# Socure RiskOS > Socure RiskOS is an identity verification and risk decisioning platform from Socure Inc. Its Evaluation API runs configured workflows for KYC, document and selfie checks, fraud scoring and watchlist screening, and returns a decision with reason codes. - Canonical: https://www.anchorterminal.com/tools/socure-riskos - Markdown: https://www.anchorterminal.com/tools/socure-riskos.md (~8,500 tokens) - Slim: https://www.anchorterminal.com/tools/socure-riskos.min.md (~2,230 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/socure-riskos.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 63.5/100 · rank #357 of 842 · #5 in Identity & business verification · not agent-ready · confidence medium** ## Assessment A public OpenAPI file, llms.txt, 15 documented error codes and dated release notes cover a ten-operation REST API, and Socure Launch publishes prices from $0.80 an evaluation with a free sandbox. API keys carry no scopes, no idempotency header is defined, no service terms are published, and production stays at zero requests until Socure activates it. ## Facts | Field | Value | | --- | --- | | Vendor | Socure Inc. (https://www.socure.com) | | Kind | HTTP API | | Category | Identity & business verification (https://www.anchorterminal.com/categories/identity-verification) | | Transport | HTTP | | Endpoint | `https://mcp.riskos.socure.com/sandbox` | | Auth | API key · Self-serve API key for the sandbox, sent as `Authorization: Bearer `. A person signs up in a browser for a Socure Launch sandbox account and copies the key from the Developer Workbench. Sandbox and production use separate keys and hosts. Production starts at 0 requests a second and needs Socure Support to activate it, and Enterprise accounts go through sandbox certification with Socure staff. Each key reaches every workflow, with no scopes. Regenerating a key keeps the old one working until it is deleted, and an additional key is requested from Support. The MCP server takes its own MCP Server Key. IP allowlisting, mutual TLS and payload encryption are optional (checked 2026-10-08). | | Pricing | Pay per use ($0.80 / tx) · Socure Launch charges per evaluation started in production, at $0.80 for document verification, $0.90 with watchlist screening, $1.00 for KYC, fraud and watchlist with a document step-up, and $1.30 with prefill. Launch accounts receive $1,000 in production credits each month. The sandbox is free, so an agent can build and test without a contract, but it returns predefined results. Evaluations an end user abandons are still charged. Socure Enterprise is priced through sales. Whether sign-up or the move to production asks for a card was not established (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the API reference, the OpenAPI file, the MCP server page or the pricing page (checked 2026-10-08). | | Licence | Proprietary service. No service agreement is published, and the OpenAPI file states its licence as Proprietary | | Tools exposed | 9 | | Packages | npm: `@socure-inc/device-risk-sdk` | | Source | https://github.com/socure-inc/.github | | Docs | https://help.socure.com/riskos/docs | | llms.txt | https://help.socure.com/riskos/llms.txt | | Last release | 2026-10-06 | | npm downloads / week | 35,395 | | API | REST with JSON at https://riskos.socure.com (production) and https://riskos.sandbox.socure.com (sandbox). OpenAPI 3.0.3, version 2025-01-01.orion, ten operations (4 POST, 3 GET, 2 PUT, 1 PATCH). An optional `X-API-Version` header pins the version | | Checks | Workflows combine Socure Verify (KYC), Predictive DocV (government ID and selfie), Sigma identity, synthetic and first-party fraud scores, email, phone and address risk, device intelligence, global watchlist screening with daily monitoring, eCBSV, deceased check, bank account verification and business onboarding | | Integration paths | Direct API, synchronous or asynchronous with webhooks, or a Socure-hosted flow that returns results by webhook. Decisions are `ACCEPT`, `REVIEW` or `REJECT` by default | | MCP server | Hosted over HTTP at https://mcp.riskos.socure.com/sandbox and /prod with an MCP Server Key as bearer token. Nine tools (`ask_docs`, `add_webhook`, `update_webhook`, `list_webhooks`, `list_events`, `list_testcases`, `list_usecases`, `list_workflows`, `integration_checklist`), two prompts and one OpenAPI resource. It runs no evaluations | | Credentials | Bearer API keys per environment, regenerated in the dashboard with the old key working until deleted. Each key reaches all workflows. Separate MCP, SDK and Okta keys. Optional IP allowlist, mutual TLS and JWE payload encryption | | Rate limits | Sandbox 10 requests a second and 1,000 a day per endpoint and method. Socure Launch 1 evaluation a second and 500 a day. Production 0 until activated, then set per account. Headers `X-RateLimit-Limit-Day`, `X-RateLimit-Limit-Window` and `X-Retry-After` on 429 | | Errors | JSON with `error`, `code`, optional `message`, `details` and `invalid_args`. 15 documented codes from `INVALID_REQUEST` to `BAD_GATEWAY`. Some legacy endpoints omit `code` | | Webhooks | Events such as `evaluation_completed` and `decision_update`, authenticated by Basic, bearer token or OAuth 2.0 client credentials. Up to 10 attempts with backoff capped at 60 seconds. Receivers dedupe on `event_id` | | SDKs | Client-side only. Digital Intelligence and Predictive DocV SDKs for web, iOS, Android and React Native. `@socure-inc/device-risk-sdk` 2.11.0 on npm (1 September 2026). No server-side SDK found | | Audit | Dashboard audit logs for account and workflow changes, and compliance reports exported as CSV. No API request log was found in the docs | | Certifications | SOC 2 Type 2, ISO/IEC 27001:2022, 27017:2015, 27018:2025 and 27701:2025, FedRAMP Moderate and TX-RAMP Level 2 per trust.socure.com and the security page | | Status | status.socure.com on Statuspage, with RiskOS and each product as components and incident history back to December 2025 | | Sub-processors | Amazon Web Services (US East), Google Cloud for RiskOS (United States) and Snowflake (United States) per trust.socure.com. The privacy notice also names service providers in the Philippines and staff access from India, the United Kingdom and Europe | | Capabilities | kyc.identity, kyc.documents, kyc.screening, kyc.business, kyc.cases | | Tags | hosted, usage, sandbox, api-key, mcp, openapi, llms-txt, webhooks, status-page, soc2, iso27001, fedramp | | JSON | https://www.anchorterminal.com/api/v1/tools/socure-riskos.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 75 | 15.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 84 | 13.7 | | Agent ergonomics | 13% | 16.2 | 46 | 7.5 | | Security & auth | 14% | 17.5 | 60 | 10.5 | | Payments & pricing | 10% | 12.5 | 35 | 4.4 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 75 | 6.6 | | Transparency & trust (editorial 53, provenance 82) | 7% | 8.8 | 68 | 6.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **63.5 → B** | ### Why each score - Reliability 75: Read with the hosted lines and scored on the Evaluation API. status.socure.com is a Statuspage site with RiskOS and each product as components and history back to December 2025 (20). It lists 13 incidents between 14 July and 22 September 2026, all marked minor or none. Most are short latency or error-rate events on single products, such as 5xx errors on fraud, KYC and watchlist for 20 minutes on 9 September, and one is an eCBSV latency incident of about 21 hours on 2 and 3 September that Socure attributes to the Social Security Administration (20 of 30). Limits have numbers, 10 requests a second and 1,000 a day per endpoint and method in the sandbox, 1 evaluation a second and 500 a day on Socure Launch, and a per-account figure in production (15). 429 responses carry `X-Retry-After`, and the docs give a backoff pattern with jitter. The same page advises idempotency keys, but no idempotency header is defined in the docs or the OpenAPI file (10 of 15). The trust centre says service levels are set in each customer's contract, and no SLA is published (0). The API is generally available under version 2025-01-01.orion (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 84: An OpenAPI 3.0.3 file for ten operations and a 3.1 file for the webhook payload are public on GitHub and embedded in each reference page (25). llms.txt for the site, the project and each section, and every page as Markdown by adding `.md` (10). Operation descriptions are short, from 76 to 689 characters, while the guides for each solution say when to choose it and which integration path it supports (12 of 20). The file has 39 enums and 47 required lists, but the evaluation request body declares no required fields at the top level, 20 schemas allow arbitrary properties, and the request and response schemas for each enrichment are in the dashboard, not the public file. Reason code and signal documentation moved to the dashboard in February 2026 (8 of 15). The file carries 357 example values, each operation documents its 4xx and 5xx responses, and the errors page lists 15 codes with sample bodies (14 of 15). An `X-API-Version` header pins the version, and dated release notes are public (15). - Agent ergonomics 46: Scored on the REST API. Evaluation responses nest every enrichment result under `data_enrichments`, and the only size control is `include_input`, which is off by default. The MCP server has nine compact tools, though none runs an evaluation (10 of 25). No endpoint lists or searches evaluations, so a caller needs the `eval_id`. The reason code catalogue filters by product, name, text and active status (6 of 20). Errors come with one of 15 codes, field-level `invalid_args` and a list of which statuses to retry, though some legacy endpoints omit `code` (18 of 20). No idempotency header is documented. Completed evaluations are immutable, webhook receivers can dedupe on `event_id`, and the MCP tool annotations could not be read without a key (6 of 20). A request needs only `id`, `timestamp`, `workflow` and `data`. The official SDKs are client-side capture and device libraries for web, iOS, Android and React Native, with no server-side SDK found (6 of 15). - Security & auth 60: Bearer API keys are separate for sandbox and production and can be regenerated with an overlap period, and the MCP server takes its own key. Each key reaches every workflow with no scopes, and an additional key is requested from Support. Optional mutual TLS, an IP allowlist and JWE payload encryption add network and transport controls (22 of 30). No read-only key or per-endpoint permission exists. The MCP key cannot read results or run evaluations but can create and change webhooks, and dashboard roles include a Developer role with no access to personal data (8 of 20). Responses carry end-user input, document extractions and adverse media. The MCP page tells users to treat AI output as advisory and keep keys out of prompts, with no guidance on untrusted content in responses (4 of 15). The dashboard has audit logs for account and workflow changes and CSV compliance reports. No API request log was found (9 of 15). SOC 2 Type 2, ISO/IEC 27001:2022, 27017, 27018 and 27701, FedRAMP Moderate, and a disclosure programme hosted by Bugcrowd. security.txt expired on 15 July 2026, and no public advisories or bounty terms were found (17 of 20). - Payments & pricing 35: Read with the hosted rubric. No x402, MPP or L402 (0). The pricing page publishes four Socure Launch solutions at $0.80, $0.90, $1.00 and $1.30 per evaluation without a login. Enterprise prices come from sales (20). The sandbox is free and Launch accounts receive $1,000 in production credits a month. We could not read the sign-up flow to confirm that no card is asked for, so this line is scored short of full (15 of 20). A person signs up in a browser, and production stays at 0 requests a second until Socure activates it (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 75: The latest release note is dated 6 October 2026 (30). More than 20 dated entries since 10 July 2026, among them 5 October, 29 September and 22 September (20). A closed service with public release notes and an email subscription, email support, chat for Launch accounts and a support department the go-live checklist describes as 24/7. We did not test a channel (10 of 15). `@socure-inc/device-risk-sdk` reached 2.11.0 on 1 September 2026 and the DocV SDKs are at v5, all client-side. No server-side SDK and no MCP registry entry were found (10 of 15). The public spec repository was synced on 21 separate days since 10 July, most recently on 5 October. No CI is visible, and the integration skill repository was last changed on 23 February 2026 (5 of 10). - Transparency & trust 68: The service is closed, and no service agreement or API terms are published. The terms page is the Website Terms of Use, the trust centre hides its terms entry, and the OpenAPI file calls the docs confidential while they are served publicly (5 of 30). The Global Services Privacy Notice, effective 1 October 2026, separates Socure's controller and processor roles and gives maximum retention periods, up to seven years for most categories and one to three years for others. It says documents and images may be used to train and test models, and the go-live checklist says customer retention is set by contract. No DPA is public, and the trust centre still cites the 19 June 2026 version of the notice (20 of 30). SDK versions have a written end-of-support policy with dates, and the removal of password sign-in for the MCP server on 21 July 2026 and new source addresses after 31 August 2026 were announced with dates. No deprecation policy for API versions was found (13 of 20). The trust centre names Amazon Web Services in US East, Google Cloud for RiskOS and Snowflake, all in the United States, and the privacy notice adds service providers in the Philippines and staff access from India, the United Kingdom and Europe (15 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/socure-riskos.md (JSON https://www.anchorterminal.com/fixes/socure-riskos.json) ### What we couldn't check - unchecked: the sign-up flow at riskos.sandbox.socure.com, whose robots.txt disallows every path, so whether a card or business verification is asked for at sign-up or before production is not established - unchecked: the MCP server's tool definitions, input schemas and annotations, which need an MCP Server Key - unchecked: the Enrichment API Reference, reason codes and signal definitions, which are in the dashboard - unchecked: GitHub star counts and any SDK source repositories beyond the two cloned - No service agreement, API terms, DPA or SLA is published, so `provenance.terms` is left out - The Launch FAQ says the sandbox has no limit, while the rate limit page gives 1,000 requests a day - The lead described the MCP server as an interface to the product. It reads docs and account configuration and manages webhooks, and cannot run or read evaluations - The Website Terms of Use forbid robots or other automatic software from monitoring or copying the website without written permission, while robots.txt on both sites allows crawling. Recorded as a fact - Socure also runs ID+ and a separate government cloud, each with its own docs. Neither was graded here ### Sources - docs index for agents: (seen 2026-10-08) - authentication and API keys: (seen 2026-10-08) - API and SDK key management: (seen 2026-10-08) - rate limits and 429 handling: (seen 2026-10-08) - error codes: (seen 2026-10-08) - evaluation reference with embedded OpenAPI definition: (seen 2026-10-08) - OpenAPI files (shallow clone, last commit 5 October 2026): (seen 2026-10-08) - MCP server: (seen 2026-10-08) - integration skill repository (shallow clone): (seen 2026-10-08) - sandbox and production environments: (seen 2026-10-08) - Socure Launch overview and FAQs: (seen 2026-10-08) - webhook configuration: (seen 2026-10-08) - go-live checklist: (seen 2026-10-08) - SDK release and maintenance policy: (seen 2026-10-08) - release notes: (seen 2026-10-08) - pricing: (seen 2026-10-08) - Global Services Privacy Notice: (seen 2026-10-08) - policies index: (seen 2026-10-08) - Website Terms of Use: (seen 2026-10-08) - security page: (seen 2026-10-08) - trust centre (certifications, sub-processors, SLA statement): (seen 2026-10-08) - status incidents feed: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - robots.txt with Content-Signal: (seen 2026-10-08) - npm package: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 82/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Socure Inc. | 20/20 | | Domain age | socure.com, registered 2003-06-20 (23 years) | 15/15 | | Endpoint on the vendor's domain | mcp.riskos.socure.com | 15/15 | | Terms of service | not found | 0/10 | | Privacy policy | read, states 7 of the 8 things a reader expects, and has 1 clause that costs points | 7.3/10 | | Status page | status.socure.com | 10/10 | | Changelog | published | 10/10 | | security.txt | published but past its Expires date | 5/10 | The Global Services Privacy Notice (effective 1 October 2026) names Socure Inc. and covers the verification services. A separate Website Privacy Notice covers the marketing site. No service agreement or API terms are published. www.socure.com/terms-of-service is the Website Terms of Use, and the policies page lists only privacy notices, the DocV Terms of Use for end users and a text messaging notice, so the terms field is left out. The API answers at riskos.socure.com and riskos.sandbox.socure.com, and the MCP server at mcp.riskos.socure.com, all socure.com subdomains. www.socure.com/.well-known/security.txt gives security@socure.com and an `Expires` value of 15 July 2026, which has passed. RDAP for socure.com gives a registration date of 2003-06-20. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0. **Privacy policy** (https://www.socure.com/privacy-en), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "Identity documents and images may also be used to train and test machine learning models and to maintain a record of images linked to repeated fraudulent activity." - Not found in the text. Gives the date it was last updated. - Says how long data is kept. Names a period of 7 days. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@socure.com. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). Socure may reuse data from a customer's transactions, as a controller, to build fraud-detection insights across its whole customer base. "When processing transactions for a Customer, Socure both acts as a Processor for a transaction, and may separately use some of that same data, as a Controller, to build fraud-detection insights across our customer base (for example, spotting a pattern of fraud across many companies)." - Also in the text (2026-10-08). Socure classifies traffic as human, bot or AI agent, and may train its agent-classification and agent-trust models on the data it collects. "Where we develop agent-classification or agent-trust features, we may train those models using data collected." - Also in the text (2026-10-08). Where Socure detects signs of automated activity, it may collect device and browser signals from tabs or windows that are not in active use. "Where we detect signs of automated activity, we may also collect these signals from browser tabs or windows that are not actively in use, to assess whether that activity is automated." ## Live (updated 2026-10-09 10:42 UTC) - Right now: up, HTTP 403, 344 ms, checked 2026-10-09 10:42 UTC (get on `https://mcp.riskos.socure.com/sandbox`, asks for auth) - Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 334 ms · p95 397 ms - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/socure-riskos.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Socure Launch, Document Verification (DocV) | $0.80 | per transaction | Per evaluation started in production, after $1,000 of monthly credits | | Socure Launch, DocV + Watchlist | $0.90 | per transaction | Per evaluation started in production | | Socure Launch, KYC + Fraud + Watchlist with DocV step-up | $1 | per transaction | Per evaluation started in production | | Socure Launch, Prefill, KYC + Fraud + Watchlist with DocV step-up | $1.30 | per transaction | Per evaluation started in production | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - OpenAPI 3.0.3 file for ten operations and a 3.1 webhook file in a public GitHub repository, last synced 5 October 2026 - llms.txt indexes for every docs section and a Markdown copy of each page, with a robots.txt signal that allows AI input - Socure Launch publishes four solutions at $0.80 to $1.30 per evaluation, with a free sandbox and $1,000 of monthly production credits - Errors return one of 15 machine-readable codes with field-level `invalid_args`, and 429 responses carry `X-Retry-After` - Release notes show entries on 5 and 6 October 2026 and more than 20 dated entries since 10 July ## Weaknesses - No service agreement or API terms are published. The only terms pages are website terms of use and end-user terms for document capture - Each API key reaches every workflow, with no scopes or read-only keys, and an additional key has to be requested from Support - The rate limit page advises idempotency keys, but neither the docs nor the OpenAPI file define an idempotency header - No endpoint lists or searches evaluations. A caller needs the `eval_id` from the original response or a webhook - Enrichment request and response schemas, reason codes and signal definitions sit in the dashboard, not in the public docs - Production starts at 0 requests a second until Socure approves it, and Launch accounts are capped at 1 evaluation a second and 500 a day ## Before you call it (notes for agents) 1. Send `Authorization: Bearer ` to `https://riskos.sandbox.socure.com/api/evaluation` for tests and `https://riskos.socure.com/api/evaluation` for live checks. The two environments use separate keys. 2. Use dummy data only in the sandbox. It returns predefined results, connects to no live data source and expects the documented test values. 3. Store the `eval_id` from every `POST /api/evaluation` response. No list or search endpoint exists to find it later. 4. On 429 wait the seconds given in `X-Retry-After`. Do not blindly resend a failed `POST /api/evaluation`, because no idempotency header is documented and Launch bills each initiated evaluation. 5. The MCP server at `https://mcp.riskos.socure.com/sandbox` reads docs, workflows and webhooks with its own MCP Server Key. It cannot run evaluations or read results. ## Connect First request: ```bash curl --request POST \ --url "https://riskos.sandbox.socure.com/api/evaluation" \ --header "Authorization: Bearer YOUR_API_KEY" \ --header "Content-Type: application/json" \ --header "Accept: application/json" \ --data '{"id":"customer-onb-12345","timestamp":"2024-12-01T08:15:30.456Z","workflow":"consumer_onboarding","data":{"individual":{"given_name":"Jane","family_name":"Doe","email":"jane.doe@example.com","phone_number":"+1-555-123-4567","address":{"line_1":"123 Main St","locality":"San Francisco","major_admin_division":"CA","postal_code":"94105","country":"US"}}}}' ``` Claude Code: ```bash claude mcp add --transport http socure-dev-assist https://mcp.riskos.socure.com/sandbox --header "Authorization: Bearer $RISKOS_MCP_KEY" ``` MCP client configuration: ```json { "mcpServers": { "socure-dev-assist": { "args": [ "-y", "mcp-remote", "https://mcp.riskos.socure.com/sandbox", "--header", "Authorization: Bearer YOUR_MCP_SERVER_KEY" ], "command": "npx" } } } ``` Through letme (picks today, calling later): https://letme.dev/socure-riskos. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Didit | BB | 75 | 60 | kyc.identity, kyc.documents, kyc.screening, kyc.business, kyc.cases | no | https://www.anchorterminal.com/tools/didit.md | | Persona | B | 69.5 | 176 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/persona.md | | Sumsub | B | 68.5 | 200 | kyc.identity, kyc.business, kyc.documents, kyc.screening, kyc.cases | no | https://www.anchorterminal.com/tools/sumsub.md | | ComplyCube | B | 63.7 | 343 | kyc.identity, kyc.documents, kyc.screening, kyc.business | no | https://www.anchorterminal.com/tools/complycube.md | | Middesk | C | 59 | 509 | kyc.business, kyc.screening, kyc.cases, kyc.identity | no | https://www.anchorterminal.com/tools/middesk.md | | Trulioo | C | 58.2 | 530 | kyc.identity, kyc.business, kyc.documents, kyc.screening | no | https://www.anchorterminal.com/tools/trulioo.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The Evaluation API has ten operations under `/api`, among them `POST /api/evaluation`, `GET` and `PATCH /api/evaluation/{eval_id}`, a state update, a document download, watchlist monitoring, custom watchlist records, feedback and a reason code catalogue (source: ) - Socure Launch is the self-serve edition, with four prebuilt solutions priced at $0.80, $0.90, $1.00 and $1.30 per evaluation and $1,000 in monthly credits. Socure Enterprise is priced through sales (source: ) - The sandbox allows 10 requests a second and 1,000 a day for each endpoint and method. Production starts at 0 requests a second until Socure Support activates it (source: ) - The MCP server has nine tools for docs, use cases, workflows, test cases and webhook configuration. Its docs say it does not execute evaluations or read results (source: ) - status.socure.com lists 13 incidents between 14 July and 22 September 2026, all marked minor or none, the longest an eCBSV latency incident of about 21 hours that Socure attributes to the Social Security Administration (source: ) - The Global Services Privacy Notice, effective 1 October 2026, gives maximum retention periods of up to seven years and says identity documents and images may be used to train and test machine learning models (source: ) - The OpenAPI file's description says the RiskOS documentation site is Socure confidential and proprietary information intended for authorised persons, while the same docs are served publicly with llms.txt and `Content-Signal: ai-input=yes` (source: ) - www.socure.com/.well-known/security.txt names security@socure.com and expired on 15 July 2026. The security page sends vulnerability reports to a disclosure programme hosted by Bugcrowd (source: ) ## Compare - [ComplyCube vs Socure RiskOS](https://www.anchorterminal.com/compare/complycube-vs-socure-riskos.md): B 63.7 vs B 63.5 - [Didit vs Socure RiskOS](https://www.anchorterminal.com/compare/didit-vs-socure-riskos.md): BB 75 vs B 63.5 - [Jumio vs Socure RiskOS](https://www.anchorterminal.com/compare/jumio-vs-socure-riskos.md): C 55 vs B 63.5 - [Persona vs Socure RiskOS](https://www.anchorterminal.com/compare/persona-vs-socure-riskos.md): B 69.5 vs B 63.5 - [Shufti vs Socure RiskOS](https://www.anchorterminal.com/compare/shufti-vs-socure-riskos.md): C 57.8 vs B 63.5 - [Socure RiskOS vs Sumsub](https://www.anchorterminal.com/compare/socure-riskos-vs-sumsub.md): B 63.5 vs B 68.5 - [Socure RiskOS vs Trulioo](https://www.anchorterminal.com/compare/socure-riskos-vs-trulioo.md): B 63.5 vs C 58.2 - [Socure RiskOS vs Veriff](https://www.anchorterminal.com/compare/socure-riskos-vs-veriff.md): B 63.5 vs C 61.1 - [ComplyAdvantage vs Socure RiskOS](https://www.anchorterminal.com/compare/complyadvantage-vs-socure-riskos.md): D 52.6 vs B 63.5 - [Middesk vs Socure RiskOS](https://www.anchorterminal.com/compare/middesk-vs-socure-riskos.md): C 59 vs B 63.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on socure.com or one of its subdomains, or the README of github.com/socure-inc/.github. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "socure-riskos", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Socure RiskOS on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Socure RiskOS on Anchor Terminal](https://www.anchorterminal.com/badges/socure-riskos.svg)](https://www.anchorterminal.com/tools/socure-riskos) ``` Plain link: ```html Socure RiskOS on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Socure RiskOS is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/socure-riskos-dark.png - Light: https://www.anchorterminal.com/assets/share/socure-riskos-light.png