Skip to main content

Digital signals (v1)

Stable / GA

This is the current stable version of this step type.

Assesses trust signals from a user’s contact details​

Helps businesses identify suspicious or trustworthy behaviour based on email, phone, name, and IP data before the user continues with e.g. identity verification or electronic signature processes.


Key features​

  • Computes a trust score from email, phone, IP and name signals.
  • Routes flow using configurable thresholds: suspiciousUserThreshold and trustedUserThreshold.
  • Required inputSources to specify step IDs (basicIdentity, extendedIdentity, deviceSignals). Must cover at least 2 potential claims.
  • Produces DigitalSignals for trusted, suspicious, and not_trusted; inconclusive when no definitive assessment.

Configuration​

OptionTypeRequiredDescription
providerstringNoThe trust signals provider to use. Currently only TRUSTFULL is supported. Accepted values: TRUSTFULL.
suspiciousUserThresholdintegerYesThe score threshold (in percent) below which a user is considered "suspicious". Must be strictly less than trustedUserThreshold.
trustedUserThresholdintegerYesThe score threshold (in percent) above which a user is considered "trusted". Must be strictly greater than suspiciousUserThreshold.
inputSourcesobjectYesSpecifies the flow step IDs to use for sourcing data. The configuration must cover at least 2 potential claims: basicIdentity contributes 1 claim, extendedIdentity contributes 2 claims (phone + email), and deviceSignals contributes 1 claim. See Input mapping.
inputSources.basicIdentitystringNoThe step ID providing basic identity data (e.g., first name, last name).
inputSources.extendedIdentitystringNoThe step ID providing extended identity data (e.g., phone, email).
inputSources.deviceSignalsstringNoThe step ID providing device signal data (e.g., IP address).

Example configuration​

{
"suspiciousUserThreshold": 25,
"trustedUserThreshold": 70,
"inputSources": {
"basicIdentity": "collect-identity",
"extendedIdentity": "collect-contact"
}
}

Input data blocks​

Data blockRequiredDescription
BasicIdentityConditionalProvides name signal (1 claim). Present only when inputSources.basicIdentity is set.
ExtendedIdentityConditionalProvides phone and email signals (2 claims). Present only when inputSources.extendedIdentity is set.
DeviceSignalsConditionalProvides IP signal (1 claim). Present only when inputSources.deviceSignals is set.

The inputSources configuration must cover at least 2 potential claims in total. extendedIdentity alone satisfies this requirement. The referenced steps must have already produced the corresponding data blocks before this step executes.


Routes​

RouteDescription
trustedThe score computed is greater than or equal to trustedUserThreshold.
suspiciousThe score computed is strictly between suspiciousUserThreshold and trustedUserThreshold.
not_trustedThe score computed is less than or equal to suspiciousUserThreshold.
inconclusiveThe actual data resolved at runtime amounts to fewer than 2 claims (e.g. basicIdentity is configured but the last name is missing, or extendedIdentity is configured but both phone and email are absent). Provider errors are not routed here — they cause step failure.

Output data blocks​

RouteData blocks produced
trustedDigitalSignals
suspiciousDigitalSignals
not_trustedDigitalSignals
inconclusiveDigitalSignals

Example payloads​

DigitalSignals — trusted
{
"provider": "TRUSTFULL",
"timestamp": "2026-02-10T14:00:01.000Z",
"services": [
"emails",
"phone",
"name"
],
"inputSources": {
"basicIdentity": "collect-identity",
"extendedIdentity": "collect-contact",
"deviceSignals": null
},
"result": "trusted",
"score": 87,
"reasons": [
{
"code": "RE001",
"details": "Email Low Velocity:Absence or very low number of connected accounts to this email address"
}
],
"signals": {
"email": {
"score": 90,
"valid": true,
"domain_age_days": 4380
},
"phone": {
"score": 84,
"valid": true,
"line_type": "mobile"
},
"name": {
"score": 88,
"match": true
}
}
}
note

The signals field contains the raw, unaltered response from the provider. Its internal structure is not guaranteed and may vary between providers or over time. Do not rely on specific field names or nesting within signals.