A CPA network has frozen a payout, called the traffic fraudulent, and asked for proof. At that point, Keitaro logs for legal evidence are not a technical appendix. They can become the factual basis for a claim, a response to a bank, or a court position — but only if the records are preserved and explained correctly.
Our legal practice works with Russian-speaking media buying teams and agencies in disputes with foreign networks, advertisers, and platforms. We review Keitaro and Binom tracker records, separate raw events from dashboard totals, and assess whether the materials support a demand for payment. First come the logs, then the assessment, then the claim.
When Keitaro logs matter in a payment hold
A hold is a temporary freeze of a payout by a CPA network or advertiser. The stated reasons are usually bots, duplicate leads, low-quality traffic, misleading advertising, or a breach of offer terms. These grounds are different. A network may rely on one short anti-fraud notice, while the actual dispute concerns several issues at once: the source of clicks, the conversion path, the postback, and the advertiser’s decision to reject leads.
Keitaro is a traffic tracker. It records the technical route of a visit through campaigns, streams, landing pages, offers, and conversion events. This does not automatically prove that every lead was valid. It does show what happened on the buyer’s side: when a click reached the tracker, which campaign rule directed it, whether a conversion postback was received, and how the tracker attributed the event.
That distinction is central. A tracker log cannot replace an advertiser’s internal verification of a call, a deposit, or an approved application. But a network also cannot reasonably reject a payout by naming fraud without connecting that allegation to identifiable traffic and contractual rules. The logs help establish where that connection exists and where it does not.
What makes Keitaro logs usable as legal evidence
A screenshot of a dashboard is usually a weak starting point. It is easy to crop, difficult to verify, and often lacks the event-level detail needed to answer objections. A useful evidence package combines the original records with a clear explanation of what each field means.
The first task is preservation. Do not clean campaigns, delete streams, overwrite domains, or change tracker settings while the dispute is active. If access to the server is shared among team members, limit changes and record who exported the materials. An export made after the dispute began can still be relevant, but its origin and method should be clear.
The second task is consistency. Campaign names, offer identifiers, sub-identifiers, timestamps, and conversion identifiers should match across the tracker, network reports, postback records, invoices, and correspondence. A difference is not always fatal. Time zones, delayed postbacks, and separate attribution rules can create ordinary discrepancies. The problem begins when no one can explain them.
The third task is context. Logs without the applicable offer terms are incomplete. We compare the tracker data with the CPA agreement, the offer description, traffic restrictions, caps, hold rules, and the network’s fraud notice. If the network prohibited a source or a promotional method, the legal assessment changes. If the restriction was absent, vague, introduced later, or unrelated to the disputed conversions, that also matters.
The records usually needed
For an initial review, we normally need the hold notice or correspondence explaining the refusal, the applicable terms and offer rules, and payment documents showing the amount claimed. From Keitaro, the useful materials generally include campaign-level and event-level exports, click identifiers, conversion data, stream settings, postback history, and records showing the server time zone.
We also need the network’s statistics for the same period. Where available, advertiser rejection reports, lead statuses, and the stated grounds for invalidation should be preserved in their original form. If the network only provides a total number of rejected conversions without identifiers or reasons, that is itself a fact to address in the claim.
Do not send a random archive of files without an index. More data is not always better evidence. A legal position needs a readable sequence: traffic was purchased, routed through defined campaigns, recorded by the tracker, attributed by the network, and later disputed under specified terms.
How tracker logs are tested against a fraud allegation
An anti-fraud statement may be correct, partly correct, or unsupported. We do not start from the assumption that every hold is unlawful. The question is whether the available evidence supports the network’s deduction and whether the deduction follows the agreement.
For example, repeated clicks from the same technical environment can require a closer review, but they do not by themselves establish artificial traffic. The pattern must be assessed together with timing, campaign settings, conversion events, and the advertiser’s verification criteria. Conversely, unusually concentrated activity, inconsistent event sequences, or conversions arriving outside the campaign logic may weaken a payment demand.
Postback data deserves separate attention. A postback is a server-to-server notice that reports a conversion from the network or advertiser to the tracker. It can confirm that a conversion was sent and attributed at a particular time. It does not prove that the network later had no contractual right to reverse that conversion. The exact terms on reversals, validation periods, and fraud deductions remain relevant.
This is why a hold dispute should not be mixed with a platform account ban. A Meta Business Manager or Google Ads restriction concerns access to an advertising account and requires an appeal based on platform facts. A CPA hold concerns payment under the relationship with the network or advertiser. The evidence may overlap, but the letters, recipients, and legal questions are different.
Building a claim from technical records
A claim should not read like a technical report copied from Keitaro. The recipient needs to understand the dispute without guessing what a stream, token, or sub-identifier means. We translate the log structure into a chronological factual position and attach the underlying materials so that key statements can be checked.
The claim usually identifies the payable period, the amount under hold, the relevant offer terms, and the network’s stated reason for nonpayment. It then addresses the specific disputed traffic. If the network has not identified the allegedly invalid conversions, the claim can require a reasoned breakdown. If it has provided identifiers, we compare them with tracker events and attribution records.
The requested remedy depends on the evidence and the contract. Sometimes the proper first step is a demand for documents and reconsideration of the hold. Sometimes the records show that part of the amount is genuinely vulnerable, and an inflated claim would make the position weaker. We say this before a formal dispute is sent, not after months of correspondence.
Where the network, advertiser, or payment side is outside the client’s country, language and procedure matter. The correspondence may need to be prepared in English, while the team’s technical explanation and evidence collection remain in Russian. Jurisdiction, contract clauses, and the payment route affect further options. No tracker export can remove those questions.
Common mistakes after a CPA payout freeze
The first mistake is waiting until the tracker server is changed or access is lost. The second is relying on screenshots when raw exports and configuration records are available. The third is arguing only that traffic was expensive or that the buyer acted in good faith. Cost and intent do not replace evidence of compliance with offer terms.
Another mistake is editing records to make the picture cleaner. Even a harmless change can create questions about the reliability of the whole package. Preserve the original data first. Any analytical table, translation, or summary should be clearly separated from the source records.
Finally, do not send a broad accusation before checking the contract. A network’s poor explanation may give grounds to request detail and challenge a deduction. It does not automatically mean every withheld conversion must be paid. The legal position should match what the logs, terms, and payment documents can actually establish.
Questions clients ask
Can Keitaro logs prove that leads were valid?
They can prove technical events and attribution on the tracker side. Lead validity may also depend on advertiser checks, call results, deposits, or other criteria stated in the offer terms. Logs are often necessary evidence, but not always sufficient on their own.
Are screenshots from Keitaro enough?
Usually no. Screenshots can support an explanation, but event-level exports, server settings, postback records, and matching network data carry more weight. The best evidence package preserves both the source records and a readable summary.
What if the network refuses to provide fraud details?
Preserve that refusal. It may be relevant where the network makes a deduction but does not identify the affected conversions, the violated rule, or the underlying basis. The next step depends on the agreement and the evidence already available.
If your CPA payout is on hold, send the hold notice, the reason given by the network, the applicable offer terms, and the Keitaro exports before changing anything in the tracker. Our lawyers will assess the evidence, identify the weak points, and prepare the next legal step for the payment dispute.