
Cryptomator
BoxCryptor
Mega
Nextcloud
Tresorit
Google Drive
Cloudfogger
Dropbox
LayerCall
IPQualityScore
ipinfo.io
MaxMind
ZeroBounce
Abstract APIs
Bounceless
DeBounce
LayerCall scores a whole signup in one API call.
Most fraud tools answer one question at a time: is this IP a VPN, is this email disposable, is this phone real. LayerCall returns all of them together โ IP, email, phone, domain and device โ plus the relationships between them, which is where most fake signups actually show up. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response carries a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than just made. Strictness is tunable per request without re-scoring, and when a data source is unavailable the response says so rather than quietly scoring lower.
It also authorizes AI agents. Web Bot Auth signature verification tells you which agent is calling and whether it can prove it, and a policy engine decides what it may do โ a question classical fraud signals cannot answer, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
Built for developers. REST, an MCP server for AI tooling, official Node and Python SDKs, a live demo that needs no signup, and a free tier that needs no card.
Cryptomator
LayerCallNo LayerCall videos yet. You could help us improve this page by suggesting one.
LayerCall's answer:
Most fraud APIs answer one question per call โ is this IP a VPN, is this email disposable, is this phone real. LayerCall returns IP, email, phone, domain and device together, and scores the relationships between them. A brand-new domain paired with a datacenter IP and a throwaway mailbox is obvious in combination and unremarkable one field at a time.
Every response also carries the reasoning: a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it, so a decision can be explained rather than only made.
It treats AI agents as a first-class case as well. Web Bot Auth signature verification establishes which agent is calling and whether it can prove it, and a policy engine decides what it is allowed to do โ a question classical fraud signals cannot settle, because an agent arrives with a real browser, a real fingerprint and a real mailbox.
LayerCall's answer:
Because of what comes back in the response, not what it costs.
Every result carries a 0โ100 risk score, an allow / review / block verdict, and the individual signals behind it โ so a decision can be explained to a customer, a colleague or an auditor rather than only made. Strictness is tunable per request without re-scoring, which means the same integration can be strict at signup and forgiving at login.
Two smaller things tend to matter more in production than they sound. When a data source is unavailable, the response says so instead of quietly scoring lower, so an incomplete answer stays distinguishable from a clean one. And test keys return fixed, fictional data that never bills and never touches live reputation data, so a test suite can assert on exact values without polluting anything.
Beyond that, it is worth comparing directly rather than taking our word for it: the live demo runs the real scoring engine with no signup, and the free tier needs no card.
LayerCall's answer:
Developers and small product teams who need a trust decision at signup, login or checkout, and who would rather call one endpoint than integrate several vendors and reconcile their answers by hand.
In practice that means SaaS signups, marketplaces, fintech onboarding, and anyone whose free tier is being farmed by throwaway accounts.
A newer part of the audience is teams who suddenly have to decide what an AI agent may do on their site. That is a different question from classical fraud โ an agent can be entirely legitimate and still need a policy โ which is why agent verification sits in the same API rather than in a separate product.
LayerCall's answer:
It started from a specific frustration: the signal that actually catches a fake signup is usually a relationship between fields, and the tools available answered one field at a time.
Blocking disposable email domains stops very little on its own. The signups that matter use real mailboxes, often on domains registered days earlier, arriving from addresses that look entirely ordinary. What gives them away is the domain's age set against the IP's provider set against whether the phone is a VoIP line โ and assembling that meant several vendors, several response shapes, several bills, and writing the correlation by hand anyway.
LayerCall is that correlation as a product: one call, every signal, and the reasoning returned next to the score.
The AI-agent side came later, from the same observation in a new place. An agent has a real browser, a real fingerprint and a real mailbox, so nothing in a classical fraud stack has an opinion about it. What you need to know is which agent it is and whether it can prove it โ a signature problem, not a fraud-signal problem.
LayerCall's answer:
TypeScript on Next.js, running on Vercel's Fluid Compute, with Postgres (Supabase) behind accounts, keys and usage.
The scoring path is deliberately boring. No third-party SDK sits in the request path; every external feed is fetched under its own timeout inside a request-wide deadline, so one slow source cannot hold up a response. A feed that fails degrades the result rather than failing the call, and the response names any signal that was unavailable so the caller can tell the difference between a clean answer and an incomplete one.
On the client side: official Node/TypeScript and Python SDKs, Express and Next.js middleware, a published OpenAPI spec, and an MCP server so AI tools can call the API directly.
Based on our record, Cryptomator seems to be more popular. It has been mentiond 303 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
> I dislike Dropbox for reasons that aren't technical, but the big thing for me is that I want either E2EE, or control/ownership of where my data is stored. You could run something like Cryptomator on top of Dropbox: https://cryptomator.org/ It even has (paid) iOS and Android apps for mobile access. - Source: Hacker News / 4 months ago
This is Nice. However, how do one access their diary, when you stopped maintaining it? Is this targeted more at the technically inclined, high-profile people who need to keep secrets? Personally, I believe that for something like a diary/journal, it should be in a format easily readable by most tools (so a Plain-Text or a MarkDown at best), then it is in a container/folder. Now, encrypt that container/folder... - Source: Hacker News / 6 months ago
If you still want/need cloud storage, but don't want to roll your own (with the warts that brings), Cryptomator is an excellent tool for source encrypting your data before uploading them. It works transparently, and has clients for Mac/Windows as well as iOS/Android. It's also open source, and "free" (IIRC there's a one time fee for the mobile client). https://cryptomator.org/. - Source: Hacker News / 9 months ago
- Syncthing (https://syncthing.net/) to keep the files synchronized between desktops and laptops computers - Webdav (https://github.com/hacdias/webdav) to access the files on the server via other applications - Cryptomator (https://cryptomator.org/) to crypt/decrypt sensible directories. - Source: Hacker News / 10 months ago
While I get the whole homelab thing is exiting and a great learning experience, it's simply not worth the time and effort for the majority of people. You will end up paying much more for your services, along with spending a ton of time maintaining it (and if you don't, you will probably find yourself on the end of a 0-day hack sometime). In Northern/Western Europe, where power costs around โฌ0.3/kWh on average,... - Source: Hacker News / about 1 year ago
BoxCryptor - Boxcryptor encrypts your sensitive files before uploading them to cloud storage services like Dropbox, Google Drive, Microsoft OneDrive, Box, and many others.
IPQualityScore - IPQualityScore (IPQS) proactively prevents fraud without disrupting the user experience. Access leading fraud prevention tools to detect bots, emulators, VPNs, proxies, stolen user data, and fake users.
Mega - Secure File Storage and collaboration
ipinfo.io - Simple IP address information.
Nextcloud - With Nextcloud enterprises host their own secure cloud solution for storage, collaboration & communication from any device, anywhere.
MaxMind - Determine the geographical location of website visitors based on the IP addresses for fraud detection, content localization, geo-targeting.