User verification (TMX)

Last update:
Aug 21, 2026
ThreatMetrix (TMX), part of LexisNexis Risk Solutions, is a digital identity and fraud prevention platform embedded into Aikyam Identity Platform (OHID/HSID) workflows to strengthen identity assurance and reduce fraud. Rather than relying on a signal, TMX evaluates patterns across device, network, and behavior to generate real-time risk decisions helping Aikyam Identity Platform stop abusive activity while keeping the experience smooth for legitimate users.
TMX supports Aikyam Identity Platform's fraud and account-protection goals by adding risk checks at the points most often targeted by attackers. This reduces exposure to synthetic identity creation, automated abuse, and account takeover attempts without requiring the platform to rely on a signal.

Primary threat areas TMX addresses:

  • Synthetic identity creation (fraudulent registrations)
  • Credential stuffing (automated login abuse)
  • Account takeover (ATO) (suspicious access and high-risk changes)

How Aikyam Identity Platform uses TMX

Aikyam Identity Platform uses TMX as an inline decision layer across selected workflows. When a user attempts a high-risk action such as creating an account, signing in under unusual conditions, or changing sensitive profile details, Aikyam Identity Platform can invoke TMX to assess the context in real time. Typical invocation pattern (high level):
  • A user initiates a high-risk action.
  • Aikyam Identity Platform calls TMX with the available context for that attempt.
  • TMX returns a risk decision.
  • Aikyam Identity Platform applies that decision to determine the next step (allow, block, or step-up).

TMX in the end-to-end journey

TMX is applied in multiple places across the user lifecycle, each chosen because it is either a common fraud entry point or a sensitive security boundary.
  1. Registration: TMX can be invoked before account creation to reduce fraudulent or synthetic registrations.
  2. Login and step-up authentication: TMX supports risk checks during authentication, especially when anomalies are detected or step-up is required.
  3. Sensitive profile updates (Settings / Manage Profile): TMX can re-verify risk before applying changes to high-risk attributes such as phone, email, or DOB.
  4. Recovery and velocity checks (where configured): TMX can help detect abnormal volumes or patterns that indicate bot or brute-force behavior.

Signals used by TMX

  • Device intelligence: fingerprinting, reputation, and emulation indicators.
  • Network and geo:IP reputation, proxy/VPN/TOR signals, and location anomalies.
  • Behavioral context: repeated failures, form velocity, and pattern anomalies.
  • Identity coherence:consistency across email/phone/DOB and observed signals.
TMX outcomes include: proceed normally (low risk), block (high risk), or step‑up authentication (medium risk).

Healthcare context

In healthcare identity journeys, TMX acts as one layer in a broader defense-in-depth strategy. It can complement controls such as MFA, rate limiting, bot management, and anomaly detection by reducing unauthorized access attempts that could expose sensitive information. In COPPA-relevant scenarios, TMX can also contribute to adult identity verification in parental/guardian contexts when used as part of layered controls and policy-driven flows.
Examples: MFA and step-up authentication, rate limiting and bot mitigation, anomaly detection and abuse monitoring.

On this page

Powered by Aikyam @2025 All rights reserved