Fraud Detection

Fraud detection built into every candidate evaluation

Generative AI has made fabricated resumes, proxy applicants, and borrowed identities cheap to produce at scale. Noon answers with a layered detection system that runs on every candidate, inbound and outbound: network and connection analysis, identity and location consistency checks, email reputation, and corroboration of the career history against the public record. Signals are cross-referenced into a single explainable risk flag that follows the candidate across every role, so your team sees exactly why a profile was flagged and decides what happens next.

How Noon detects fraud

Four signal layers, one explainable flag.

Network layer: VPN, proxy, and datacenter connection analysis
Identity layer: claimed location versus observed timezone and geography
Email layer: disposable domains, throwaway patterns, deliverability
Footprint layer: career history corroborated against the public record
Persistent risk flag with the triggering signals, on every candidate

Inbound: risk scored on arrival

Inbound is the widest attack surface in hiring, because anyone can apply and a resume is unverifiable text. Every application Noon pulls from your ATS passes through the detection pipeline before a recruiter sees it. Connection metadata is analyzed for VPN, proxy, and datacenter routing. The location the applicant claims is reconciled against the timezone and geography Noon observes. The contact email is checked for disposable domains and throwaway patterns. Each signal is weighed against the others, so a single anomaly is context while several together become a flag. The result is written onto the applicant record alongside the evaluation, with the specific signals that fired, and it persists across every role that applicant touches. Learn more about Inbound Screening and candidate fraud red flags.

Inbound detection pipeline

Runs on every application, before review.

Connection analysis: VPN, proxy, and datacenter detection
Location reconciliation: claimed location versus observed timezone
Email reputation: disposable and throwaway domain detection
Signal correlation: anomalies weighed together, not in isolation
Cross-role persistence: flags follow the candidate everywhere

Outbound: corroborated before contact

Outbound fraud is quieter: a profile that reads well but has nothing behind it. Noon’s AI Sourcer builds each candidate from their public professional footprint across the web rather than from a self-submitted document, then evaluates the full career history for internal consistency: tenure overlaps, implausible progressions, and claims that no public record supports. Before AI Outreach sends a single message, every contact email is verified for deliverability and screened for disposable domains, and undeliverable addresses are removed. Every candidate who reaches your pipeline has a corroborated history and a working, verified contact. Learn more about the AI Sourcer and AI Outreach.

Outbound safeguards

Built into sourcing and outreach.

Profiles built from the public record, not self-submitted resumes
Career history checked for tenure overlaps and implausible progressions
Contact emails verified for deliverability before outreach
Disposable domains and dead addresses screened out
Evaluation and risk flag synced to your ATS with the candidate

Fraud Detection FAQ

How does Noon’s fraud detection work?

Noon runs a layered detection system on every candidate. On inbound applications it analyzes connection metadata for VPN, proxy, and datacenter routing, reconciles the claimed location against the observed timezone and geography, and checks the contact email for disposable or throwaway patterns. On outbound, it builds candidates from their public professional footprint, evaluates the career history for internal consistency, and verifies contact emails before outreach. Signals are correlated rather than treated in isolation, and the resulting flag is written onto the candidate record with the specific signals that fired.

What kinds of candidate fraud does Noon catch?

The patterns Noon is built to surface include proxy applicants operating through VPNs or datacenters, mass fabricated applications using disposable email addresses, identity misuse where the claimed location does not match where the applicant actually is, and thin or fabricated profiles with career histories that the public record does not support.

Does Noon reject flagged candidates automatically?

No. Detection is designed to be explainable and reviewer-in-the-loop. Flagged candidates are marked in Noon with the signals that fired, right next to the evaluation. Your team sees the reasoning, makes the final call, and can clear a flag if it is a false positive.

Does fraud detection cover both inbound and outbound candidates?

Yes. Inbound applicants pulled from your ATS pass through the detection pipeline before review, and outbound candidates found by the AI Sourcer are corroborated against the public record and contact-verified before outreach. Both sides land in the same pipeline under the same standard, and flags persist across every role a candidate touches.

Is Noon’s fraud detection a background check or identity verification service?

No. Noon surfaces fraud risk early, at the screening stage, so fake or suspicious candidates are caught before your team invests time in them. It complements rather than replaces formal background checks and identity verification, which run later in your process.

Is fraud detection included in the Noon plan?

Yes. Fraud detection is part of Noon’s single plan alongside Inbound Screening, the AI Sourcer, AI Outreach, and every other agent, with no add-on fee.

Is Noon secure enough for our security review?

Noon is SOC 2 Type II and GDPR compliant, supports SSO and SAML, and offers dedicated support with custom contracts and invoicing for enterprise customers.

See Noon's Fraud Detection in action, or explore the unlimited plan and enterprise options.