Skip to content
§
§ · build vs buy

Ecommerce Fraud and Chargeback Software: Keep Signifyd, or Build Your Own Risk Stack?

Annual online volume is the threshold and roughly $20M is the floor. 3 per cent, buy: Signifyd, Riskified and Forter are credible, and paying somebody to carry a risk you do not want to carry is a legitimate trade rather than a weakness.

Custom software code editor and API illustration for E-commerce Fraud Chargeback Software Build vs Buy Guide.
The short answer

Annual online volume is the threshold and roughly $20M is the floor. Below it, or with a chargeback rate comfortably under 0.3 per cent, buy: Signifyd, Riskified and Forter are credible, and paying somebody to carry a risk you do not want to carry is a legitimate trade rather than a weakness. Above roughly $100M, paying a guarantee vendor a percentage of every approved order, a build usually pays for itself inside 18 months. Between those numbers the deciding question is not fraud loss but false declines, which most merchants have never measured.

When is off the shelf genuinely the right call here?

Buy if your annual online volume is under roughly $20M, if your chargeback rate sits comfortably under 0.3 per cent, or if you genuinely value the balance sheet certainty a guarantee provides more than the margin it costs. There is nothing wrong with paying somebody to carry a risk you would rather not carry, and saying so is not a weakness in the argument for building.

Signifyd, Riskified and Forter are all credible, and they hold one advantage you can never replicate at any budget: their models see patterns across many merchants, which is a genuine strength against organised card testing that hits several retailers in the same week. Do not pretend otherwise when you build your internal case, because somebody in the room will know and the rest of your argument will lose credibility with it.

Keep a chargeback specialist such as Chargebacks911 for the long tail even if you automate everything else. Their value is process and template knowledge on unusual dispute types, unfamiliar regions and arbitration cases where your own volume is too low to build expertise economically.

Buy and stop, too, if your decline rate is healthy and your losses are stolen card fraud rather than policy abuse. That is exactly the problem transaction scoring vendors solve well, and replacing a working answer with your own version is expensive novelty.

When does a custom build actually pay off?

Two or more of these need to be true before the arithmetic works.

Your guarantee fees now exceed what a small risk engineering team costs, which is a number you can read off a statement rather than estimate. Your decline rate is unknown or unmanaged and merchandising has started asking about it. Your margin varies widely across the catalogue and one global threshold is visibly wrong, because a category with thin margin and a category with high resale value should not be judged by the same score. Your losses are increasingly policy abuse rather than stolen cards, which a transaction scoring vendor structurally cannot see because the transaction was legitimate. Or you are approaching a card network monitoring programme threshold and need to move your rate deliberately rather than by asking a vendor to tighten.

The structural reason sits underneath all five. A guarantee vendor optimises for the loss they carry, which is the correct behaviour for their business and not the same as optimising for your margin. Their incentive is to decline anything ambiguous. Yours is to approve anything whose expected margin exceeds its expected loss, and those two thresholds are different numbers on most catalogues.

The tipping point is not technical. At scale the risk threshold is a pricing decision, and pricing decisions should not sit outside your business.

How do they compare on the things that matter in this industry?

  • Cross merchant signal. Vendors win here and it is worth stating plainly. Patterns visible across many retailers catch coordinated attacks earlier than any single merchant can. Nothing you build recovers that.
  • Threshold ownership. A vendor applies one policy shaped by the risk they carry. Setting a different threshold per category, per customer tenure and per fulfilment method requires owning the decision, and it is where the margin sits on a varied catalogue.
  • Policy abuse. Serial returners, refund abuse and promotion abuse involve legitimate transactions that score clean. A transaction scoring service cannot see them by design, so those losses stay with you whatever you pay.
  • Explainability. Every decline needs a human readable reason for your support team and your analysts. A model that outputs a score and nothing else gets overridden into uselessness within a quarter, meaning you paid for a model and are running on overrides.
  • Acquirer coverage. Adyen, Stripe, Braintree, Worldpay and Chase Paymentech expose disputes differently, with different evidence field limits, submission windows and webhooks that disagree about state. Experience with one does not transfer, for a vendor or for you.
  • Data portability. Your order history, labelled with outcomes, is the asset that makes any model work. Where it lives decides how free you are later.

Read that list as a split rather than a scoreboard. Vendors are ahead on network signal and behind on threshold ownership and policy abuse, and neither position changes with a product release, because both follow from what they sell. A merchant whose losses are stolen cards and whose catalogue is uniform should stay bought. A merchant with wide margin variation and rising abuse losses is being underserved by a model that is working correctly.

What does total cost of ownership look like at your scale?

In Digital Heroes delivery experience a first release runs $65,000 to $140,000 and ships in 12 to 16 weeks. That covers a decision engine trained on your own order history, an editable rules layer your analysts can change without a deployment, a review queue with proper case handling, and automated representment packs for your top dispute reason codes on one acquirer. A full platform adding retraining pipelines with correct handling of delayed labelling, policy abuse detection, issuer specific evidence templates, additional acquirers, European traffic under its different liability picture and network monitoring alerts runs $160,000 to $400,000 over 6 to 12 months.

Volume is a poor predictor of price here. Label quality is the first driver: if historical chargeback outcomes were never written back to the orders that caused them, phase one becomes a data reconstruction job before anything can be scored. Check that before you request a quote. Acquirer count is second, region count third, and marketplace liability allocation fourth.

Ongoing cost has three parts. A retainer at fifteen to twenty per cent of build value a year covering acquirer interface changes, card network evidence rule changes and model serving. Analyst time, which good software makes far more effective and does not remove. And the line unique to this category: approving a small random sample above your threshold to correct selection bias, because orders you decline have no outcome. Some of those will be fraud, and that loss is a real recurring budgeted cost of keeping the model honest.

What does the hybrid look like, and when is it the honest answer?

The hybrid is the right first move for almost every merchant in the middle of the range, and it splits along a line most people miss.

Disputes and decisions are separate problems. Representment does not depend on the decision engine at all, so automate disputes for your top two reason codes on one acquirer while your guarantee vendor keeps deciding. That delivers recovery immediately, it is the easiest part of the programme to justify, and it changes nothing about your risk posture while you evaluate the bigger question.

The second hybrid is shadow running. Build the feature store, decision engine and rules layer, and run them against live traffic while the incumbent still decides. A month of that produces a direct comparison on your own orders, which is worth more than any vendor benchmark and costs you nothing in risk. If your engine matches the vendor, you have a decision to make on economics. If it approves good orders the vendor declined, you have found the money.

The steady state many merchants land on is also a hybrid: automate your high volume reason codes, keep a specialist for arbitration and unusual regions, and own the threshold. That is a sensible destination rather than a compromise.

Hold back ten to fifteen per cent of budget for the period after you take the decision away from the incumbent, because that transition is where the surprises live. Traffic mixes shift, promotional periods behave differently from the months you trained on, and the first organised attack after cutover is the real test rather than the shadow month.

The smallest useful version of the hybrid is representment alone, with no decision engine at all. It is the bottom of the first band, it produces recovered revenue rather than avoided loss, and it needs no change to your risk vendor relationship. If your business case has to survive a sceptical finance review, start there, because it is the only part of this programme that pays back in cash inside a quarter.

Which should you choose, by operator size and stage?

Under roughly $20M online: buy. Signifyd, Riskified or Forter, whichever quotes best, and spend the difference on acquisition. Nothing else here applies.

$20M to $100M with a healthy decline rate and stolen card losses: buy the guarantee, and automate representment yourself if disputes are consuming analyst time. That is a $65,000 to $140,000 first release scoped to one acquirer and two reason codes, and it does not disturb the risk decision.

$20M to $100M with a varied catalogue: measure before deciding. Report approval rate by category, by customer tenure and by fulfilment method alongside fraud loss for one quarter. If your highest margin categories are declined at the same rate as your most resale friendly ones, a single global threshold is leaving margin on both sides.

Above roughly $100M paying a percentage guarantee: build, and run in shadow mode for a month before switching. Project five years of guarantee fees against build, retainer, the fraud loss you will now absorb and the bias correction sample. If the fee line is larger, you have arithmetic rather than an argument.

Marketplaces and multi seller platforms of any size: model liability allocation between platform and seller before writing anything. Getting it wrong means disputes land on the wrong balance sheet, and that is a design problem rather than a cost.

Merchants whose losses are mainly policy abuse: build regardless of volume, because no transaction scoring vendor can see the problem you have.

If you want a second opinion before signing anything, Digital Heroes starts every engagement with a signed specification covering the data model, permissions and acceptance criteria, which is what keeps a fixed price fixed. Nothing about that commits you to the build.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. The 2015 CHAOS data (based on the modern definition of success) reports that only about 29% of software projects succeed, 52% are challenged, and 19% fail, with the three most important success skills being executive sponsorship, emotional maturity, and user involvement. Source: The Standish Group (reported via InfoQ Q&A with Jennifer Lynch) (2015) →
  2. Almost half of all the activities people are paid almost $16 trillion in wages to do in the global economy have the potential to be automated by adapting currently demonstrated technologies. Source: McKinsey Global Institute (2017) →
  3. In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
  4. The NRF discontinued its long-running annual shrink report, stating that a broad study of retail shrink 'is no longer sufficient for capturing the key challenges and needs of the industry' - important context that qualifies how POS/shrink benchmarks should be cited going forward. Source: Retail Dive (2024) →
FAQ

Frequently asked questions

What does it cost to leave Signifyd or Forter once we build?

The software switching cost is small. The balance sheet change is not, and it is the part to plan for. Once you stop paying a guarantee you carry the fraud loss yourself, which moves a predictable fee into a variable loss line.

Get your finance team to agree to that before the project starts rather than after the first bad month. Also keep a specialist for arbitration and unusual regions, because that expertise is not worth rebuilding at your volume.

What if our guarantee vendor changes its rate?

Guarantee pricing is a percentage of approved volume, so it grows with your success automatically and a rate change compounds on top of that. Project five years at your expected growth rate rather than judging a single quote.

Owning the decision changes the negotiation permanently. A vendor pricing conversation becomes a comparison against a number you can calculate, rather than a choice between their rate and no coverage at all.

How long does a first release take before it decides anything?

Twelve to sixteen weeks in our delivery experience, then a month of shadow running against live traffic while the incumbent still decides. That shadow month is not optional padding, it is how you validate on your own orders.

If your chargeback outcomes were never linked back to the originating orders, add a data reconstruction phase before modelling starts and price it separately. That single fact is the biggest schedule variable in the category.

Is Riskified enough if our chargeback rate is already low?

Very likely yes, and a low rate is a reason to be careful rather than confident about building. A vendor keeping your rate low is doing the job you pay them for.

The question a low rate does not answer is what it cost to achieve. A very low chargeback rate alongside an unexamined decline rate often means good customers are being refused, and that shows up as absent revenue rather than as a charge on any statement.

How do we measure false declines without building anything?

Report approval rate by category, by customer tenure and by fulfilment method alongside fraud loss for one quarter. You already have the data and it needs no new system.

If your highest margin categories are declined at the same rate as your most resale friendly ones, a single global threshold is leaving margin on both sides of the decision. A refused good customer does not complain, they buy elsewhere, so this cost is invisible until you look for it deliberately.

Why do we have to deliberately approve some risky orders?

Because orders you decline have no outcome, so your training set only ever contains orders you approved. That biases every future model towards your existing policy, and the bias compounds with each retraining cycle.

The standard correction is approving a small random sample above your threshold. Some of those will be fraud and that loss is real, recurring and worth budgeting explicitly. Nobody puts it in a proposal. Put it in yours.

Can one system handle Adyen and Stripe disputes together?

Yes, behind an adapter per provider, but treat each as its own integration rather than a variant. Evidence field limits, submission windows and dispute state models differ, and their webhooks disagree about what stage a case is in.

Start with your highest volume acquirer and your top two reason codes. That covers the majority of disputed value and proves the representment engine before you widen it, which is also how you keep the first release inside its band.

Who owns the models and the order history if an agency builds this?

You should own the repository, the feature store, the trained models and the cloud accounts, agreed in the contract before kickoff. At Digital Heroes the client owns the repository from the first commit.

Your labelled order history is the asset that makes any of this work, and it should never sit in someone else's account. A developer who resists that is building a hold over you rather than a system for you.

What is a discovery phase, and is it worth paying for separately?

Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.

Should we build an MVP first or go straight to the full system?

MVP first, for almost everyone: ship the single workflow that carries the business value in 10 to 16 weeks, learn from real users, then fund phase two from evidence instead of guesses. The caveat is that an MVP is a small version of a well-built system, not a badly built version of a big one; the data model must already support what comes next. An agency that cannot tell you what they deliberately left out of your MVP has not designed one.

Will custom software work with the tools we already use, like QuickBooks and Stripe?

Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.

What are the biggest mistakes first-time software buyers make?

Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.

We run everything on Airtable and spreadsheets. When is it time to go custom?

The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.

How do I make sure custom software is secure and compliant with rules like HIPAA?

Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.

Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?

For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.

If an agency builds my software, who actually owns the code?

You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.

What questions should I ask a development agency on the first call?

Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.

Will an app built for 10 users survive growing to 500?

Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.

Is a solo freelancer enough for my project, or do I really need an agency?

A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply