Last updated: June 2026
Anti-fraud Policy
ProofTest's value depends on activity being real. This policy describes how we keep it that way and what is prohibited.
1. The principle
A report is only worth something if the underlying activity cannot be forged. Every measure below exists to protect that.
2. How activity is verified
SDK events are signed with a per-campaign ingest key using HMAC-SHA256 and verified server-side. Events that are unsigned or carry an invalid signature are rejected.
Each session carries a client-generated identifier so re-sent batches are deduplicated and never double-counted.
A device fingerprint may belong to only one tester account per campaign.
3. Prohibited behaviour
Emulators, device farms, or scripts that simulate activity without a real person using the app.
Sharing or reusing one device across multiple tester accounts on the same campaign.
Any attempt to fabricate sessions or tamper with the SDK payload.
4. Consequences
Accounts found generating fraudulent activity may have payouts withheld and access revoked. Affected campaigns may be re-run at our discretion.
5. Reporting
Report suspected fraud to contact@prooftest.com.