Modern cybersecurity in the “post-perimeter” era has become increasingly asymmetrical: online services face an expanding attack surface as audiences broaden beyond trusted partners, while attackers can succeed by exploiting a single unpatched weakness. This problem is especially acute for B2C services, where transactions originate from unmanaged, potentially compromised customer devices. Unlike enterprise environments, these services cannot feasibly mandate centrally managed endpoints, EDR tooling, or strict posture controls without prohibitive cost, operational burden, regulatory complications, and major customer attrition. Traditional server-side protections such as rules-based Web Application Firewalls are described as insufficiently flexible, hard to maintain, and blind to endpoint-side activity, limiting detection of credential hijacking, transaction tampering, and other client-side threats; banking has partially addressed this gap through fraud technologies driven by regulation, and other industries are pressured to follow.
Cleafy, founded in 2014 by engineers from Politecnico di Milano and part of the Moviri Group since 2017, positions itself as a unified threat detection and protection platform for financial and e-commerce institutions. It combines endpoint-style signals with online fraud detection, but avoids signature- or behavior-based anti-malware approaches in favor of patented, clientless, application-independent, passive transaction monitoring and risk assessment. Deployed out-of-band and integrated with common delivery infrastructure (e.g., Citrix, F5, Microsoft, NGINX, Kong), it transparently injects a small JavaScript block into pages to create an obfuscated polymorphic sandbox that dynamically encrypts content, detects page manipulation attempts, and sends evidence asynchronously for analysis. Multiple engines correlate indicators (including ML-based behavior analytics and threat intelligence) across sessions, maintain device profiles, generate detailed risk-scored tags for downstream fraud/auth systems, and integrate via APIs/webhooks into SIEM and incident workflows. The portfolio includes DETECT, PROTECT, MOBILE, ASK, and SaaS, with plans to repackage offerings by industry segment.
See All Locations
See All Locations