Audience: Organizations

The short answer: The Risk tab provides detailed fraud signal data for transactions — including identity, location, phone, email, and device information — to help you make informed decisions about a signer's legitimacy.

The information you have access to depends on your user role and your organization's subscription. The Risk tab is only available to customers with Defend enabled.


AI-Generated Risk Summary

At the top of the Risk tab, Defend generates a plain-language summary explaining why a transaction received its risk score. The summary includes:

  • A one-sentence risk score showing how the transaction compares to typical transactions
  • A short explanation of what drove the score and the type of fraud it may indicate
  • The most concerning risk signals, with an explanation of why each one matters
  • Positive signals that may indicate the signer is legitimate
  • A recommended next step, if any, based on the overall risk level

The summary isn't generated automatically. Select View Signals at the top of the Identity or Risk tab to generate it — allow a brief moment for it to load. 


Identity

The Identity section shows a summary of the verification methods used, including:

  • Identity Verification Methods
  • Selfie Comparison Results and Date
  • Identification

Open the Identity tab (left of the Risk tab) for more detailed information, such as the Identity Timeline.

Risk tab Identity section

Location

The Location section shows:

  • A map of the home address, with icons indicating the location of the home address and IP address
  • Last known IP address
  • Last known mobile location
  • Home address
  • Last known desktop location

Defend provides location information so you can make an informed decision about the identity and transaction. For example:

  • Location Mismatch: If a user claims to be in Florida but shows a location signal from an IP address in another country, that's worth investigating.
  • Device Reputation: Check if the device being used has been associated with multiple different user IDs recently, which could indicate a fraud farm or a compromised device.
Location information on the Risk tab

Meeting

The Meeting section provides a recording-level view of the recipient's session, including:

  • Meeting recording — a video of the recipient's session, along with a Deepfake risk score that indicates whether the video feed may have been tampered with.
  • Notary assessment (if applicable) — the notary's assessment of the signer during the meeting.
  • Device information — details about the device the recipient used to complete the transaction.
Meeting tab on the Risk tab showing deepfake risk score and meeting recording

Phone & Email

The Phone & Email section shows:

  • Email address
  • Matches identity
  • Phone number
  • Line type
  • Seen on network
  • Name of carrier
  • Email age
  • Last SIM swap

Use this section to spot red flags in the signer's contact information. A recent SIM swap or a brand-new email address, for example, may warrant a closer look.

Phone and email Risk tab

Device

The Device section surfaces device-level signals for any transaction — including those that are in-progress or previously executed. For each device used during the transaction, you can see:

  • Device fingerprint — the device type, model, and how recently it was first seen on Proof's network
  • Environment details — OS version, browser, screen resolution, and camera and audio hardware
  • Risk indicators — flags such as VPN usage, unusual hardware configurations, or mismatched device settings that may indicate spoofing or emulation

Devices are listed in order of most recently used (Device 1 through Device n). Each device also shows whether it is unique to the signer's identity on Proof's network, which can help you spot shared or suspicious devices across transactions.

A Risk Insights panel at the bottom of the section highlights any automatically detected anomalies — for example, if a device emulator is likely being used, which could indicate device spoofing.

💡
Device signals are available for both in-progress and previously executed transactions. This section is enabled by your CSM for organizations with Defend and is visible by default once the feature flag is turned on.
Device signals section in the Risk tab showing device fingerprint, environment details, and risk insights

Access the Risk tab

Risk assessments are available for transactions in Complete status. Device signals are also visible for in-progress transactions.

  1. Select Transactions from the navigation panel on the left.
  2. Find the desired transaction.
  3. Select the transaction name to open Transaction Details.
  4. Select the Risk tab at the top of the page to display the Defend data available for the transaction.
  5. Select View Signals to generate the AI risk summary for the transaction.

Summary Checklist

  • The Risk tab is only available to customers with Defend enabled.
  • Risk assessments appear for completed transactions; device signals are also visible for in-progress transactions.
  • The Risk tab contains identity, location, phone, email, and device signal information.
  • An AI-generated summary at the top of the tab explains the risk score, key signals, and a recommended next step.
  • Look for red flags like location mismatches, recent SIM swaps, new email addresses, VPN usage, or device emulation warnings.
  • Check the Risk Insights panel for automatically detected device anomalies.

Still Unsure?

Our support team is happy to help. Submit a support request or chat with us from any page in the app.


Updated

Was this article helpful?

0 out of 0 found this helpful