Account takeover prevention.

Rupt learns the devices and networks each account signs in from, lets trusted logins through, and challenges the ones it does not recognize.

CrexiHouzz ProManatalVyondAgorapulseSmartScoutBreaking Into Wall Streetiwd.ioSketchyTettraDesignfilesPrep101Cheddar UpNorth DataStealthWriterPharmAchieve
CrexiHouzz ProManatalVyondAgorapulseSmartScoutBreaking Into Wall Streetiwd.ioSketchyTettraDesignfilesPrep101Cheddar UpNorth DataStealthWriterPharmAchieve

The engine

End-to-end account takeover protection.

Rupt learns the devices, behavior, and networks that normally use an account, then flags suspicious login attempts. You set the policies that challenge them, block them, or let them through.

1Familiar

Rupt knows what a real login looks like on this account.

Every account builds up a set of devices, browsers and networks it actually signs in from. A trusted login from these sources passes unhindered. A login from an unknown source is flagged for challenge or review.

Logins /user_8fa2
Live

Trusted for this account

MacBook Pro, ChromeSeattle · 41 logins
iPhone 15, SafariSeattle · 12 logins
24.18.44.x, ComcastSeattle · Home network
172.58.x.x, T-MobileSeattle · Mobile network

Just now

Windows, Chrome 141Frankfurt · VPN

New device, new network, impossible travel

Then Challenge

Challenge, run by Rupt

Owner asked to verifyEmail and SMS
Ownership provenNever completed
Automation on the formPlaywright
Attempts from this device47 in 6 min
Accounts it tried12
Real ownerNever interrupted
Then Denied

Your policy

Whenlogin

impossible_travel is true

oris_new_fingerprint and is_new_ip

orip_is_vpn is true

Thenchallenge via email, sms

Signals it can draw on

Device intelligenceIP intelligenceBehaviorEmailAccount history
trusted devices
2 trusted devices
trusted networks
2 trusted networks
login flagged
1 login flagged

2Challenged

We run the challenge, you do not need to build one.

The flagged session gets a hosted challenge: prove ownership of the email or phone on the account. Rupt also reads the attempt itself, so a script working through a leaked credential list is denied before any code is sent.

Logins /Challenge
Live

Trusted for this account

MacBook Pro, ChromeSeattle · 41 logins
iPhone 15, SafariSeattle · 12 logins
24.18.44.x, ComcastSeattle · Home network
172.58.x.x, T-MobileSeattle · Mobile network

Just now

Windows, Chrome 141Frankfurt · VPN

New device, new network, impossible travel

Then Challenge

Challenge, run by Rupt

Owner asked to verifyEmail and SMS
Ownership provenNever completed
Automation on the formPlaywright
Attempts from this device47 in 6 min
Accounts it tried12
Real ownerNever interrupted
Then Denied

Your policy

Whenlogin

impossible_travel is true

oris_new_fingerprint and is_new_ip

orip_is_vpn is true

Thenchallenge via email, sms

Signals it can draw on

Device intelligenceIP intelligenceBehaviorEmailAccount history
channels offered
2 channels offered
attempts denied
47 attempts denied
code entered
0 code entered

3Yours

Every signal, under one policy you control.

IP intelligence, device intelligence, behavior, email reputation and the account's own history all feed one decision. Tighten the policy during an attack, loosen it afterwards, and change it again whenever you need to. No release required.

Logins /Policies
Live

Trusted for this account

MacBook Pro, ChromeSeattle · 41 logins
iPhone 15, SafariSeattle · 12 logins
24.18.44.x, ComcastSeattle · Home network
172.58.x.x, T-MobileSeattle · Mobile network

Just now

Windows, Chrome 141Frankfurt · VPN

New device, new network, impossible travel

Then Challenge

Challenge, run by Rupt

Owner asked to verifyEmail and SMS
Ownership provenNever completed
Automation on the formPlaywright
Attempts from this device47 in 6 min
Accounts it tried12
Real ownerNever interrupted
Then Denied

Your policy

Whenlogin

impossible_travel is true

oris_new_fingerprint and is_new_ip

orip_is_vpn is true

Thenchallenge via email, sms

Signals it can draw on

Device intelligenceIP intelligenceBehaviorEmailAccount history
signals available
40+ signals available
policy to edit
1 policy to edit
deploys from you
0 deploys from you

Your real users

Hard to break into, easy to log into.

Teams put off account takeover protection because they expect it to punish every customer to catch a handful of attackers. Here is what actually reaches them.

  • Familiar logins are not interrupted

    Many products challenge every login, every time. Rupt only stops a session it cannot match to the account's own history, which on most products is a small share of logins.

  • Verify once, then that device is trusted

    When the owner clears a challenge, the device and network they used become trusted. The same laptop tomorrow passes through. A new one next month does not.

  • You choose the channels and the bar

    One-time code by email, by SMS, or a live selfie through a KYC challenge. Pick which channels you offer, what order they come in, and whether one is enough or all are required. Then set how unknown a login has to be before any of it triggers.

https://trust.yourdomain.com/verify
Verify your account to continue

We've sent a code to a•••••@yourdomain.com. Please enter the code below.

-

Questions teams ask before turning on account takeover prevention:

Find out who is really signing into your users' accounts.

Rupt scores every login from the first one. Within a week of shipping, most teams can see which sign-ins come from sources their accounts have never used, before they challenge or block anything.