Brands
Latest top stories
Start-ups
Technology

The technology deciding whether a digital identity is real

28 August 2026

 

A customer enters a name, address, telephone number and date of birth to open an account. Everything looks plausible. The address exists, the phone is active and the identification number passes a basic database check.

But do those details belong to the same person? Is the applicant using a credible device? Has the telephone number appeared in numerous other applications? Is a human completing the form, or is an automated system submitting hundreds of slightly different identities?

These are the questions Socure’s identity verification technology is designed to help answer.

The US company provides identity verification and fraud detection technology to banks, government agencies, healthcare providers, telecommunications companies, online gaming platforms and ecommerce businesses. Its software helps them decide whether to approve an application, request additional evidence, refer it to an analyst or reject it.

The company has now secured $156 million in a Series E extension that values it at $5.2 billion.It has also acquired Fravity, a startup that uses AI agents to automate fraud, risk and compliance work and that could enable Socure to automate more of what happens after the alarm is raised.

 

How Socure verifies digital identities

 

Traditional digital identity checks frequently rely on information supplied by the applicant. A company might compare a name, address and date of birth against a database, then ask for a photograph of a passport or driving licence.

That works reasonably well when the information is obviously false. It becomes less reliable when criminals use stolen personal information, sophisticated forged documents or synthetic identities assembled from a mixture of real and fabricated details.

Socure takes a broader approach. Its RiskOS platform combines identity verification, document and biometric checks, fraud detection, compliance screening and decision-making workflows.

Instead of asking only whether each piece of information is valid, the system examines whether the complete identity is consistent.

A legitimate address paired with a real telephone number is not necessarily enough. Socure can assess associations between names, addresses, telephone numbers and email accounts, while also examining the device, network and historical interactions connected with an applicant.

Organisations can use these signals to approve low-risk applicants without asking them to take additional steps. Higher-risk users can be asked for further evidence, such as an identity document, one-time passcode or facial verification.

Requiring every customer to upload a passport may reduce some forms of fraud, but it can also cause legitimate customers to abandon an application. Collecting additional identity documents creates privacy, security and data-retention responsibilities as well.

The practical objective is therefore not maximum checking. It is applying an appropriate level of verification to each level of risk.

 

How Socure’s identity graph detects fraud

 

One of Socure’s central technologies is its Identity Graph. This maps connections between attributes such as names, addresses, email accounts, telephone numbers and devices.

Consider 20 applications that appear to come from different people. Viewed separately, each might look credible. Graph analysis could reveal that 15 were submitted from the same device, several use variations of one address and all are linked to a small cluster of telephone numbers.

Those connections could expose organised fraud that would be difficult to spot when each application is assessed in isolation.

Socure also offers Local Graph, which connects identity information with activities, signals and outcomes inside an individual customer’s organisation. The company describes this as a time-aware view because it allows users to examine how identities and their associated attributes evolve.

Socure’s wider Network Identity Graph provides cross-industry signals, while Local Graph helps an organisation find connections across its own internal data.

Socure says its Identity Graph sees five billion identities annually and draws on a cross-industry network of more than 3,000 companies. Its Risk Insights Network combines consortium feedback with more than 400 curated data sources, alongside device and behavioural intelligence. These are company figures, but they explain Socure’s technical proposition: a broader view of identity relationships can reveal patterns that may be invisible to an individual bank, retailer or government agency.

 

Device intelligence can reveal what documents conceal

 

Documents represent only one part of a digital identity. Socure’s Digital Intelligence suite also analyses devices, networks, connections and historical user behaviour.

A criminal may possess a victim’s correct name, address and government identification number. They are less likely to reproduce the victim’s established associations with devices, email accounts and telephone numbers.

Behavioural analytics can also identify anomalies or patterns suggesting automation. These additional signals are becoming more important as generative AI reduces the cost of producing convincing application materials. Fraudsters can generate synthetic faces, manipulate documents and automate submissions. Detecting them requires finding inconsistencies across an interaction rather than waiting for one obviously false element.

Machine-learning models combine these signals into risk scores or decision recommendations. Customers can then create workflows inside RiskOS: accept an application below a chosen risk threshold, request additional verification in an uncertain case or send a complex application to an analyst.

RiskOS supports Socure’s own products as well as third-party data sources. Customers can configure rules, thresholds and decision outcomes through its workflow tools. According to Socure’s documentation, possible outcomes include acceptance, rejection or manual review, accompanied by reason codes.

The thresholds should not be copied blindly from a vendor. A bank opening current accounts, a gaming service checking a user’s age and a government agency distributing benefits face different risks. Each needs to test the system against its own fraud losses, customer population and consequences of rejection.

 

Avoiding false positives in identity verification

 

An effective identity platform must detect fraud without excluding people whose data does not fit conventional patterns.

Young adults may have little financial history. Recent immigrants may have moved frequently or use documents from another jurisdiction. Lower-income customers can have thinner digital footprints. People also mistype addresses, change their names and share devices with family members.

These cases can resemble fraud to a rigid rule-based system.

Socure argues that combining more data sources and identity relationships allows it to verify legitimate applicants without immediately demanding documents. Prospective users should nevertheless test that proposition rather than accept a general accuracy figure.

Useful questions include how often the system incorrectly refers or rejects genuine users, whether performance differs between demographic groups and how customers can challenge an adverse decision. The quality of an identity platform is reflected as much in whom it lets through as in whom it catches.

 

What Fravity adds to Socure’s RiskOS platform

 

Automated fraud detection has not eliminated manual work. In some organisations, it has simply moved the bottleneck.

When a system flags an ambiguous case, an analyst may need to retrieve evidence from several systems, review transactions, conduct sanctions or politically exposed persons checks, search adverse media and document the eventual decision.

Fravity develops specialised AI agents that can automate portions of this process. Its platform includes more than 70 pre-built agents for tasks including document analysis, sanctions screening and adverse-media research. Organisations can also design workflows around their own policies and risk models.

Integrated into Socure’s platform, the technology will be offered as RiskOS Agents. The aim is to assemble evidence and produce case-ready information that helps analysts reach decisions more quickly, rather than merely generating another risk score.

This could be useful for organisations overwhelmed by alerts, but it changes the implementation question. Buyers must determine not only whether the risk model is accurate, but also what an agent is permitted to access and do.

An agent that gathers evidence is different from one authorised to freeze an account or reject a customer. Sensitive actions require restricted permissions, traceable source material, complete audit logs and clearly defined points for human review.

Socure does not provide a universal system for authenticating every autonomous agent operating inside a company. Its focus is deploying agents within identity, fraud and compliance workflows.

 

Socure’s competitors in identity verification

 

The identity verification and fraud prevention market overlaps in complicated ways.

Persona offers modular verification, fraud prevention and configurable identity workflows. Its flexibility and international reach may appeal to organisations that need different verification journeys across markets and use cases.

Alloy concentrates heavily on financial institutions and fintech companies. Like Socure, it combines identity, fraud, compliance and decision orchestration. It has also introduced agentic assistance for fraud and compliance operations, putting the two companies in increasingly direct competition.

SentiLink specialises in application fraud, including synthetic identity, identity theft and first-party fraud. Entrust, Jumio and Estonia-based Veriff are particularly prominent in document and biometric verification. Experian and LexisNexis Risk Solutions compete through their extensive data and established risk products.

Socure’s differentiating proposition is the combination of its cross-industry identity intelligence, predictive models, device and behavioural signals, document verification and configurable workflows. Fravity adds automated investigation to that stack.

For prospective users, however, the decisive question is not which provider advertises the highest overall accuracy. It is which system catches the organisation’s actual fraud while allowing the largest possible number of genuine customers through with the least unnecessary friction.

Socure’s latest expansion points towards a future in which identity platforms do more than answer: “Is this person real?” They will also gather evidence, investigate anomalies and help determine what an organisation should do next.

That could save substantial manual work. It also makes transparency and human oversight more important, because identity technology is no longer merely checking information. It is becoming part of the decision itself.

 

 

Further reading on MoveTheNeedle.news:

Can human investigators keep pace with AI-powered deception?

Who gave the AI agent permission to do that?