Learn how the Norphluchs background-intelligence platform works, which professional background checks are available, how pricing and units work, and how Norphluchs supports secure, responsible workflows.
Search the FAQ for a quick answer or switch to the Knowledge Base for deeper operational guidance.
Platform & FeaturesChecks, ECHO-360 and modules
Pre-EmploymentCandidate screening workflows
Pricing & AccessUnits, registration and volume
Privacy & LegalGDPR, retention and responsible use
Help Center FAQ
Allgemein
6 Fragen
Norphluchs ist eine europäische Softwareplattform für professionelle Background Intelligence.
Organisationen nutzen Norphluchs für strukturierte Pre-Employment Screenings, Exposure Checks und weitere personenbezogene Prüfungen. Die Plattform verbindet ausgewählte öffentliche Quellen, offizielle Register, lizenzierte Intelligence-Datensätze und Verifizierungsservices in einem kontrollierten Workflow.
Norphluchs liefert Erkenntnisse für die professionelle Prüfung. Interpretation und finale Entscheidung verbleiben beim autorisierten Nutzer.
Norphluchs ist ausschließlich für die professionelle Nutzung durch freigeschaltete Unternehmen, öffentliche Stellen und Organisationen in offizieller Funktion konzipiert.
Die Zugangsbeschränkung unterstützt dabei, personenbezogene Prüfungen für einen dokumentierten geschäftlichen Zweck und innerhalb angemessener rechtlicher und organisatorischer Kontrollen durchzuführen. Private Nutzung durch Verbraucher und Recherchen aus reiner persönlicher Neugier sind nicht zulässig.
Ja. Organisationen können eine auf ihren vorgesehenen Anwendungsfall zugeschnittene Demonstration anfragen.
Ein Norphluchs Account sollte einer namentlich benannten Person zugeordnet sein. Der Zugriff von mehreren freigegebenen Geräten kann möglich sein.
Zugangsdaten dürfen nicht mit anderen Personen geteilt werden.
Nein. Norphluchs Accounts sind für einzelne autorisierte Nutzer vorgesehen und sollten nicht innerhalb eines Teams geteilt werden.
Separate Accounts verbessern Sicherheit, Zugriffskontrolle und Nachvollziehbarkeit, weil klar erkennbar ist, wer eine Prüfung gestartet und geprüft hat.
Norphluchs führt mehrere Intelligence- und Verifizierungsebenen in einer professionellen Softwareumgebung zusammen.
Statt Teams separate Tools für CV-Verifizierung, Identity Checks, Dokumentenanalyse, Public-Source-Recherche, digitale Exposure, Medien-Screening, Compliance-Daten und Unternehmensinformationen nutzen zu lassen, ermöglicht Norphluchs die Auswahl der für den jeweiligen Fall relevanten Module.
Das Ergebnis ist ein flexibler Workflow für professionelle Prüfung — kein Black-Box-Score und keine automatisierte Entscheidung.
Norphluchs unterstützt modulare personenbezogene Checks für verschiedene professionelle Anwendungsfälle, darunter:
Pre-Employment Screening
Executive- und Board-Screening
Exposure Checks
Compliance- und Due-Diligence-Unterstützung
Prüfungen von Drittparteien und Geschäftspartnern
autorisierte interne Ermittlungen
Mitarbeiterprüfungen bei dokumentiertem Anlass
Der verfügbare Umfang hängt von Zweck, Jurisdiktion, Rolle der Person und gewähltem Deployment ab.
Ja. Norphluchs kann mehrere Candidate-Screening-Schritte innerhalb eines Kandidatenfalls koordinieren.
Je nach ausgewähltem Workflow kann dies CV-Verifizierung, Dokumentenchecks, Identitätsprüfung, Referenzchecks sowie rollenrelevante OSINT- oder Compliance-Recherche umfassen. Ergebnisse werden verfügbar, sobald einzelne Checks abgeschlossen sind. So kann HR den Fortschritt verfolgen und Erkenntnisse bei der Interviewvorbereitung berücksichtigen.
Norphluchs entscheidet nicht, ob ein Kandidat eingestellt werden soll.
Ein Exposure Check untersucht, was über eine Person in ausgewählten digitalen und offiziellen Informationsumgebungen öffentlich sichtbar, verknüpft, exponiert oder berichtet ist.
Organisationen können Exposure Checks für Führungskräfte, Board-Mitglieder, Schlüsselpersonen, Mitarbeitende in Security-Awareness-Programmen, Principals von Family Offices oder andere Personen mit erhöhter Sichtbarkeit oder besonderen Zugriffsrechten einsetzen.
Ziel ist, den digitalen Fußabdruck der Person für eine professionelle Prüfung sichtbar zu machen — nicht, Fehlverhalten zu unterstellen.
ECHO-360 ist ein konfigurierbarer, zeitpunktbezogener Background- und Exposure-Check.
Autorisierte Nutzer können bekannte Informationen wie Name, E-Mail-Adressen, Telefonnummern und relevante Unternehmensbeziehungen einer Person eingeben. Norphluchs durchsucht die ausgewählten Intelligence-Module und führt verfügbare Ergebnisse in einer kompakten Personenübersicht zusammen.
Je nach Deployment können Ergebnisse im Browser geprüft, als PDF, CSV oder JSON exportiert, im Bulk gestartet oder über eine API abgerufen werden.
Der ECHO-360-Kernworkflow kann folgende Angaben nutzen:
einen vollständigen Namen
eine oder mehrere E-Mail-Adressen
eine oder mehrere Telefonnummern
relevante Unternehmen oder organisatorische Rollen
Qualität und Breite der verfügbaren Ergebnisse hängen von den eingegebenen Identifikatoren, den ausgewählten Modulen und der Verfügbarkeit von Informationen in den zugrunde liegenden Quellen ab.
Ja. Norphluchs ist modular.
Organisationen können nur die für einen konkreten Fall benötigten Checks auswählen — zum Beispiel CV-Verifizierung, Identity Check, Clear-Web-Suche, Dark-Web-Exposure-Check, Mediensuche, PEP-Screening oder Sanktions- und Watchlist-Prüfung.
So können Teams jede Prüfung verhältnismäßig am Zweck ausrichten, statt auf jede Person dasselbe breite Screening-Paket anzuwenden.
Automatisierte Checks liefern Ergebnisse innerhalb weniger Minuten. Checks, die die Mitwirkung von Kandidaten oder Antworten von Referenzpersonen erfordern, dauern länger.
Norphluchs liefert keine „Go“- oder „No-Go“-Entscheidungen. Autorisierte Nutzer müssen die abgerufenen Informationen prüfen und ihre eigene professionelle Entscheidung treffen.
Norphluchs wurde entwickelt, um den Aufwand zu reduzieren, große Mengen voneinander getrennter Suchergebnisse manuell durchzuarbeiten.
Je nach Modul erhalten Nutzer eine strukturierte Übersicht mit verfügbaren Ergebnissen, Eingaben, Quellenreferenzen und Abrufdaten
. Detaillierte Modulergebnisse können geöffnet werden, wenn eine genauere Prüfung erforderlich ist.
Ja. Der Norphluchs CV Check kann berufliche Zeitangaben, Arbeitgeber, Bildungseinrichtungen und weitere CV-Informationen auf Plausibilität und Konsistenz prüfen.
Je nach gewähltem Workflow und verfügbaren Modulen kann Norphluchs die Verifizierung von Identitätsdokumenten, Dokumentenanalyse und Bildverifizierung unterstützen.
Dies kann die Prüfung umfassen, ob eingereichte Dokumente intern konsistent sind, Manipulationsindikatoren zeigen oder künstlich erzeugte Elemente zu enthalten scheinen.
Nein. Automatisierte Suchen können schnell Ergebnisse liefern, während Identitätsprüfung, Dokumentenbestätigung und Referenzchecks von der Mitwirkung des Kandidaten oder Dritter abhängen.
Norphluchs koordiniert die einzelnen Module innerhalb eines Kandidatenfalls und zeigt Ergebnisse an, sobald sie verfügbar sind.
Nein. Norphluchs liefert strukturierte Erkenntnisse für die menschliche Prüfung. Finale Bewertung und Einstellungsentscheidung verbleiben bei der verantwortlichen Organisation.
Ja. Einzelne Screening-Module können entsprechend Position und Screening-Zweck ausgewählt werden.
Automatisierte Ergebnisse können innerhalb weniger Minuten verfügbar sein. Referenzchecks, externe Bestätigungen und vom Kandidaten durchgeführte Verifizierungsschritte können länger dauern.
Ja. Der Workflow sollte der einstellenden Organisation ermöglichen, relevante Erkenntnisse mit dem Kandidaten zu besprechen und zusätzliche Erklärungen oder Unterlagen einzuholen.
Ja. Je nach Deployment kann Norphluchs über die API in Applicant-Tracking- und interne Systeme integriert werden.
Nach der Registrierung werden Ihre Angaben von einem Norphluchs Mitarbeiter geprüft, um Identität und Accountinformationen zu verifizieren. Nach Freigabe der Registrierung erhalten Sie Zugriff auf Ihren Account.
Anschließend können Sie jederzeit im Self-Service-Bereich unter „Billing“ Units erwerben oder direkt über die Plattform einen On-Demand-Check starten.
Ja. Das On-Demand-Modell ist für einzelne oder gelegentliche Fälle ausgelegt.
Damit kann eine Organisation einen zweckgebundenen Background- oder Exposure-Check durchführen, ohne sich zu einem größeren Plattform-Deployment zu verpflichten. Umfang und Preis der Prüfung hängen von den ausgewählten Modulen und den zu prüfenden Informationen ab.
Units sind Nutzungsguthaben für einzelne Checks und Intelligence-Module innerhalb der Norphluchs Plattform.
Jedes Modul verbraucht eine definierte Anzahl an Units. Eine fokussierte Prüfung benötigt daher weniger Units als ein breiter Check über mehrere Intelligence-Umgebungen.
Organisationen können dadurch ein gemeinsames Guthaben für unterschiedliche Prüfarten nutzen, statt für jede Funktion ein separates Abonnement zu erwerben.
Der Preis hängt in erster Linie vom Umfang der Prüfung ab.
Relevante Faktoren sind:
die ausgewählten Intelligence- und Verifizierungsmodule
die Anzahl der eingegebenen Namen, E-Mail-Adressen, Telefonnummern oder Unternehmen
Nach den aktuellen kommerziellen Bedingungen sind gekaufte Units ab Kaufdatum 12 Monate gültig, sofern nicht schriftlich ein anderer Zeitraum vereinbart wurde.
Nicht genutzte Units verfallen nach diesem Zeitraum. Für Enterprise-Kunden können abweichende vertragliche Regelungen vereinbart werden.
Ja. Organisationen mit wiederkehrendem oder höherem Volumen können geeignete Unit-Pakete oder eine Enterprise-Vereinbarung besprechen.
Enterprise-Preise können erwartete Volumina, benötigte Module, Integrationsbedarf, Support-Level und vertragliche Anforderungen berücksichtigen.
Je nach ausgewähltem Produkt und Deployment können Ergebnisse verfügbar sein:
innerhalb der Norphluchs Browser-Plattform
als PDF-Bericht
als strukturierte CSV- oder JSON-Ausgabe
über eine API-Integration
über einen Bulk-Workflow
Ja. Bestimmte Workflows können einen Bulk-Start über Spreadsheet-Upload unterstützen.
Ja. Norphluchs kann über die API in freigegebene HR-, Security-, Compliance-, Due-Diligence- und Case-Management-Umgebungen integriert werden.
Ja. Norphluchs ist darauf ausgelegt, kontrollierte, transparente und DSGVO-orientierte Workflows zu unterstützen. Die Nutzung von Software macht jedoch nicht jede Prüfung automatisch rechtskonform.
Der Kunde muss den Zweck definieren, einen angemessenen und verhältnismäßigen Umfang wählen, die relevante Rechtsgrundlage festlegen, Transparenzpflichten erfüllen und den Zugriff auf autorisierte Nutzer beschränken.
Der Kunde, der die Prüfung durchführt, bestimmt in der Regel, warum und wie personenbezogene Daten verwendet werden, und ist daher für die Festlegung der geeigneten Rechtsgrundlage verantwortlich.
Norphluchs stellt die Software bereit und verarbeitet Daten entsprechend der vereinbarten Leistungsbeziehung. Die jeweiligen Rollen und Verantwortlichkeiten sollten vertraglich dokumentiert und für die relevante Jurisdiktion und den Anwendungsfall geprüft werden.
Nein. Norphluchs ist darauf ausgelegt, Erkenntnisse für eine menschliche Prüfung bereitzustellen.
Die verantwortliche Organisation muss Richtigkeit, Relevanz und Verhältnismäßigkeit der Informationen bewerten und die finale Entscheidung treffen.
Nein. Ein Fund sollte niemals als automatische Ablehnung behandelt werden.
Er kann auf eine Abweichung, einen möglichen Treffer oder Klärungsbedarf hinweisen. Der Arbeitgeber muss die zugrunde liegenden Informationen prüfen, ihre Relevanz für die Rolle bewerten und dem Kandidaten, soweit erforderlich, eine angemessene Möglichkeit zur Erklärung oder Korrektur relevanter Angaben geben.
Potenzielle Treffer müssen validiert werden, bevor darauf vertraut wird.
Namen, Kontaktdaten und Online-Identifikatoren können geteilt, veraltet oder falsch zugeordnet sein. Norphluchs garantiert nicht, dass jedes Ergebnis vollständig ist oder sich auf die richtige Person bezieht; die aktuellen Bedingungen berücksichtigen ausdrücklich, dass technisch unvermeidbare False Positives auftreten können.
Nein. Das Fehlen zugänglicher Informationen beweist nicht, dass keine Beziehung, Exposure oder Auffälligkeit besteht.
Automatisierte Checks sind auf die Informationen beschränkt, die innerhalb der ausgewählten Quellen und des definierten Umfangs verfügbar sind. Private, nicht offengelegte, nicht registrierte, ungenaue oder nicht zugängliche Informationen können unentdeckt bleiben.
Norphluchs ist nach den Prinzipien der Datenminimierung und begrenzten Aufbewahrung gestaltet.
Nach den aktuellen Plattformbedingungen werden Prüfungsdaten bis zu 30 Tage aufbewahrt. Kunden können die Daten jederzeit vor Ablauf dieses Zeitraums löschen. Ergebnisse, die weiter aufbewahrt werden sollen, sollten exportiert werden; für die Verwaltung dieser Exporte entsprechend eigenen Aufbewahrungsrichtlinien und rechtlichen Pflichten ist der Kunde verantwortlich.
Ja. In Deutschland.
Ja. Norphluchs kann autorisierte, zweckgebundene Prüfungen unterstützen, wenn ein dokumentierter Sicherheits-, Compliance- oder Integritätsanlass vorliegt.
Es sollte nicht für allgemeine oder kontinuierliche Mitarbeiterüberwachung eingesetzt werden. Die Organisation muss eine angemessene Rechtsgrundlage, interne Autorisierung, einen verhältnismäßigen Umfang und einen transparenten Prozess festlegen und dabei geltende arbeits- und datenschutzrechtliche Anforderungen berücksichtigen.
Ja. Sie können genutzt werden, wenn die Organisation einen legitimen, dokumentierten Security-Awareness-Zweck und eine angemessene Rechtsgrundlage hat.
Der Umfang sollte verhältnismäßig und transparent sein. Ziel sollte sein, Mitarbeitenden zu zeigen, wo geschäftliche Identifikatoren online erscheinen und wie digitale Exposure reduziert werden kann — nicht, sachfremdes privates Verhalten zu bewerten.
No matching question found. Try a broader search term or another category.
Knowledge Base
Go deeper than the FAQ.
Use the Knowledge Base for operational guidance: when to use a capability, how to scope it, what findings mean, how to validate them and what to do next.
25in-depth guides
All guides25 guides
No matching Knowledge Base guide found. Try a broader search term.
Start here01
Norphluchs at a glance
Norphluchs is a European platform for professional background intelligence. It helps approved organizations turn fragmented person-related information into structured findings for professional review.
Who Norphluchs is for
Norphluchs is designed for approved B2B and B2G organizations using person-related intelligence for a documented professional purpose. Typical teams include HR, security, compliance, due diligence, investigations and risk functions.
What the platform brings together
Pre-employment screening modules, including CV, document, identity, image, reference and role-relevant OSINT/compliance checks.
Exposure Checks that make publicly visible, connected, exposed and reported information around a person easier to review.
Selected public sources, media, company/register data, exposure datasets and structured compliance data.
Structured outputs that reduce the need to work through multiple disconnected research tools.
What Norphluchs does not do
It does not make hiring, employment, compliance or investigative decisions for you.
It does not turn a finding into an automatic conclusion about a person.
It does not guarantee that all available information is complete, current or correctly associated with the person being reviewed.
It does not make a workflow automatically lawful simply because the software can technically perform it.
A useful way to think about the platform
Use Norphluchs as an intelligence layer around a defined decision. Start with the question your team needs to answer, select only the relevant modules, review findings in context, and document the reasoning behind any follow-up.
Related guides
Start here02
A responsible background-intelligence workflow
The strongest background-intelligence process starts with the decision, not the data source. Use the workflow below to keep each assessment focused, proportionate and reviewable.
1. Define the decision and purpose
Write down why the assessment is being performed and what decision it is intended to support. Avoid broad research without a clear business purpose.
What do we need to verify or understand?
Why is this information relevant to the role, transaction, relationship or documented concern?
Who is authorized to initiate and review the assessment?
2. Select a proportionate scope
Choose the modules that answer the specific question. A focused assessment should use fewer data categories than a broad one. Scope can depend on the person’s role, level of access, jurisdiction, internal policy and the questions your team needs answered.
3. Collect and structure findings
Norphluchs searches the selected intelligence and verification environments and presents the available results in a structured form. Automated modules may return findings within minutes; candidate-led or third-party steps can take longer.
4. Validate before relying on a finding
Confirm that the result relates to the correct person or organization.
Review the underlying source, retrieval date and surrounding context where available.
Distinguish a verified fact from an indicator, possible match or unresolved discrepancy.
Do not treat a lack of results as proof that no relationship, exposure or concern exists.
5. Clarify material discrepancies
Where a finding could materially affect a decision, give the relevant person an appropriate opportunity to explain or correct the information where required by the applicable process.
6. Make and document the human decision
The responsible organization makes the final decision. Document the purpose, scope, sources considered, relevant clarifications and the reasoning that led to the outcome.
Related guides
Existing employees and documented concerns
Accounts & access03
Account approval, user access and security
Norphluchs access is restricted to approved professional users. Accounts are individual, attributable and intended to support controlled use of person-related intelligence.
Who can register
Norphluchs is intended for companies, public authorities and other organizations acting in an official capacity. Registration details are reviewed before access is approved.
Named-user accounts
Each account should be assigned to one authorized user.
Credentials should not be shared across a team.
Access from multiple approved devices may be possible, but the account remains attributable to one person.
Separate user accounts improve access control, accountability and auditability.
Password recovery
Use the password-reset function available from the sign-in flow.
If self-service recovery is not sufficient, contact the Norphluchs team through the approved support channel.
Multi-factor authentication
Multi-factor authentication adds a second verification step and is obligatory.
Good account hygiene
Use an individual business email address.
Do not share passwords or verification codes.
Remove access promptly when a user changes role or leaves the organization.
Use the least amount of access needed for the user’s responsibilities.
Related guides
Accounts & access04
Units, pricing and on-demand use
Norphluchs uses a modular usage model so organizations can run focused checks without purchasing a separate product for every intelligence layer.
How units work
Units are usage credits for individual checks and intelligence modules. A focused assessment typically uses fewer units than a broader assessment across multiple data environments.
What determines the price of an assessment
The intelligence and verification modules selected.
The number and type of identifiers or entities entered.
The workflow or deployment model agreed with the customer.
For enterprise use, expected volume, integrations, support and contractual requirements.
Can we start with one case?
Yes. On-demand use is intended for individual or occasional cases where an organization needs a purpose-defined background or exposure check without committing to a broader deployment.
How long are purchased units valid?
Under the current commercial terms reflected in the Help Center, purchased units are valid for 12 months from the purchase date unless a different period has been agreed in writing. Unused units expire after that period.
What happens if an account is deleted?
Account deletion can affect remaining units and access to platform data. Export any information that must be retained under your own policies before deleting an account, and confirm the commercial consequences in the applicable agreement.
Related guides
Platform operations05
Results, exports, bulk workflows and API access
Different teams need findings in different operational environments. Norphluchs can support browser review, structured exports, bulk initiation and API-based integration depending on the product and deployment.
Ways to access results
Within the Norphluchs browser platform.
As a PDF report.
As structured CSV or JSON output where supported.
Through an approved API integration.
Through supported bulk workflows.
Bulk workflows
Certain workflows can be initiated in bulk using a spreadsheet-based upload. Each person or entity should be represented as a separate case with the identifiers required for the selected check. Available limits, file formats and report options can vary by deployment.
API integration
The API is designed to add selected Norphluchs capabilities to an existing operational environment rather than forcing the organization to replace its core systems.
Typical integration environments include:
Applicant-tracking and HR systems.
Security and case-management platforms.
Compliance and due-diligence solutions.
Internal enterprise applications.
Approved partner and white-label products.
Design principle
Keep the decision logic in the customer’s process. The integration should transport inputs and findings, preserve traceability and support human review rather than converting Norphluchs outputs into an automatic decision.
Related guides
Privacy & responsible use06
Data retention, hosting and privacy responsibilities
Norphluchs is designed around data minimization and controlled access in order to support GDPR-aligned workflows The customer still remains responsible for defining a lawful, proportionate use of the platform.
Assessment-data retention
Under the current platform terms reflected in the Help Center, assessment data is retained for up to 30 days. Customers may delete it earlier. Exported reports become the customer’s responsibility and should be handled under the organization’s own retention and security policies.
Hosting
The Norphluchs platform is hosted in Germany.
Customer responsibilities
Define the purpose of the assessment.
Establish the appropriate legal basis.
Select a relevant and proportionate scope.
Meet applicable transparency or notice obligations.
Restrict access to authorized users.
Validate material findings before relying on them.
Apply the organization’s own retention and deletion rules to exported results.
Norphluchs' role
Norphluchs provides the software and processes data according to the agreed service arrangement. Applicable controller/processor roles and other responsibilities should be documented contractually and assessed for the specific jurisdiction and use case.
Related guides
Existing employees and documented concerns
Pre-Employment Screening07
Pre-Employment Screening overview
Coordinate six independent screening modules within one candidate case, while keeping the final hiring decision with the responsible organization.
The six screening modules
Module
Primary question
Typical output
CV Verification
Is the candidate's professional timeline plausible and internally consistent?
Structured discrepancies and items requiring clarification.
Document Verification
Do submitted documents support the information provided?
Indicators of inconsistency, alteration or manipulation for review.
Identity Verification
Can the person completing the process be verified?
Identity-document and candidate-led verification outputs.
Image Verification
Is the submitted image authentic, manipulated, AI-generated or reused elsewhere where the use case allows?
Image-analysis indicators and contextual findings.
Reference Check
What can nominated professional references confirm?
Structured third-party responses linked to the candidate case.
OSINT and Compliance Check
What do relevant public, official and compliance sources reveal?
Role-relevant public-source and compliance findings.
Checks complete at different speeds
Automated research may return within minutes. Candidate-led identity steps and reference responses can take longer. Treat the candidate case as a coordinated workflow rather than a single synchronous search.
Use only what the role requires
Not every position requires all six modules. Select the checks according to the documented purpose, role, level of responsibility, jurisdiction and internal policy.
Human review remains essential
Norphluchs does not decide whether a candidate should be hired. A finding can indicate a discrepancy or potential match that requires review; it should not be treated as an automatic rejection.
Related guides
Pre-Employment Screening08
CV Verification
Use CV Verification to review professional history, education and timelines for plausibility, completeness and consistency before relying on the information in a hiring process.
When to use it
CV Verification is useful when the role, level of responsibility or internal policy justifies a structured review of the candidate’s stated professional background.
What the module reviews
Employment history and stated employers.
Job titles and professional timelines.
Education and stated institutions.
Gaps, overlaps and other internal inconsistencies.
Where appropriate and available, selected public professional sources and company/register information.
Typical findings
Unexplained employment gaps.
Overlapping full-time roles.
Employers, positions or institutions that require clarification.
Education claims that cannot be verified from the available sources.
How to interpret a discrepancy
A discrepancy is a review prompt, not proof of misrepresentation. Source coverage can be incomplete, company names can change, job titles can vary across records, and education programmes may not be verifiable from public information.
Related guides
Pre-Employment Screening09
Document Verification
Use Document Verification to examine whether submitted supporting documents are internally consistent and whether they show indicators that deserve closer human review.
Typical documents
Academic degrees and diplomas.
Professional qualifications and training certificates.
Employment certificates and records.
Reference letters.
Other role-relevant supporting documents.
What the module can help identify
Internal inconsistencies in the document.
Indicators of alteration or manipulation.
Metadata or structural signals where available.
Possible artificially generated elements where the selected analysis supports this.
What the result means
Document-analysis findings are indicators for review. A technical signal alone should not be treated as proof that a document is fraudulent. Compare the result with the document context, the candidate’s explanation and any available issuer verification.
Related guides
Pre-Employment Screening10
Identity Verification
Identity Verification confirms the person behind the application using a separate candidate-led verification process.
When to use it
Use Identity Verification where confirming the person completing the application process is relevant and proportionate to the role or workflow.
Depending on the selected procedure, verification may include
Government-issued identity-document validation.
Data extraction and consistency checks.
Live-photo capture.
Face matching.
Liveness verification.
What HR should review
Focus on whether the identity step completed successfully, whether any inconsistencies need clarification and whether the result relates to the same candidate case. Avoid expanding the check beyond the documented purpose.
Timing
Identity verification requires candidate participation and may therefore complete later than automated research modules.
Related guides
Pre-Employment Screening11
Image Verification
Image Verification helps reviewers assess whether a submitted image may be manipulated, artificially generated or reused elsewhere on the web where the use case and applicable requirements allow.
Depending on the selected scope, image verification may include
Indicators of manipulation or alteration.
Indicators associated with AI-generated images.
Image consistency and plausibility checks.
Metadata analysis where available.
Reverse-image research for identical or visually similar images where permitted.
Contextual review of relevant online findings.
How to interpret image-analysis results
Treat image-analysis outputs as indicators, not automatic conclusions. Compression, editing, screenshots, platform processing and incomplete metadata can all affect technical signals.
Related guides
Pre-Employment Screening12
Reference Checks
Reference Checks bring structured third-party responses into the same candidate case so they can be reviewed alongside the candidate’s stated history.
What the reference process may cover
Employment period.
Position and responsibilities.
Performance-related questions.
Eligibility for rehire where legally permitted.
Questions defined by the hiring organization.
Why reference checks finish later
Reference checks depend on third-party responses. A reference can remain pending while other modules are already complete. Do not delay review of available findings simply because every module has not finished.
How to compare a reference with the CV
Look for material differences in dates, role, responsibilities or other facts relevant to the hiring decision. Small wording differences are not automatically meaningful. Where the reference conflicts with the candidate’s account, clarify the discrepancy before relying on it.
Related guides
Pre-Employment Screening13
OSINT and Compliance Check
Use the OSINT and Compliance Check to add role-relevant public, official, media, company/register and compliance intelligence to the candidate case.
The scope can include
Selected clear-web research.
Selected deep-web research.
Media coverage.
Company and register information.
Sanctions, black and watchlists.
Politically exposed person screening.
Selected exposure or dark-web indicators where proportionate to the role and purpose.
Scope it to the role
A senior role with elevated financial, security or reputational responsibility may justify a different scope from a standard operational role. Define the reason for each module before enabling it.
What not to do
Do not treat broad internet visibility, personal opinions or unrelated private activity as automatically relevant to employment. Review only information that is appropriate to the documented purpose and applicable legal framework.
Related guides
Exposure Checks14
Exposure Checks and ECHO-360 overview
Exposure Checks make the digital footprint around a person visible in a structured, point-in-time assessment. ECHO-360 brings selected intelligence layers together around known identifiers.
Typical inputs
Full name.
One or more email addresses.
One or more telephone numbers.
Relevant companies or organizational relationships.
What an Exposure Check can help answer
What information is publicly visible?
Which accounts or identifiers may be connected?
Where has personal or professional information been exposed?
Which organizations or company roles are associated with the person?
What public reporting exists?
Which findings deserve closer professional review?
Underlying intelligence environment
Source category
Current coverage indicator used in relaunch copy
Global media outlets
140,000+ outlets · approximately 60 languages
Reddit
30 billion+ data points
Dark-web / exposure data
5 billion+ entries
Telegram threat-intelligence coverage
Billions of messages from relevant threat-intelligence groups and channels
Clear-web selected sources
1,500+
Business-data jurisdictions
260+
PEP, sanctions, blacklists & watchlists
380+ structured datasets
Coverage figures are useful scale indicators, not a promise that every source will return a result for every person. Data availability, selected modules and identifiers determine the actual output.
Point-in-time, not a permanent verdict
An Exposure Check reflects the available information within the selected sources at the time of retrieval. It should be repeated only when there is a documented reason to do so.
Related guides
Exposure Checks15
Clear-Web Intelligence
Clear-Web Intelligence helps connect selected publicly available information around known identifiers such as names, emails, phone numbers, usernames or other supported selectors.
Best for
Understanding a person’s publicly visible digital footprint.
Identifying public profiles, registrations or aliases connected to known identifiers.
Adding context to an Exposure Check or other authorized assessment.
What may be returned
Depending on source availability and privacy settings, results can include public profiles, professional information, websites, forum activity, aliases, images or other publicly accessible context.
What 'live' means
Clear-web lookups are live/current searches rather than a static historical archive. That means the result can change over time and deleted or inaccessible content may not appear.
Coverage
1,500+ selected clear-web sources.
Interpretation
A connection between an identifier and an online account should be validated before it is attributed to a person. Shared names, recycled usernames and outdated information can create false associations.
Related guides
Search selectors and query behavior
Exposure Checks16
Adverse Media
Adverse Media helps surface public reporting that may be relevant to due diligence, compliance, exposure or other professional assessments.
What adverse media is
Adverse media, sometimes called negative news, is public reporting that may indicate allegations, investigations, enforcement action, misconduct or other risk-relevant events relating to a person or organization.
Why it is useful
It can surface context that has not yet appeared in a sanctions or watchlist result.
It can show how an issue developed across multiple reports.
It can support a more complete due-diligence picture when reviewed alongside official and structured sources.
Articles are not conclusions
A media mention can describe an allegation, opinion, historic event or unrelated namesake. Review the publication, date, person match, status of the matter and the relevance to the specific assessment.
Coverage
Norphluchs covers more than 140,000 media outlets across approximately 60 languages. Exact historical lookback and source availability can vary by module and deployment.
Related guides
Exposure Checks17
Dark-Web and Exposure Intelligence
Use Dark-Web and Exposure Intelligence to identify whether known selectors appear in large exposure datasets or archived dark-web data environments.
Best for
Checking whether an email, domain, phone number or other supported selector appears in exposure data.
Supporting digital-exposure reviews for executives, key personnel or approved security-awareness use cases.
Adding breach/exposure context to a broader person-level assessment.
Why results can vary
New data may be added and old data may become unavailable.
Large result sets can be limited by result buckets or backend constraints.
Temporary maintenance or timeouts can affect returned volume.
Different deployments can use different approved backend configurations.
Source visibility
Archived data may not always expose exact origin metadata beyond the bucket, title or source information shown in the report. Treat provenance as part of the reliability assessment.
Related guides
Search selectors and query behavior
Exposure Checks18
Telegram Intelligence
Telegram Intelligence provides structured access to large-volume Telegram data for approved professional research and threat-intelligence use cases.
Coverage
Norphluchs covers billions of Telegram messages from relevant threat-intelligence groups and channels.
Search modes
Post search using supported keyword modes.
User search using available identifiers such as username, phone number or unique user ID.
Group/channel context where available.
File search where the deployment exposes indexed files.
Advanced Boolean or regex search where supported by the Telegram module.
How to use the result strategically
The presence of a name, username or identifier in a threat-intelligence-related group does not by itself establish intent, ownership or misconduct. Validate the identifier, review the surrounding conversation and determine why the result is relevant to the approved purpose.
File-safety warning
Related guides
Exposure Checks19
Reddit Intelligence
Reddit Intelligence helps authorized users find relevant posts, comments, users and communities within a large indexed Reddit data environment.
Coverage
The current coverage is 30 billion+ Reddit data points.
What you can investigate
Posts and comments matching relevant criteria.
Reddit users where the identifier or activity is relevant to the assessment.
Subreddits and discussion context.
Interpretation
Do not assume that a username belongs to the person under review without corroboration. Reddit content is contextual, conversational and often pseudonymous; account attribution requires additional evidence.
Related guides
Exposure Checks20
Company and Register Intelligence
Company and register intelligence helps connect individuals with organizations, official roles and business information across approved company-data environments.
Coverage
The current global coverage indicator is 260+ business-data jurisdictions.
DACH context in the source material
Germany: company data and registered-entrepreneur information are described as available.
Austria: enhanced company, person, association and compliance information is described as available.
Switzerland: basic company information is described as available.
Potential company-level information
Depending on jurisdiction and module, company data can include registration details, addresses, legal form, organizational roles, ownership information, financial information, trade data and other register-derived facts.
Austrian compliance reports
Norphluchs offers enhanced Austrian compliance reports offdered by Compass-Verlag for companies, associations and individuals, including sanctions/PEP information, insolvency, Russian-state affiliation and selected ownership or role data.
Strategic use
Company data is most useful when it answers a defined question: whether a claimed employer existed, whether a person held a stated role, whether an affiliation requires further review, or whether a transaction has relevant person-level connections.
Related guides
Compliance intelligence21
PEP, Sanctions, Blacklists and Watchlists
Structured compliance data can add an important layer to person-level research, but a possible match must be validated before it is used in a decision.
Coverage
The current coverage indicator is 380+ PEP, sanctions, blacklist and watchlist datasets.
What a PEP result means
A politically exposed person (PEP) result indicates a possible match to a person holding, or having held, a prominent public function or a relevant association. PEP status is not evidence of wrongdoing. It is a compliance signal that can trigger additional review where applicable.
What sanctions and watchlist results mean
Sanctions, blacklist and watchlist screening can surface possible matches to structured datasets maintained by governments, international organizations, enforcement bodies or other approved data providers.
Legal and policy point
Screening obligations and required follow-up depend on the jurisdiction, the organization, the transaction and the applicable regulatory framework. The customer remains responsible for the legal basis and compliance process.
Related guides
Research & analysis22
OSINT and OSINF fundamentals
Open-source information is the raw material. Open-source intelligence is the result of collecting, validating and interpreting that information for a defined professional question.
OSINF
Open-Source Information (OSINF) is raw, legally accessible information such as public records, websites, public images, media reporting, forums and other open sources.
OSINT
Open-Source Intelligence (OSINT) is the structured process of turning selected open information into an assessment that supports a decision.
The practical difference
A six-step intelligence cycle
Planning and direction: define the question, purpose and scope.
Collection: gather only the information needed from selected sources.
Processing: organize, deduplicate and structure the returned data.
Analysis: validate identity, relevance and reliability; compare across sources.
Dissemination: present material findings clearly and traceably.
Feedback and review: refine the questions, scope and internal process for future cases.
Related guides
Research & analysis23
Interpreting findings, false positives and no-result cases
The most important analytical skill is distinguishing a result from a conclusion.
A result can be one of several things
A verified fact supported by an official or reliable source.
A likely match that still requires identity validation.
An indicator that suggests further review.
A discrepancy between two sources.
An unverified claim or contextual mention.
A false positive caused by shared names, identifiers or outdated information.
How to handle a potential match
Confirm the selector or identity used in the search.
Check whether the source relates to the same person.
Review dates, locations, roles, aliases and other corroborating fields.
Assess whether the information is relevant to the documented purpose.
Seek clarification where the finding could materially affect the decision.
Document why the finding was accepted, rejected or left unresolved.
No result does not mean no risk
An absence of accessible information does not prove that no relationship, exposure or concern exists. Private, undisclosed, inaccurate, unregistered, deleted or inaccessible information may not be available to the selected sources.
No final risk score
Norphluchs is designed to provide structured findings for human review rather than a final 'go/no-go' score.
Related guides
Troubleshooting24
Why search results can change
Live and large-scale intelligence sources change continuously. A different result does not automatically mean the previous search was wrong.
Common reasons
New data was added or old data became unavailable.
The source platform or index changed.
A result limit or bucket limit was applied.
A temporary timeout reduced the number of records returned.
Maintenance affected one source temporarily.
The same input was normalized differently by a different module or backend.
The person’s public visibility changed.
What to do
Confirm that the input selector is identical and correctly formatted.
Review the retrieval date and source category.
Use available filters to narrow large result sets.
Re-run only when the purpose justifies a fresh point-in-time check.
If a material discrepancy persists, document both retrievals rather than silently replacing the earlier result.
Related guides
Search selectors and query behavior
Research & analysis25
TracePanel and connected analysis
TracePanel is a graph-based environment for connecting findings across searches and documenting analytical context.
What it is useful for
Visualizing relationships between people, organizations and digital identifiers.
Adding selected findings from different research modules to one graph.
Creating custom nodes when an important relationship cannot be represented automatically.
Adding structured notes, context, source information or hypotheses to findings.
Exporting or re-importing supported session data where enabled.
Strategic use
Use the graph to explain why two findings may be connected, not to imply that proximity in a graph proves a relationship. Connections should be backed by source evidence and clearly distinguished from analyst hypotheses.
Related guides
Still need a specific answer?
Contact Norphluchs for product, deployment or workflow questions that go beyond the Help Center.