Category

Behavioral Biometrics SDK — Cross-Platform
Session Risk Scoring.

A behavioral biometrics SDK measures how a person uses an app — the timing, cadence, and physical signature of their session — and turns that into a real-time risk score. ValorQ ships that SDK for Android, iOS, Web, and React Native, with one scoring model, on-device processing, and three deployment models designed for regulated teams.

What a behavioral biometrics SDK actually does

Behavioral biometrics is a category of authentication and fraud signals derived from the way a legitimate user interacts with an app, rather than from what they know (a password) or what they are (a fingerprint). A behavioral biometrics SDK is the library that lives inside your mobile or web application and produces those signals in real time.

The problem it solves is straightforward. A password can be phished, a session cookie can be stolen, and a device fingerprint can be re-used. But an attacker sitting in someone else's session moves differently: they type faster, paste credentials instead of typing them, complete flows at machine speed, and skip the small hesitations a legitimate user shows. A behavioral biometrics SDK captures those differences and hands your app a verdict it can act on before the transaction reaches your backend.

The right way to think about it: behavioral biometrics is an additional signal layer. It does not replace your existing device fingerprinting, WAF, or transaction-monitoring stack. It adds a behavior-of-user dimension none of those tools can produce on their own.

What ValorQ's SDK measures

ValorQ's SDK captures nine dimensions of behavioral signal grouped into four families. Each is compared, per session, against the user's own history — not a population average.

Timing signals

Interaction signals

Motion signals

Behavioral drift

The verdict lands in one of three tiers: CLEAR (0–34) means no action; REVIEW (35–69) triggers step-up authentication; BLOCK (70–100) stops the flow immediately. Every score is traceable back to the signals that produced it — no black box, no unfalsifiable ML judgment.

Platforms supported

ValorQ ships four native packages. They share one scoring model and one risk verdict, so signal from one platform is comparable to signal from another. Baselines are platform-specific by design — a user's tap rhythm on iPhone differs from their tap rhythm on a laptop — and ValorQ handles that separation for you.

On-device vs cloud — why architecture matters

The single most important architectural decision in a behavioral biometrics SDK is where the scoring happens. ValorQ scores on-device by default. This is not a minor detail; it changes what data leaves the customer's environment and how much of your app falls under regulated data-processing scope.

A cloud-scored architecture streams every touch, keystroke, and motion sample to a vendor backend for analysis. That means (a) every session incurs network latency before a verdict lands, (b) the vendor becomes a data processor for behavioral data that likely qualifies as personal under GDPR/DPDP, and (c) an outage on the vendor side means your app either fails open or fails closed — neither is a good option.

An on-device architecture scores locally. The risk callback fires immediately — before any backend transaction is authorized. In ValorQ's SDK-only deployment, no behavioral data ever leaves the device, so the vendor never becomes a processor for regulated data. When a session risk needs to be queried server-side (say, to gate a transfer above a threshold), a small verdict object can be sent — not the raw behavioral stream that produced it.

The trade-off is that on-device scoring is constrained to what you can compute on the client. ValorQ's scoring engine is built on robust statistical methods (MAD-based z-scores against per-user baselines) precisely because those methods are fast, statistically robust, and effective without needing gigabytes of population data.

Three deployment models

Behavioral biometrics is not a monolithic capability. Different teams need different depths of integration, and forcing a heavyweight backend on a team that just wants to see signals in a test environment is a good way to kill the pilot. ValorQ ships three tiers you can grow through.

Model 1 — SDK Only

All scoring happens on-device. Zero network calls from the SDK. Risk callbacks fire locally. Baselines persist in encrypted local storage. There is no vendor backend in the loop, so ValorQ never enters your data-processing boundary. This is the fastest way to evaluate — a mobile team can integrate and start seeing signals in a test build in a few days.

Model 2 — SDK + Backend

Adds a lightweight backend that receives events, re-scores against full user history, and hydrates baselines across device upgrades. Your app queries session risk from your own backend via API before authorizing high-value actions. This is the model most production deployments settle on: enough infrastructure to persist baselines across a device swap, but no more.

Model 3 — Full Platform

Adds the observability layer for enterprise security teams: a live operations dashboard, fleet analytics, webhook alerts on tier changes, audit log and compliance export. Aimed at teams that need SOC/fraud-ops workflow around the raw signal, not just the signal itself.

Developer experience

Integration should be quiet. The SDK sits in the background, watches the user's natural interaction with your existing screens, and surfaces a single risk state you subscribe to.

Two things happen when you integrate:

  1. You wrap a flow. A flow is a bounded sequence of screens the user moves through — login, add-a-payee, transfer, checkout. You tell the SDK when a flow starts and ends so it can score relative to that flow's baseline.
  2. You register a risk callback. Whenever the composite risk crosses a tier boundary, ValorQ fires onRiskChange with the new score, tier, and the signals that produced it. Your app decides what to do — allow, step-up, block.

A short example (Web / TypeScript)

import { ValorQ } from "@valorq/web";

const valorq = ValorQ.init({
  tenantId: process.env.NEXT_PUBLIC_VALORQ_TENANT,
  mode: "sdk-only", // or "with-backend"
});

valorq.onRiskChange(({ score, tier, signals }) => {
  if (tier === "BLOCK") {
    stopFlow();
    reportToBackend({ score, signals });
  } else if (tier === "REVIEW") {
    requireStepUp();
  }
});

// Wrap a sensitive flow
valorq.startFlow("wire-transfer");
// … user completes flow …
valorq.endFlow("wire-transfer");

A short example (iOS / Swift)

import ValorQ

let valorq = try ValorQ.shared.configure(
    tenantId: Bundle.main.valorqTenant,
    mode: .sdkOnly
)

valorq.onRiskChange { verdict in
    switch verdict.tier {
    case .block:  flowCoordinator.abort(reason: .highRisk)
    case .review: flowCoordinator.requireStepUp()
    case .clear:  break
    }
}

// SwiftUI integration
TransferScreen()
    .valorqFlow("wire-transfer")

The integration surface is intentionally small — configure once, subscribe once, wrap flows. Most teams land on this shape within a sprint.

How ValorQ compares to alternatives

Behavioral biometrics is a real category and the vendors in it are not interchangeable. A fair reading:

The right question is not “which vendor is best” but “which architecture matches our compliance posture and where do we need signal we don't have today.” ValorQ is architected for teams that need on-device processing, cross-platform consistency, and a statistically robust scoring model. If those constraints match yours, we're a good conversation.

Quick comparison

A rough shape-of-fit table. Every deployment is different; treat this as a starting point for a real conversation, not a scorecard.

DimensionValorQCloud-scored vendorsDevice fingerprinting
Where scoring happensOn-device by defaultVendor backendClient + vendor lookup
Data egress requiredZero in Model 1Full behavioral streamDevice identifiers
Verdict latencyImmediate (local)Network round-tripNetwork round-trip
Cross-platform baselineUnified model, per-platform baselinesVaries by vendorDevice-level, not user-level
Scoring modelStatistically robust (MAD z-score), auditableOften ML, less transparentRule + reputation
Best fit forRegulated mobile-first teamsEstablished desktop-heavy banksComplementary layer

The most useful way to read this: behavioral biometrics is not a binary buy-or-don't decision. Most mature fraud stacks end up layering behavioral signal on top of device fingerprinting and transaction monitoring, because each catches a different attack pattern. ValorQ is designed to be that behavioral layer without forcing the rest of your stack to change.

Getting started

See ValorQ running on your stack.

Start with Model 1 — no backend required. We'll walk through signals, scoring tiers, and integration paths for your specific platform mix.

Request SDK access