Detection at the terminal, not at the transaction.
ATMList reads every terminal on your network and scores every cash withdrawal for skimmer, shim, and cash-trap signatures — in the authorization path, with the evidence attached.
Skimming is a device crime. A card number changes hands only after a skimmer sits on a reader, so a transaction model sees a normal withdrawal on a normal card and allows it. ATMList reads the machine that produced the withdrawal.
What is live today.
- Terminals monitored
- 2.1M
- Markets live
- 70+
- P50 decision time
- <40 ms
- Known kits caught before the first cash-out
- 94%
What changes for an issuer.
- Skimming is caught at the terminal, before the first cash-out, instead of after the cards have been dumped.
- Disputes fall because a block carries a reason code and the terminal risk behind it, not a score with no explanation.
- Investigations assemble themselves: artifacts, the terminal timeline, and neighbouring terminals arrive as one case file.
- Fleet teams work a ranked visit list instead of an incident pile.
How a withdrawal is scored.
Signals
Device telemetry from the terminal, read patterns from the card reader, and kit signatures shared across the network.
Decision
The model scores the withdrawal inside the authorization path and returns allow, step_up, or block with the reason codes behind it.
Evidence
A block opens a case with the artifacts, the terminal's history, and the neighbouring terminals a field team needs.
One decision call, three read paths.
Bearer-key REST, snake_case JSON, ISO-8601 UTC timestamps, cursor pagination, and webhooks for terminal.compromised and withdrawal.blocked.
- POST /v1/score/withdrawal
- GET /v1/terminals
- GET /v1/cases
- GET /v1/signatures
No PAN, no retention by default.
Card numbers arrive as tokenised references. Nothing is stored unless you ask for it. SOC 2 Type II, with optional data residency.