Applicant risk labels

Be aware of the risk level of your applicants.

Risk labels are indicators assigned during the verification process to highlight certain characteristics or potential risks associated with applicants.

By default, risk labels do not influence verification flows and not taken into account when our system is passing decision on specific applicant. However, it is possible to setup automated workflows that will trigger specific actions—like manual review or rejection—for an applicant based on the risk labels assigned to them. For example, you can use risk labels to detect VPN access and reject applicants for using a VPN connection.

View risk labels

To see the risk labels:

  1. In the Dashboard, go to the Applicants page.
  2. Open an applicant profile and scroll down to the Risk labels section.

Email risk labels

Email risk labels are associated with email and phone verification.

LabelAPI nameDescription
Disposable email
disposableTemporary email address that usually expires after a short period of time.
High risk email
highRiskA verdict made by the system according to the check results and internal logic.
Medium risk email
mediumRiskA verdict made by the system according to the check results and internal logic.
No registrations on Web services found
noWebRegistrationsEmail address registration is not detected.
No website exists
noWebsiteExistsEmail domain does not exist.
Non-deliverable
nonDeliverableAn email address to which the messages cannot be delivered.
Gibberish email address
gibberishAn email address that does not look like a human-readable address and could be generated automatically.
Fresh email with short digital footprint history
freshEmailEmail first appeared on the web less than 3 months ago, indicating a potential single-use or burner account pattern.

Phone risk labels

Phone risk labels are associated with email and phone verification.

LabelAPI nameDescription
Disposable phone number
disposableA temporary phone number that usually expires after a short period of time.
High risk phone
highRiskA verdict made by the system according to the check results and internal logic.
Medium risk phone
mediumRiskA verdict made by the system according to the check results and internal logic.
No registrations on Web services found
noWebRegistrationsPhone number registration is not detected.
Virtual phone
virtualA virtual phone number is a number not associated with any physical location, allowing to make calls via internet.
Fresh phone with short digital footprint history
freshPhonePhone number first appeared on the web less than 3 months ago, indicating a potential single-use or burner account pattern.
Phone number country does not match IP country
phoneCountryVsIpCountryMismatchPhone number country does not match the IP address country.
Phone number country does not match email domain country
phoneCountryVsEmailDomainCountryMismatchPhone number country does not match the country of the email domain.
Phone number country does not match physical address country
phoneCountryVsAddressCountryMismatchPhone number country does not match the country of the applicant's physical address.
Phone number country does not match applicant country
phoneCountryMismatchPhone number country does not match the applicant's country.
Phone number country does not match company country
phoneCountryVsCompanyCountryMismatchPhone number country does not match the company country.

Device risk labels

Device risk labels are associated with devices used by applicants to pass verification.

LabelAPI nameDescription
Ad Blocker
adblockDetects whether the advertisement blocking software is used.
App tampering
tamperingIndicates the usage of anti-detect browser or tampering with the browser default behavior.
Automation
badBotIndicates that device activity appears to be automated, which may reflect malicious bot behavior or legitimate AI agent usage.
Cloned Application
clonedAppIndicates the request is from a cloned version of the user's app.
Developer tools detected
developerToolsInforms whether developer tools were manually opened in Chrome or Firefox browsers.
Devices from distant IP locations were used
distantIpLocationsLogin from different and distant IP addresses over a short period of time.
Emulator Detected
emulatorIndicates the user's app is running from within an Android emulator instead of a physical device.
Failure to continue on another device
failedSessionContinuationThe session was interrupted due to inability to seamlessly transfer sessions from one device to another.
Frida Tool Detected
fridaToolIndicates the user's app is being tampered with using Frida tool.
High risk IP
highRiskIpIndicates high risk IP addresses.
Incognito mode
incognitoDetects whether incognito or private modes are being used.
Jailbroken Device
jailbrokenIndicates the user's app is running on a jailbroken iOS device.
Known bot
goodBotIndicates that the bot is a well-known web crawler or other search engine bot.
Lengthy onboarding session
lengthySessionThe session lasts too long.
Link access via external source
thirdPartyLinkAccessThe verification link has been opened in messaging apps or link shortening services.
Location Spoofing
locationSpoofingIndicates the mobile device is trying to spoof its location.
Man-in-the-Middle Attack
mitmAttackIndicates the request from the user's app is intercepted and potentially modified.
Multiple devices were used
multipleDevicesInforms whether the applicant uses multiple devices.
Multiple mobile devices were used
multipleMobileDevicesInforms whether the applicant uses multiple mobile devices.
Privacy settings enabled
privacySettingsModePrivacy settings that have the ability to randomize and obfuscate signal output are enabled.
Recent Factory Reset
factoryResetThe device has been recently factory reset, which may be used to erase previous activity or bypass fraud detection.
Rooted Device
rootedIndicates the user's app is running on a rooted Android device.
TOR usage
torUsageDetects whether TOR connection is used.
Virtual machine
virtualMachineDetects whether the browser is running inside a virtualization software by examining the browser configuration.
VPN usage
vpnUsageDetects whether VPN connection is used.
Quick session completion
quickSessionDetects whether the applicant completes complex steps, such as selfie or ID document capture, unusually fast. Indicates using a script or automation.
Activity during night hours
nightTimeActivityDetects whether a verification session occurs between 00:00 and 06:00 based on the applicant's timezone. Indicates fake identities.
Many applicants using the same device
manyApplicantsSameDeviceDetects whether several unique applicants use the same device: more than 1 during 5 minutes, more than 2 during an hour, more than 5 during a day, more than 10 during a month. Indicates multi-accounting.

Cross-check risk labels

Cross-check risk labels are associated with the cross-checks based on matching different applicant data.

LabelAPI nameDescription
Accounts in many other services
accountsInManyServicesThe same account is registered in different services (>=5 accounts in different sources).
Browser language does not match IP or document country
browserLanguageMismatchBrowser language does not match the IP or document country.
Country of photo creation is different from IP and ID document countries
exifCountryVsIdDocCountryOrIpCountryMismatchCountry of photo creation is different from IP and ID document countries.
Diverse countries in ID documents
diverseIdDocCountriesIdentity documents were issued in different countries.
Email domain country does not match applicant country
emailDomainCountryMismatchThe email domain country does not match the applicant's country.
IP location timezone differs from browser timezone
ipLocationVsTimezoneMismatchThe IP location timezone differs from the device timezone.
Many duplicates exists
manyAccountDuplicatesLots of account duplicates are detected (>=3 accounts from one source; one client and one source key).
Mismatch between applicant address and IP country
addressCountryVsIpCountryMismatchThe physical address does not meet the IP address.
Mismatch between ID document country and IP country
idDocCountryVsIpCountryMismatchID document country mismatches the country IP address.
Potential link to fraudulent applicant
potentialLinkToFraudulentApplicantA potential link to a known fraudulent applicant is detected, based on a fraud networks pattern with softer signals such as similar device.
Strong link to fraudulent applicant
strongLinkToFraudulentApplicantA strong link to a known fraudulent applicant is detected, based on duplicate search (biometrics, documents, email, phone) or a reliable fraud networks pattern such as exact same device.

Selfie risk labels

Selfie risk labels are associated with selfies.

LabelAPI nameDescription
Estimated age is different from the age on the ID document
estimatedAgeMismatchThe estimated age does not match the age indicated in documents.
Many attempts to submit a selfie
manyAttemptsThere were too many attempts of passing a selfie check (>5 selfie attempts).
Suspected third-party involvement
thirdPartyInvolvedThere are signs that another person may be assisting or present during the selfie or Liveness capture process.
Possible phone usage
phoneThere are indications that a phone or similar device may be used during the selfie or Liveness capture process.
Persons seems to be asleep
asleepThe person in the picture is asleep.
Similar applicants with different data
sameFaceWithDifferentDataSimilar or matching faces detected across multiple applicants within the client’s environment while the associated identity data (such as name, document number, or other personal details) differs.
Usage of virtual cameras
virtualCameraPresentA visual software simulating real camera is detected.

AML risk labels

AML risk labels are associated with AML screening and monitoring.

LabelAPI nameDescription
Adverse media
adverseMediaCompromising information related to the applicant was found in the media.
Crime
crimeApplicant is suspected of criminal activities.
PEP
pepApplicant belongs to the PEP (Politically Exposed Person) category.
Sanctions
sanctionsApplicant was found in sanctions lists.
Terrorism
terrorismApplicant is suspected of terrorism.
Fitness probity
fitnessProbityApplicant is found in the Fitness and Probity lists.

Person risk labels

Person risk labels are assigned when the applicant has certain characteristics as per the following table.

LabelAPI nameDescription
Famous person
famousPersonIndicates an assumption that the applicant is a famous person.
Name mismatch with the names associated with the email
emailNameMismatchFromWebServicesThe provided applicant name does not match the names found by the specified email address.
Name mismatch with the names associated with the phone
phoneNameMismatchFromWebServicesThe provided applicant name does not match the names found by the specified phone number.
No email names found in web services
noEmailNamesFromWebServicesNo email names found in web services.
No phone names found in web services
noPhoneNamesFromWebServicesNo phone names found in web services.
Strange name
strangeNameApplicant name seems to be not a real one.
Contact data linked to multiple different names across the web
manyUniquePersonsLinkedToContactDataApplicant's contact data (email or phone) is linked to multiple distinct, unrelated identities across the web.

Company risk labels

Company risk labels are associated with the Companies applicants.

LabelAPI nameDescription
Required company fields are absent in the document
companyDocumentMissesRequiredFieldMajor fields (like Company name/Registration Number) haven't been found in the uploaded company documents.
Mismatch of additional company fields in the document
companyDocumentDataMismatchAdditional fields (Incorporated on, Legal Address), presented on the document, mismatch the data from the registry check provider (incorporatedOn, legalAddress).
Additional company fields are absent in the database
companyAdditionalDataNotFoundAdditional fields (Incorporated on, Legal Address, Website, Tax ID) could not be verified as they're missing from the reference database.
Mismatch of additional company fields in the database
companyDataMismatchAdditional fields (Incorporated on, Legal Address, Website, Tax ID) mismatch with the reference database.
Company ownership data is not available
companyOwnershipDataNotFoundCompany Ownership data (information on persons with significant control) is absent from the reference database.
Company UBO data is not available
companyBeneficialOwnershipDataNotFoundUltimate Beneficial Ownership could not be established due to insufficient Company Ownership data or current threshold settings.
Company officers data is not available
companyOfficersDataNotFoundCompany Officers data is absent from the reference database.
Associated party data mismatch
companyAssociatedPartyDataMismatchNot all company officials are properly declared, so the provided information does not match the company data in registry.
Usage of graphic editors
companyDocumentGraphicEditorUploaded document or image may have been modified using graphic editing software.
Excessive associated parties
companyExcessiveAssociatedPartiesThere are known redundant company officials. As a result, the provided information does not completely match the registry data.


Did this page help you?