Fraud prevention policy
Last updated
Every conversion on this platform is money moving from an advertiser to a publisher. This page describes how we decide that the action behind it really happened, what we do when it did not, and how to argue with us when we get it wrong.
1. Why this exists
A CPA network with no fraud control does not fail gradually. Advertisers stop buying because they are paying for nothing, honest publishers leave because the network cannot pay, and what remains is the fraud. The controls below are not an add-on to the product; the hold period, the click identifier and the ledger were designed around them.
The other half is just as important. Over-rejection is also a failure. A publisher whose honest traffic is refused has been robbed just as effectively as an advertiser who paid for a bot, so every control here is written to be arguable.
2. What we require of a conversion
Nothing is paid on assertion. A conversion has to be tied to a click we minted, and the tie is the click identifier: an unguessable value we generate when a user is sent to an advertiser, and which the advertiser hands back when the action completes. No click id, no conversion — an advertiser cannot invent one, and neither can a publisher.
On top of that:
- The click must still be live. Each offer sets a conversion window, and a postback arriving after it closes is refused.
- Inbound postbacks are authenticated. An advertiser posts to a token that identifies them, and a signature check rejects anything that does not match.
- Duplicates are impossible, not merely detected. Two unique database indexes — one on the advertiser's transaction id, one on the click and goal — make a second payment for the same action a constraint violation rather than a judgement call. A retried postback returns success and pays once.
- Timed formats are timed by us. A Paid To Click visit is measured on our servers, twice, and cannot be completed faster than the offer's stated duration whatever the browser claims.
3. What we score
Every conversion is scored before it is accepted. The signals include:
- Time between click and conversion. An action that takes a person two minutes, completed in one second, did not happen the way it is being described. For formats where the duration is defined — Paid To Click — the offer's own dwell time is the floor, so honest users are never caught by a generic rule.
- Velocity. A placement producing far more conversions per hour than its own history supports.
- Repetition across identities. The same device or address converting the same offer as a series of different users.
- Consistency. Whether the country, device and operating system recorded at click time match what the conversion reports.
- Blocklists. Addresses, devices, end-user identifiers and placements already established as sources of invalid traffic.
- Advertiser evidence. A reversal from the advertiser's own systems — a refunded purchase, a fake registration, a cancelled trial — inside the hold window.
A score above a threshold rejects the conversion outright; a score below it may still raise a flag for a human to look at. We do not publish the thresholds or the weights. They are operator settings, they change, and printing them would be a tuning guide for exactly the people this policy is about.
4. The hold period
An accepted conversion is not immediately withdrawable. It is held for a period the advertiser sets on the offer, during which either side can produce evidence that it should not stand. The advertiser is charged when the conversion is accepted; the publisher's share only becomes withdrawable when the hold elapses.
That asymmetry is deliberate. It means a reversal costs the publisher money they had not yet been paid, rather than clawing back money already sent — and it means an advertiser cannot spend a conversion's budget twice while disputing it.
A reversal is symmetric: the advertiser is refunded in full, the publisher's share is removed, and both movements are recorded in the ledger with the reason attached. There is no partial reversal and no quiet adjustment.
5. What happens when traffic is invalid
In rough order of severity:
- The conversion is rejected. Nobody is charged and nobody is paid. The rejection and its reason are recorded against the click.
- The conversion is reversed. If it was already accepted, the advertiser is refunded and the publisher's share is removed.
- A payout is held. If a pattern rather than an incident is involved, we hold the withdrawal and tell you what we are looking at. We do not hold silently.
- An offer or placement is paused. Serving stops while the question is open, in either direction — a misconfigured advertiser can waste a publisher's traffic just as easily as the reverse.
- The account is suspended or closed. For deliberate, repeated or large-scale invalid traffic. Earnings attributable to it are forfeited; earnings that are not are paid.
A mistake is not fraud and we will not treat it as fraud. A broken integration, a test postback left running, a placement that accidentally auto-clicks — these produce invalid conversions that are reversed, and that is the end of it. What changes the response is intent and persistence.
6. What we expect from publishers
The full version is in the publisher advertising guidelines. In short: real users, taking a real action, of their own accord. No automated clicking, no incentivised misrepresentation of what an offer requires, no traffic you bought from a source you cannot account for, no proxying users into markets an offer excludes.
7. What we expect from advertisers
- Postback only on the real event. Firing on page load rather than on the completed action charges you for nothing and destroys the publisher's ability to optimise.
- Reverse inside the hold, not after it. The window exists for exactly this. A reversal request that arrives weeks later, against money already paid out, is one we will usually refuse — and you will be asked why your own systems took that long.
- Reverse with a reason. "Quality" is not a reason. Systematic reversal without evidence is itself a form of fraud — against publishers — and we treat it that way.
- Describe the offer accurately. Most disputed conversions are not fraud at all; they are users who did what the instructions said, where the instructions did not match the requirement.
8. Disputing a decision
Write to [email protected] with the click identifiers or conversion ids in question. Every conversion carries its timestamps, its recorded country and device, its score and the reason it was refused, and we will show you what we hold.
What we will not do is describe which specific signal fired or what value it took. That is the one thing we keep back, for the reason given in section 3 — and it is the boundary of what this page can promise.
9. Reporting fraud to us
If you find a way to obtain a conversion that should not be payable, tell us rather than demonstrating it at scale. Reports to [email protected] are welcome and we will not penalise an account for a good-faith report, including one that involved a small number of test conversions — tell us about those and they will be reversed without consequence.
Who you are dealing with
Trovewall is operated by Trovewall LLC., registered at Office 251 House of Francis, Ile du Port, Mahe, Seychelles.
| Report a problem or ask about this document | [email protected] |
| Publisher accounts and traffic | [email protected] |
| Advertiser accounts and campaigns | [email protected] |
| Everything else | [email protected] |