Most of our customers do use Sift Science for financial fraud, but because it's a machine learning system, you can train it to detect other types of bad behavior like spam. We have customers in production using us to detect spam, fake inventory, and duplicate accounts. If you have a use-case that doesn't quite seem to fit, let me know and we can figure out how to train our system to recognize that type of behavior: brandon@siftscience.com.
If a fraudster bypasses the JS, we still have REST events such as transactions (or any other custom event sent from the backend). Seeing a user who has REST events but no Javascript events is a suspicious signal in itself, so fraudsters can't circumvent the system by just turning off JS.
FWIW, we're on some pretty major sites that we can't announce, so we've gone through a bunch of compliance, audit, security, and other concerns already.