New research on device-signature drift in African digital environments
Device intelligence is increasingly becoming part of the infrastructure behind digital finance, health, education and all critical digital businesses.
But one assumption deserves closer examination:
Is a device signature actually the same thing as device identity?
At KEVERD, we spent five months measuring how device signals behave in real production environments across Kenya and Tanzania.
We analyzed 10,097 fingerprint submission events across four production sites, focusing on devices that appeared repeatedly.
What we found was clear:
Hardware signatures drift. And the more frequently a device is observed, the more likely its signature is to change.
Executive Summary
Between 17 April and 17 August 2026, we analyzed 10,097 fingerprint submission events from production environments in Kenya and Tanzania.
Of these, 413 devices were observed more than once.
Among those devices, the proportion showing a changed hardware signature increased substantially with repeated observations:
Observation frequency vs Devices with changed signature
- Seen twice - 12%
- Seen 3–4 times - 29%
- Seen 5–9 times - 52%
- Seen 100+ times - 80%
This does not mean the underlying device changed.
Browsers update. Operating systems receive patches. Drivers change. Software environments evolve.
The important distinction is therefore between a changing signature and a changing identity.
Our results suggest that these should not be treated as the same thing.
Finding 1: Hardware Signatures Drift Constantly
Among the 413 devices we observed repeatedly, signature changes became increasingly common as observation frequency increased.
A device observed twice had a much lower probability of showing a changed signature than a device observed dozens or hundreds of times.
The pattern is important because it challenges the idea that a device signature can simply be treated as a permanent identifier.
The signature does not necessarily fail once.
It erodes over time.
Every browser update, operating-system patch or change in the software environment creates another opportunity for the observable signature to move.
This creates an important problem for systems that anchor identity directly to that signature.
Your most engaged customer—the person who returns repeatedly—is also the person who has had the most opportunities to arrive with a changed signature.
If the signature is treated as identity, that customer can eventually look like a new device.
Finding 2: Identity Can Persist Through Signature Change
This is where our approach differs.
Of the devices in our sample that experienced a hardware-signature change, 138 devices changed their canvas or audio signature.
Our derived device identity maintained continuity through those changes.
The reason is fundamental to how we think about device intelligence.
We do not treat a single signature as the identity of a device.
Instead, identity is derived from the broader collection of signals available about that device.
A signature is one piece of evidence.
It is not the identity itself.
An independent measurement
We also performed a separate drift measurement that was not based on the original canvas comparison.
That measurement flagged 67 of the 138 devices whose signatures changed—48.6%.
Among devices whose signatures remained stable, it flagged 5 of 667—0.7%.
The agreement between two independent measurements gives us additional confidence that the relationship between signature change and signal drift is real.
It also reinforces a broader principle:
Device intelligence should reason over evidence rather than depend on a single immutable identifier.
Finding 3: False Merging Was Not the Observed Failure Mode
There are two important ways an identity system can fail.
A single device can become multiple identities.
Or multiple devices can incorrectly become one identity.
We tested for the second case.
Across 437 repeatedly observed devices, we found zero cases where identities were merged across different operating systems, platforms, GPU configurations or browsers.
This result is encouraging.
But it is important to state precisely what it means.
It does not mean the system can never produce a false merge.
It means we did not observe one in this dataset.
That distinction matters when publishing research.
The Boundary: Identity Is Scoped to the Browser Environment
There is another boundary we want to make explicit.
Our current definition of device identity is scoped to the device within its browser environment.
A user switching from Chrome to Firefox can therefore appear as a new device.
That is deliberate.
We define the identity we are measuring as:
This device in this browser environment.
It is important for anyone building on device intelligence to understand that boundary before relying on the signal.
We Got One Number Wrong
Research is not just about publishing interesting numbers.
It is about being willing to remove numbers when the analysis does not support them.
Our first analysis produced a clean headline:
One in three devices changed signature.
It was wrong.
Not fabricated.
Not manipulated.
Wrong.
The problem was the observation distribution.
Devices observed more frequently naturally had more opportunities to experience a change. Averaging the observations without accounting for exposure frequency produced a number that reflected our traffic mix rather than the underlying behaviour of devices.
We caught the problem.
We removed the number.
We re-ran the analysis using an exposure-corrected approach.
And we are publishing the correction because we believe this is part of what credible research should look like.
In device intelligence, numbers are often presented without enough context.
Detection rates can be quoted without denominators.
Match rates can be circular by construction.
Persistence numbers can be difficult to independently validate.
Our position is simple:
If a number cannot survive the question “How was this calculated?”, it should not be used to make a product claim.
What We Know—and What We Don't
The current dataset gives us useful evidence, but it has clear limitations.
What we measured
- 10,097 fingerprint submission events
- 413 repeatedly observed devices
- Production environments across Kenya and Tanzania
- Five months of observations
- Hardware-related signals including canvas and audio
- Independent drift measurement
- Cross-device false-merge testing
What the dataset does not yet represent
The dataset is desktop-weighted.
That matters.
African digital finance is overwhelmingly shaped by mobile devices, and particularly Android devices.
We therefore do not consider this study the final word on device-signature behaviour in Africa.
A controlled test across entry-tier Android handsets is now underway.
We will publish those results with the same level of transparency—regardless of whether the numbers make our assumptions look better or worse.
Why We Are Publishing This
Most of the world's device-intelligence infrastructure has been developed around datasets and environments that are not necessarily representative of African digital markets.
Yet financial institutions, fintechs and digital platforms across Africa increasingly depend on these systems to understand risk and trust.
We believe the region needs its own evidence base.
Not assumptions imported from other markets.
Not vendor claims without denominators.
Not opaque numbers that cannot be interrogated.
We are going to build that evidence base publicly.
This is the first publication in a broader KEVERD research series examining device trust in African digital environments.
Future research will examine:
- Device-signature drift
- Shared IP concentration
- Cross-site device recognition
- Device persistence on entry-tier Android devices
The objective is not to prove that our technology is perfect.
The objective is to understand what actually happens in the environments where African digital finance operates.
The Question We Think the Industry Should Be Asking
If you are building on device signals in African digital finance, the important question is not simply:
“Does your system recognize devices?”
Ask something harder:
How often does the same device reach you as a new one—and would you know if it did?
Because a device signature is observable evidence.
It can change.
It can drift.
It can disappear.
But that does not necessarily mean the device itself has changed.
The signature is evidence.
It was never identity.
Methodology
Dataset: 10,097 fingerprint submission events
Period: 17 April–17 August 2026
Production environments: Four sites across Kenya and Tanzania
Repeated devices analyzed: 413
Devices with observed canvas or audio signature changes: 138
Independent drift measurement: 67 of 138 changed devices flagged (48.6%) versus 5 of 667 stable devices (0.7%)
False-merge test: 0 of 437 repeatedly observed devices were merged across different OS, platform, GPU configuration or browser
The study is based on production observations and should not be interpreted as a controlled laboratory experiment. The dataset is desktop-weighted, and the Android-specific analysis is ongoing.
About KEVERD
KEVERD builds device trust infrastructure for digital businesses operating in high-risk and rapidly changing environments.
Our focus is simple:
Turn device signals into trustworthy evidence.
Trust, engineered.
