Skip to content
Skip to main content
Payments & Banking Technical Explainer

What can payment records prove about a device?

They can associate an event with a provider device identifier, application, browser or session. That association does not identify the human holding or directing the endpoint.

Provider device data describes an access route

Records may show internal device ID, operating system, application or browser, friendly name, IP-related data, session and authentication, plus registration or removal. Names can be generic or user-selected, endpoints can be shared or remotely controlled, and notifications may arrive somewhere other than initiation.

Corroborate the event on the endpoint

Preserve internal IDs rather than only display names. Compare provider time and session with forensic artefacts, application data, communications, possession and location, looking for creation, authentication or confirmation rather than installation alone.

Report the provider association first and identify a user only where converging evidence supports it.

The point to remember

Device records identify an account access route; endpoint and contextual evidence are needed to identify its user.

Reference: PAY-211Payments & Banking