Socure Fraud
Use Socure Fraud to assess fraud and synthetic-identity risk for an individual. Lendflow sends the primary business owner’s identity, contact, address, and business information to Socure and stores Socure’s risk scores, identity-correlation scores, alert-list findings, and reason codes. The Workflow Builder block is Socure Fraud, its service ID issocure_fraud, and it is available for individual entities in the Fraud block group.
Requirements
Socure Fraud uses the primary business owner’s information and the business legal name stored on the application. Every field marked required must be present and valid before Lendflow contacts Socure.API flow
Start Socure Fraud
- Call
PUT /api/applications/{application_id}/enrichthrough Enrich Business Credit Application. - Set
providertosocure_fraud. - Omit
optionsor send an empty object. Socure Fraud does not require provider-specific options. - Omit
stage_idunless you need to associate the run with a particular underwriting stage. When supplied, it must be the UUID of an underwriting stage in the application’s current workflow. - Treat
{"data":{"onqueue":true}}as confirmation that Lendflow queued the work, not that Socure completed it.
options and stage_id:
Retrieve status, response, and request data
Socure Fraud runs in a queued job. Poll Get Commercial Data untildata.statuses.socure.fraud is Success or contains an error:
The stored request is obfuscated by Lendflow. Use it to confirm which application values and Socure modules were used without exposing the complete SSN or ITIN.
Data Orchestration availability and flow
Socure Fraud is available in Data Orchestration for individual applications. Its conditions can evaluate the returned address-risk, email-risk, phone-risk, synthetic-risk, and name-correlation scores.- In the Lendflow Dashboard, open Builders > Data Orchestration.
- Create or edit a template and add Socure Fraud from the Fraud category.
- Select the score that the condition should evaluate, configure the comparison, and connect each outcome.
- Save and publish the template.
- Call Execute Data Orchestration at
POST /api/applications/{application_id}/data_orchestration/executewithtemplate_idandapplication_id. Includestage_idonly when targeting a compatible workflow stage. - Treat
{"data":{"executed":true}}as confirmation that Lendflow accepted the orchestration run, not as the completed Socure result. - Follow the run through List Data Orchestration Logs and Get Data Orchestration Log, and retrieve the provider payload through Get Commercial Data when needed.
socure_fraud synchronously and then evaluates the returned score. If a record already exists, it satisfies the prerequisite and is reused by default. A returned null score is still a completed provider result and can be handled with a null condition; it is different from having no Socure Fraud record.
See Data Orchestration for the complete template-building workflow.
What the service returns
Representative response
The following sanitized response shows the major objects without reproducing a full provider payload:Response attributes
Fraud and synthetic-identity models
Contact and address risk
Identity correlations
Alert list and request identity
Score interpretation
The current integration and Dashboard treat Socure scores as numeric values on a zero-to-one scale. Examples in the stored response use values such as0.01, 0.461, and 0.99.
- For
fraud,synthetic,emailRisk,phoneRisk, andaddressRisk, a higher score represents greater risk. - For name-correlation results, a higher score represents stronger correlation between the submitted identity elements.
- A score is provider evidence, not a Lendflow approval or decline decision. Define thresholds in your organization’s policy and Data Orchestration conditions.
nullor a missing score means Socure did not return that score. It must not be interpreted as zero, low risk, or a failed API request.
Errors and statuses
A provider finding, high risk score, reason code, or alert-list match is a completed fraud result. It is not the same as an API or execution failure.
FAQ
Which person does Socure Fraud evaluate?
Which person does Socure Fraud evaluate?
Socure Fraud evaluates the application’s primary business owner. The Workflow Builder block is available only for individual entities.
Are address, email, and telephone optional?
Are address, email, and telephone optional?
No. The current request validation requires the primary owner’s email, country, street address, city, state, ZIP code, and U.S. telephone number. It also requires the owner’s first and last name, SSN or ITIN, and date of birth, plus the business legal name. Address line 2 and the prequalification IP address are optional.
Does Socure Fraud require options in the enrichment request?
Does Socure Fraud require options in the enrichment request?
No. Set
provider to socure_fraud and omit options, or send an empty object. Include stage_id only when you need to associate the run with a valid underwriting stage.Does onqueue true mean the Socure result is ready?
Does onqueue true mean the Socure result is ready?
No. It means Lendflow queued an asynchronous job. Poll
data.statuses.socure.fraud until it is Success or contains an error.Why is commercial data null after the request was accepted?
Why is commercial data null after the request was accepted?
data.commercial_data.socure.fraud remains null until Lendflow stores a provider response. Inspect data.statuses.socure.fraud to distinguish a queued or running job from an error.What happens when Data Orchestration has no prior Socure Fraud result?
What happens when Data Orchestration has no prior Socure Fraud result?
The selected score is marked as requiring provider data. Data Orchestration runs Socure Fraud synchronously to obtain that prerequisite, stores the response, and then evaluates the configured condition. Missing or invalid required application data causes that prerequisite run to fail.
Does Data Orchestration rerun Socure Fraud when a result already exists?
Does Data Orchestration rerun Socure Fraud when a result already exists?
A stored Socure Fraud record satisfies the score prerequisite and is reused by default. If your policy requires a fresh provider result, run
socure_fraud again before evaluating the template.Does a null score mean low risk?
Does a null score mean low risk?
No. A
null or missing score means Socure did not return that score. Handle it explicitly with a null condition or a manual-review outcome; do not convert it to zero.Should reason codes be used as automatic pass or fail decisions?
Should reason codes be used as automatic pass or fail decisions?
Not by themselves. Reason codes explain the associated provider result. Combine them with the returned scores, alert-list findings, and your organization’s approved underwriting policy.