Socure RiskOS

by Socure Inc. HTTP API in Identity & business verification

Hosted

Socure Inc. · socure.com since 2003 · status page · who's behind it

Socure RiskOS is an identity verification and risk decisioning platform from Socure Inc. Its Evaluation API runs configured workflows for KYC, document and selfie checks, fraud scoring and watchlist screening, and returns a decision with reason codes.

Good for A company in the United States that wants one decision from combined KYC, document, fraud and watchlist checks through a single evaluation call.

Is this your product? Claim this listing or verify it

Assessment. A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it.

Facts

Transport
HTTP
Endpoint
https://mcp.riskos.socure.com/sandbox
Auth
API key
Pricing
Pay per use · $0.80 / tx
x402
No
Licence
Proprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary
Tools exposed
9
Packages
npm @socure-inc/device-risk-sdk
llms.txt
published
Last release
npm / week
35k
API
REST with JSON at https://riskos.socure.com (production) and https://riskos.sandbox.socure.com (sandbox). OpenAPI 3.0.3, version 2025-01-01.orion, ten operations (4 POST, 3 GET, 2 PUT, 1 PATCH). An optional X-API-Version header pins the version
Checks
Workflows combine Socure Verify (KYC), Predictive DocV (government ID and selfie), Sigma identity, synthetic and first-party fraud scores, email, phone and address risk, device intelligence, global watchlist screening with daily monitoring, eCBSV, deceased check, bank account verification and business onboarding
Integration paths
Direct API, synchronous or asynchronous with webhooks, or a Socure-hosted flow that returns results by webhook. Decisions are ACCEPT, REVIEW or REJECT by default
MCP server
Hosted over HTTP at https://mcp.riskos.socure.com/sandbox and /prod with an MCP Server Key as bearer token. Nine tools (ask_docs, add_webhook, update_webhook, list_webhooks, list_events, list_testcases, list_usecases, list_workflows, integration_checklist), two prompts and one OpenAPI resource. It runs no evaluations
Credentials
Bearer API keys per environment, regenerated in the dashboard with the old key working until deleted. Each key reaches all workflows. Separate MCP, SDK and Okta keys. Optional IP allowlist, mutual TLS and JWE payload encryption
Rate limits
Sandbox 10 requests a second and 1,000 a day per endpoint and method. Socure Launch 1 evaluation a second and 500 a day. Production 0 until activated, then set per account. Headers X-RateLimit-Limit-Day, X-RateLimit-Limit-Window and X-Retry-After on 429
Errors
JSON with error, code, optional message, details and invalid_args. 15 documented codes from INVALID_REQUEST to BAD_GATEWAY. Some legacy endpoints omit code
Webhooks
Events such as evaluation_completed and decision_update, authenticated by Basic, bearer token or OAuth 2.0 client credentials. Up to 10 attempts with backoff capped at 60 seconds. Receivers dedupe on event_id
SDKs
Client-side only. Digital Intelligence and Predictive DocV SDKs for web, iOS, Android and React Native. @socure-inc/device-risk-sdk 2.11.0 on npm (1 September 2026). No server-side SDK found
Audit
Dashboard audit logs for account and workflow changes, and compliance reports exported as CSV. No API request log was found in the docs
Certifications
SOC 2 Type 2, ISO/IEC 27001:2022, 27017:2015, 27018:2025 and 27701:2025, FedRAMP Moderate and TX-RAMP Level 2 per trust.socure.com and the security page
Status
status.socure.com on Statuspage, with RiskOS and each product as components and incident history back to December 2025
Sub-processors
Amazon Web Services (US East), Google Cloud for RiskOS (United States) and Snowflake (United States) per trust.socure.com. The privacy notice also names service providers in the Philippines and staff access from India, the United Kingdom and Europe

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • OpenAPI 3.0.3 file for ten operations and a 3.1 webhook file in a public GitHub repository, last synced 5 October 2026
  • llms.txt indexes for every docs section and a Markdown copy of each page, with a robots.txt signal that allows AI input
  • Socure Launch publishes four solutions at $0.80 to $1.30 per evaluation, with a free sandbox and $1,000 of monthly production credits
  • Errors return one of 15 machine-readable codes with field-level invalid_args, and 429 responses carry X-Retry-After
  • Release notes show entries on 5 and 6 October 2026 and more than 20 dated entries since 10 July

Weaknesses

  • No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture
  • Each API key reaches every workflow, with no scopes or read-only keys, and an additional key has to be requested from Support
  • The rate limit page advises idempotency keys, but neither the docs nor the OpenAPI file define an idempotency header
  • No endpoint lists or searches evaluations. A caller needs the eval_id from the original response or a webhook
  • Enrichment request and response schemas, reason codes and signal definitions sit in the dashboard, not in the public docs
  • Production starts at 0 requests a second until Socure approves it, and Launch accounts are capped at 1 evaluation a second and 500 a day

Before you call it notes for agents

  1. Send Authorization: Bearer <key> to https://riskos.sandbox.socure.com/api/evaluation for tests and https://riskos.socure.com/api/evaluation for live checks. The two environments use separate keys.
  2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.
  3. Store the eval_id from every POST /api/evaluation response. No list or search endpoint exists to find it later.
  4. On 429 wait the seconds given in X-Retry-After. Do not blindly resend a failed POST /api/evaluation, because no idempotency header is documented and Launch bills each initiated evaluation.
  5. The MCP server at https://mcp.riskos.socure.com/sandbox reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results.

Who's behind it provenance 82/100

  • Legal entity namedSocure Inc.20/20
  • Domain agesocure.com, registered 2003-06-20 (23 years)15/15
  • Endpoint on the vendor's domainmcp.riskos.socure.com15/15
  • Terms of servicenot found0/10
  • Privacy policyread, states 7 of the 8 things a reader expects, and has 1 clause that costs points7.3/10
  • Status pagestatus.socure.com10/10
  • Changelogpublished10/10
  • security.txtpublished but past its Expires date5/10

Terms and privacy, as read

Terms of service none to read

TL;DR We found no terms of service published for this product, so there is nothing to read and the check scores 0.

Privacy policy gives no date, states 7 of 8, 1 to know

TL;DR Gives no date. States 7 of the 8 things a reader expects. To know before relying on it, model training with no opt-out found.

Says it may use customer content to train or improve models, and no opt-out was foundcosts points
Identity documents and images may also be used to train and test machine learning models and to maintain a record of images linked to repeated fraudulent activity.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
…products and services (the “Services”), and describes How Socure Works, the Personal Information We Collect (and the Sources), Where We Store And Transfer Your Personal Information, How We Use Your Personal Information, How We Disclose Your Personal Information, How Long We Retain Your Personal Information, How We Pro…

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 7 days
Special Notice re Data Rights Requests: We delete any personal information used to verify your identity for a data rights request within 7 days of verification.

Says when data sent to the service is deleted.

Says who else receives the data
If you live in California, your state’s privacy law, the California Consumer Privacy Act, uses different terms instead: “Business” and “Service Provider,” defined by what your contract with us says rather than by who decides how your data is used.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
Socure does not sell or share, and has not sold or shared in the preceding 12 months, any personal information (including biometric data or other personal information), as those terms are defined by applicable law.

A plain statement either way.

Says what rights people have over their data
You may contact EDPO regarding matters pertaining to the GDPR: (1) by using EDPO’s online request form;

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@socure.com
To contact the Socure Privacy team, including our Data Protection Officer (DPO), you may email privacy@socure.com or call 1-888-690-3709.

An address or officer to send a request to.

Says where data is transferred or stored Relies on the Data Privacy Framework
Where Socure processes personal information on behalf of a Customer, we may direct individuals to that Customer or otherwise act in accordance with the Customer’s instructions, consistent with applicable law and the Data Privacy Framework Principles.

The countries data goes to and the safeguard used.

Socure may reuse data from a customer's transactions, as a controller, to build fraud-detection insights across its whole customer base.
When processing transactions for a Customer, Socure both acts as a Processor for a transaction, and may separately use some of that same data, as a Controller, to build fraud-detection insights across our customer base (for example, spotting a pattern of fraud across many companies).

Noted by a second reader on 2026-10-08.

Socure classifies traffic as human, bot or AI agent, and may train its agent-classification and agent-trust models on the data it collects.
Where we develop agent-classification or agent-trust features, we may train those models using data collected.

Noted by a second reader on 2026-10-08.

Where Socure detects signs of automated activity, it may collect device and browser signals from tabs or windows that are not in active use.
Where we detect signs of automated activity, we may also collect these signals from browser tabs or windows that are not actively in use, to assess whether that activity is automated.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,515 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Global Services Privacy Notice (effective 1 October 2026) names Socure Inc. and covers the verification services. A separate Website Privacy Notice covers the marketing site.

No service agreement or API terms are published. www.socure.com/terms-of-service is the Website Terms of Use, and the policies page lists only privacy notices, the DocV Terms of Use for end users and a text messaging notice, so the terms field is left out.

The API answers at riskos.socure.com and riskos.sandbox.socure.com, and the MCP server at mcp.riskos.socure.com, all socure.com subdomains.

www.socure.com/.well-known/security.txt gives security@socure.com and an Expires value of 15 July 2026, which has passed.

RDAP for socure.com gives a registration date of 2003-06-20.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-09 09:03 UTC

Right nowUpHTTP 403 · 352 ms · 5 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h334 msget
p95 24h352 msanswers, asks for auth

Probed every five minutes at https://mcp.riskos.socure.com/sandbox. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 1 minute ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/socure-riskos.json

Notable

  • The Evaluation API has ten operations under /api, among them POST /api/evaluation, GET and PATCH /api/evaluation/{eval_id}, a state update, a document download, watchlist monitoring, custom watchlist records, feedback and a reason code catalogue source
  • Socure Launch is the self-serve edition, with four prebuilt solutions priced at $0.80, $0.90, $1.00 and $1.30 per evaluation and $1,000 in monthly credits. Socure Enterprise is priced through sales source
  • The sandbox allows 10 requests a second and 1,000 a day for each endpoint and method. Production starts at 0 requests a second until Socure Support activates it source
  • The MCP server has nine tools for docs, use cases, workflows, test cases and webhook configuration. Its docs say it does not execute evaluations or read results source
  • status.socure.com lists 13 incidents between 14 July and 22 September 2026, all marked minor or none, the longest an eCBSV latency incident of about 21 hours that Socure attributes to the Social Security Administration source
  • The Global Services Privacy Notice, effective 1 October 2026, gives maximum retention periods of up to seven years and says identity documents and images may be used to train and test machine learning models source
  • The OpenAPI file's description says the RiskOS documentation site is Socure confidential and proprietary information intended for authorised persons, while the same docs are served publicly with llms.txt and Content-Signal: ai-input=yes source
  • www.socure.com/.well-known/security.txt names security@socure.com and expired on 15 July 2026. The security page sends vulnerability reports to a disclosure programme hosted by Bugcrowd source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 15.0
Read with the hosted lines and scored on the Evaluation API. status.socure.com is a Statuspage site with RiskOS and each product as components and history back to December 2025 (20). It lists 13 incidents between 14 July and 22 September 2026, all marked minor or none. Most are short latency or error-rate events on single products, such as 5xx errors on fraud, KYC and watchlist for 20 minutes on 9 September, and one is an eCBSV latency incident of about 21 hours on 2 and 3 September that Socure attributes to the Social Security Administration (20 of 30). Limits have numbers, 10 requests a second and 1,000 a day per endpoint and method in the sandbox, 1 evaluation a second and 500 a day on Socure Launch, and a per-account figure in production (15). 429 responses carry X-Retry-After, and the docs give a backoff pattern with jitter. The same page advises idempotency keys, but no idempotency header is defined in the docs or the OpenAPI file (10 of 15). The trust centre says service levels are set in each customer's contract, and no SLA is published (0). The API is generally available under version 2025-01-01.orion (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.7
An OpenAPI 3.0.3 file for ten operations and a 3.1 file for the webhook payload are public on GitHub and embedded in each reference page (25). llms.txt for the site, the project and each section, and every page as Markdown by adding .md (10). Operation descriptions are short, from 76 to 689 characters, while the guides for each solution say when to choose it and which integration path it supports (12 of 20). The file has 39 enums and 47 required lists, but the evaluation request body declares no required fields at the top level, 20 schemas allow arbitrary properties, and the request and response schemas for each enrichment are in the dashboard, not the public file. Reason code and signal documentation moved to the dashboard in February 2026 (8 of 15). The file carries 357 example values, each operation documents its 4xx and 5xx responses, and the errors page lists 15 codes with sample bodies (14 of 15). An X-API-Version header pins the version, and dated release notes are public (15).
Agent ergonomics 13%16.2 7.5
Scored on the REST API. Evaluation responses nest every enrichment result under data_enrichments, and the only size control is include_input, which is off by default. The MCP server has nine compact tools, though none runs an evaluation (10 of 25). No endpoint lists or searches evaluations, so a caller needs the eval_id. The reason code catalogue filters by product, name, text and active status (6 of 20). Errors come with one of 15 codes, field-level invalid_args and a list of which statuses to retry, though some legacy endpoints omit code (18 of 20). No idempotency header is documented. Completed evaluations are immutable, webhook receivers can dedupe on event_id, and the MCP tool annotations could not be read without a key (6 of 20). A request needs only id, timestamp, workflow and data. The official SDKs are client-side capture and device libraries for web, iOS, Android and React Native, with no server-side SDK found (6 of 15).
Security & auth 14%17.5 10.5
Bearer API keys are separate for sandbox and production and can be regenerated with an overlap period, and the MCP server takes its own key. Each key reaches every workflow with no scopes, and an additional key is requested from Support. Optional mutual TLS, an IP allowlist and JWE payload encryption add network and transport controls (22 of 30). No read-only key or per-endpoint permission exists. The MCP key cannot read results or run evaluations but can create and change webhooks, and dashboard roles include a Developer role with no access to personal data (8 of 20). Responses carry end-user input, document extractions and adverse media. The MCP page tells users to treat AI output as advisory and keep keys out of prompts, with no guidance on untrusted content in responses (4 of 15). The dashboard has audit logs for account and workflow changes and CSV compliance reports. No API request log was found (9 of 15). SOC 2 Type 2, ISO/IEC 27001:2022, 27017, 27018 and 27701, FedRAMP Moderate, and a disclosure programme hosted by Bugcrowd. security.txt expired on 15 July 2026, and no public advisories or bounty terms were found (17 of 20).
Payments & pricing 10%12.5 4.4
Read with the hosted rubric. No x402, MPP or L402 (0). The pricing page publishes four Socure Launch solutions at $0.80, $0.90, $1.00 and $1.30 per evaluation without a login. Enterprise prices come from sales (20). The sandbox is free and Launch accounts receive $1,000 in production credits a month. We could not read the sign-up flow to confirm that no card is asked for, so this line is scored short of full (15 of 20). A person signs up in a browser, and production stays at 0 requests a second until Socure activates it (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.6
The latest release note is dated 6 October 2026 (30). More than 20 dated entries since 10 July 2026, among them 5 October, 29 September and 22 September (20). A closed service with public release notes and an email subscription, email support, chat for Launch accounts and a support department the go-live checklist describes as 24/7. We did not test a channel (10 of 15). @socure-inc/device-risk-sdk reached 2.11.0 on 1 September 2026 and the DocV SDKs are at v5, all client-side. No server-side SDK and no MCP registry entry were found (10 of 15). The public spec repository was synced on 21 separate days since 10 July, most recently on 5 October. No CI is visible, and the integration skill repository was last changed on 23 February 2026 (5 of 10).
Transparency & trusteditorial 53, provenance 82 7%8.8 6.0
The service is closed, and no service agreement or API terms are published. The terms page is the Website Terms of Use, the trust centre hides its terms entry, and the OpenAPI file calls the docs confidential while they are served publicly (5 of 30). The Global Services Privacy Notice, effective 1 October 2026, separates Socure's controller and processor roles and gives maximum retention periods, up to seven years for most categories and one to three years for others. It says documents and images may be used to train and test models, and the go-live checklist says customer retention is set by contract. No DPA is public, and the trust centre still cites the 19 June 2026 version of the notice (20 of 30). SDK versions have a written end-of-support policy with dates, and the removal of password sign-in for the MCP server on 21 July 2026 and new source addresses after 31 August 2026 were announced with dates. No deprecation policy for API versions was found (13 of 20). The trust centre names Amazon Web Services in US East, Google Cloud for RiskOS and Snowflake, all in the United States, and the privacy notice adds service providers in the Philippines and staff access from India, the United Kingdom and Europe (15 of 20).
Negative events≤15None recorded0
Total63.5 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 19 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Socure RiskOS, or have the agent fetch /fixes/socure-riskos.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Socure RiskOS

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/socure-riskos, the October 2026 research run, assessed 8 October 2026. Grade B, 63.5 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Socure RiskOS: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Agent ergonomics, 46 out of 100, up to 8.8 more on the total

Why it scored 46: Scored on the REST API. Evaluation responses nest every enrichment result under `data_enrichments`, and the only size control is `include_input`, which is off by default. The MCP server has nine compact tools, though none runs an evaluation (10 of 25). No endpoint lists or searches evaluations, so a caller needs the `eval_id`. The reason code catalogue filters by product, name, text and active status (6 of 20). Errors come with one of 15 codes, field-level `invalid_args` and a list of which statuses to retry, though some legacy endpoints omit `code` (18 of 20). No idempotency header is documented. Completed evaluations are immutable, webhook receivers can dedupe on `event_id`, and the MCP tool annotations could not be read without a key (6 of 20). A request needs only `id`, `timestamp`, `workflow` and `data`. The official SDKs are client-side capture and device libraries for web, iOS, Android and React Native, with no server-side SDK found (6 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 2. Payments & pricing, 35 out of 100, up to 8.1 more on the total

Why it scored 35: Read with the hosted rubric. No x402, MPP or L402 (0). The pricing page publishes four Socure Launch solutions at $0.80, $0.90, $1.00 and $1.30 per evaluation without a login. Enterprise prices come from sales (20). The sandbox is free and Launch accounts receive $1,000 in production credits a month. We could not read the sign-up flow to confirm that no card is asked for, so this line is scored short of full (15 of 20). A person signs up in a browser, and production stays at 0 requests a second until Socure activates it (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Security & auth, 60 out of 100, up to 7 more on the total

Why it scored 60: Bearer API keys are separate for sandbox and production and can be regenerated with an overlap period, and the MCP server takes its own key. Each key reaches every workflow with no scopes, and an additional key is requested from Support. Optional mutual TLS, an IP allowlist and JWE payload encryption add network and transport controls (22 of 30). No read-only key or per-endpoint permission exists. The MCP key cannot read results or run evaluations but can create and change webhooks, and dashboard roles include a Developer role with no access to personal data (8 of 20). Responses carry end-user input, document extractions and adverse media. The MCP page tells users to treat AI output as advisory and keep keys out of prompts, with no guidance on untrusted content in responses (4 of 15). The dashboard has audit logs for account and workflow changes and CSV compliance reports. No API request log was found (9 of 15). SOC 2 Type 2, ISO/IEC 27001:2022, 27017, 27018 and 27701, FedRAMP Moderate, and a disclosure programme hosted by Bugcrowd. security.txt expired on 15 July 2026, and no public advisories or bounty terms were found (17 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Reliability, 75 out of 100, up to 5 more on the total

Why it scored 75: Read with the hosted lines and scored on the Evaluation API. status.socure.com is a Statuspage site with RiskOS and each product as components and history back to December 2025 (20). It lists 13 incidents between 14 July and 22 September 2026, all marked minor or none. Most are short latency or error-rate events on single products, such as 5xx errors on fraud, KYC and watchlist for 20 minutes on 9 September, and one is an eCBSV latency incident of about 21 hours on 2 and 3 September that Socure attributes to the Social Security Administration (20 of 30). Limits have numbers, 10 requests a second and 1,000 a day per endpoint and method in the sandbox, 1 evaluation a second and 500 a day on Socure Launch, and a per-account figure in production (15). 429 responses carry `X-Retry-After`, and the docs give a backoff pattern with jitter. The same page advises idempotency keys, but no idempotency header is defined in the docs or the OpenAPI file (10 of 15). The trust centre says service levels are set in each customer's contract, and no SLA is published (0). The API is generally available under version 2025-01-01.orion (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 5. Transparency & trust, 68 out of 100, up to 2.8 more on the total

Made of editorial 53, provenance 82.

Why it scored 68: The service is closed, and no service agreement or API terms are published. The terms page is the Website Terms of Use, the trust centre hides its terms entry, and the OpenAPI file calls the docs confidential while they are served publicly (5 of 30). The Global Services Privacy Notice, effective 1 October 2026, separates Socure's controller and processor roles and gives maximum retention periods, up to seven years for most categories and one to three years for others. It says documents and images may be used to train and test models, and the go-live checklist says customer retention is set by contract. No DPA is public, and the trust centre still cites the 19 June 2026 version of the notice (20 of 30). SDK versions have a written end-of-support policy with dates, and the removal of password sign-in for the MCP server on 21 July 2026 and new source addresses after 31 August 2026 were announced with dates. No deprecation policy for API versions was found (13 of 20). The trust centre names Amazon Web Services in US East, Google Cloud for RiskOS and Snowflake, all in the United States, and the privacy notice adds service providers in the Philippines and staff access from India, the United Kingdom and Europe (15 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: not found (0 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects, and has 1 clause that costs points (7.3 of 10)
- security.txt: published but past its Expires date (5 of 10)

## 6. Schema & documentation, 84 out of 100, up to 2.6 more on the total

Why it scored 84: An OpenAPI 3.0.3 file for ten operations and a 3.1 file for the webhook payload are public on GitHub and embedded in each reference page (25). llms.txt for the site, the project and each section, and every page as Markdown by adding `.md` (10). Operation descriptions are short, from 76 to 689 characters, while the guides for each solution say when to choose it and which integration path it supports (12 of 20). The file has 39 enums and 47 required lists, but the evaluation request body declares no required fields at the top level, 20 schemas allow arbitrary properties, and the request and response schemas for each enrichment are in the dashboard, not the public file. Reason code and signal documentation moved to the dashboard in February 2026 (8 of 15). The file carries 357 example values, each operation documents its 4xx and 5xx responses, and the errors page lists 15 codes with sample bodies (14 of 15). An `X-API-Version` header pins the version, and dated release notes are public (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 7. Maintenance & community, 75 out of 100, up to 2.2 more on the total

Why it scored 75: The latest release note is dated 6 October 2026 (30). More than 20 dated entries since 10 July 2026, among them 5 October, 29 September and 22 September (20). A closed service with public release notes and an email subscription, email support, chat for Launch accounts and a support department the go-live checklist describes as 24/7. We did not test a channel (10 of 15). `@socure-inc/device-risk-sdk` reached 2.11.0 on 1 September 2026 and the DocV SDKs are at v5, all client-side. No server-side SDK and no MCP registry entry were found (10 of 15). The public spec repository was synced on 21 separate days since 10 July, most recently on 5 October. No CI is visible, and the integration skill repository was last changed on 23 February 2026 (5 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the sign-up flow at riskos.sandbox.socure.com, whose robots.txt disallows every path, so whether a card or business verification is asked for at sign-up or before production is not established
- unchecked: the MCP server's tool definitions, input schemas and annotations, which need an MCP Server Key
- unchecked: the Enrichment API Reference, reason codes and signal definitions, which are in the dashboard
- unchecked: GitHub star counts and any SDK source repositories beyond the two cloned
- No service agreement, API terms, DPA or SLA is published, so `provenance.terms` is left out
- The Launch FAQ says the sandbox has no limit, while the rate limit page gives 1,000 requests a day
- The lead described the MCP server as an interface to the product. It reads docs and account configuration and manages webhooks, and cannot run or read evaluations
- The Website Terms of Use forbid robots or other automatic software from monitoring or copying the website without written permission, while robots.txt on both sites allows crawling. Recorded as a fact
- Socure also runs ID+ and a separate government cloud, each with its own docs. Neither was graded here

## Weaknesses

- No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture
- Each API key reaches every workflow, with no scopes or read-only keys, and an additional key has to be requested from Support
- The rate limit page advises idempotency keys, but neither the docs nor the OpenAPI file define an idempotency header
- No endpoint lists or searches evaluations. A caller needs the `eval_id` from the original response or a webhook
- Enrichment request and response schemas, reason codes and signal definitions sit in the dashboard, not in the public docs
- Production starts at 0 requests a second until Socure approves it, and Launch accounts are capped at 1 evaluation a second and 500 a day

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send `Authorization: Bearer <key>` to `https://riskos.sandbox.socure.com/api/evaluation` for tests and `https://riskos.socure.com/api/evaluation` for live checks. The two environments use separate keys.
- Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values.
- Store the `eval_id` from every `POST /api/evaluation` response. No list or search endpoint exists to find it later.
- On 429 wait the seconds given in `X-Retry-After`. Do not blindly resend a failed `POST /api/evaluation`, because no idempotency header is documented and Launch bills each initiated evaluation.
- The MCP server at `https://mcp.riskos.socure.com/sandbox` reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results.

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the sign-up flow at riskos.sandbox.socure.com, whose robots.txt disallows every path, so whether a card or business verification is asked for at sign-up or before production is not established
  • unchecked: the MCP server's tool definitions, input schemas and annotations, which need an MCP Server Key
  • unchecked: the Enrichment API Reference, reason codes and signal definitions, which are in the dashboard
  • unchecked: GitHub star counts and any SDK source repositories beyond the two cloned
  • No service agreement, API terms, DPA or SLA is published, so provenance.terms is left out
  • The Launch FAQ says the sandbox has no limit, while the rate limit page gives 1,000 requests a day
  • The lead described the MCP server as an interface to the product. It reads docs and account configuration and manages webhooks, and cannot run or read evaluations
  • The Website Terms of Use forbid robots or other automatic software from monitoring or copying the website without written permission, while robots.txt on both sites allows crawling. Recorded as a fact
  • Socure also runs ID+ and a separate government cloud, each with its own docs. Neither was graded here

Sources 26

  1. docs index for agents help.socure.com · seen 2026-10-08
  2. authentication and API keys help.socure.com · seen 2026-10-08
  3. API and SDK key management help.socure.com · seen 2026-10-08
  4. rate limits and 429 handling help.socure.com · seen 2026-10-08
  5. error codes help.socure.com · seen 2026-10-08
  6. evaluation reference with embedded OpenAPI definition help.socure.com · seen 2026-10-08
  7. OpenAPI files (shallow clone, last commit 5 October 2026) github.com · seen 2026-10-08
  8. MCP server help.socure.com · seen 2026-10-08
  9. integration skill repository (shallow clone) github.com · seen 2026-10-08
  10. sandbox and production environments help.socure.com · seen 2026-10-08
  11. Socure Launch overview and FAQs help.socure.com · seen 2026-10-08
  12. webhook configuration help.socure.com · seen 2026-10-08
  13. go-live checklist help.socure.com · seen 2026-10-08
  14. SDK release and maintenance policy help.socure.com · seen 2026-10-08
  15. release notes help.socure.com · seen 2026-10-08
  16. pricing socure.com · seen 2026-10-08
  17. Global Services Privacy Notice socure.com · seen 2026-10-08
  18. policies index socure.com · seen 2026-10-08
  19. Website Terms of Use socure.com · seen 2026-10-08
  20. security page socure.com · seen 2026-10-08
  21. trust centre (certifications, sub-processors, SLA statement) trust.socure.com · seen 2026-10-08
  22. status incidents feed status.socure.com · seen 2026-10-08
  23. security.txt socure.com · seen 2026-10-08
  24. robots.txt with Content-Signal help.socure.com · seen 2026-10-08
  25. npm package registry.npmjs.org · seen 2026-10-08
  26. domain registration rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use $0.80 / tx Socure Launch charges per evaluation started in production, at $0.80 for document verification, $0.90 with watchlist screening, $1.00 for KYC, fraud and watchlist with a document step-up, and $1.30 with prefill. Launch accounts receive $1,000 in production credits each month. The sandbox is free, so an agent can build and test without a contract, but it returns predefined results. Evaluations an end user abandons are still charged. Socure Enterprise is priced through sales. Whether sign-up or the move to production asks for a card was not established (checked 2026-10-08).

Prices

ItemPriceUnitNote
Socure Launch, Document Verification (DocV)$0.80per transactionPer evaluation started in production, after $1,000 of monthly credits
Socure Launch, DocV + Watchlist$0.90per transactionPer evaluation started in production
Socure Launch, KYC + Fraud + Watchlist with DocV step-up$1per transactionPer evaluation started in production
Socure Launch, Prefill, KYC + Fraud + Watchlist with DocV step-up$1.30per transactionPer evaluation started in production

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/socure-riskos.xml, or this listing's score history at history.json.

Connect

First request

curl --request POST \
  --url "https://riskos.sandbox.socure.com/api/evaluation" \
  --header "Authorization: Bearer YOUR_API_KEY" \
  --header "Content-Type: application/json" \
  --header "Accept: application/json" \
  --data '{"id":"customer-onb-12345","timestamp":"2024-12-01T08:15:30.456Z","workflow":"consumer_onboarding","data":{"individual":{"given_name":"Jane","family_name":"Doe","email":"jane.doe@example.com","phone_number":"+1-555-123-4567","address":{"line_1":"123 Main St","locality":"San Francisco","major_admin_division":"CA","postal_code":"94105","country":"US"}}}}'

Claude Code

claude mcp add --transport http socure-dev-assist https://mcp.riskos.socure.com/sandbox --header "Authorization: Bearer $RISKOS_MCP_KEY"

MCP client configuration

{
  "mcpServers": {
    "socure-dev-assist": {
      "args": [
        "-y",
        "mcp-remote",
        "https://mcp.riskos.socure.com/sandbox",
        "--header",
        "Authorization: Bearer YOUR_MCP_SERVER_KEY"
      ],
      "command": "npx"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/socure-riskos

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Didit Didit Identity Spain, S.L.BB75kyc.identity kyc.documents kyc.screening kyc.business kyc.casesno
Persona Persona Identities, Inc.B69.5kyc.identity kyc.business kyc.documents kyc.screening kyc.casesno
Sumsub Sum and Substance LtdB68.5kyc.identity kyc.business kyc.documents kyc.screening kyc.casesno
ComplyCube ComplyCube (Teemo Technology Ltd)B63.7kyc.identity kyc.documents kyc.screening kyc.businessno
Middesk Middesk, Inc.C59kyc.business kyc.screening kyc.cases kyc.identityno
Trulioo Trulioo Information Services Inc.C58.2kyc.identity kyc.business kyc.documents kyc.screeningno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Socure RiskOS on Anchor Terminal, B, 63.5/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/socure-riskos"><img src="https://www.anchorterminal.com/badges/socure-riskos.svg" alt="Socure RiskOS on Anchor Terminal" height="20"></a>
    [![Socure RiskOS on Anchor Terminal](https://www.anchorterminal.com/badges/socure-riskos.svg)](https://www.anchorterminal.com/tools/socure-riskos)

    It counts on a page on socure.com or one of its subdomains, or the README of github.com/socure-inc/.github.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "socure-riskos", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.