manages vendor consent records for GDPR compliance across participating advertising technology companies.
RawGit
RawGit
RawGit was a CDN that served raw files directly from GitHub repositories with proper content-type headers. Now defunct and replaced by jsDelivr; references to RawGit may appear in legacy codebases. No active tracking, advertising, or data collection functionality remains.
F5 Networks
F5 Networks
Web security and DDoS protection solution for e-commerce and enterprise sites. F5 Networks scripts may appear as part of bot management and web application firewall (WAF) deployments, performing browser integrity checks to identify automated traffic.

Manage consent for Sift Science

ConsentStack automatically detects and manages Sift Science trackers so your site stays compliant with global privacy regulations.