ProcureTwin does not declare companies or individuals fraudulent. It surfaces risk indicators to support independent verification.
The company and the sender are separate
A genuine company’s name may appear on a forged purchase order. A warning attached to a domain, phone number or delivery location does not label the named company fraudulent. We identify the subject of each finding and keep impersonation context visible.
Public sources
- Companies House: we link to the official company record. This public version does not perform an automated Companies House API verification. A company record does not establish the sender’s authority or approved delivery sites.
- Domain comparison: we compare the sender’s domain with the independent domain you supply, or with an approved company profile you select. A match does not authenticate the message. An unlisted domain may be legitimate.
- RDAP: we query the public registry’s domain registration service. Unsupported registries, missing dates and failed lookups are shown as unavailable. Registration age alone is not a fraud finding.
- Official warnings: our source register contains notices published by the affected organisations. We show the original source and review date, and distinguish publication dates from our review dates. Historical or undated warnings do not establish that an organisation is currently being impersonated.
Organisation profiles
A company representative may submit official details. Submission alone is not verification. Before approval the operator checks the company record, the applicant’s authority through an independently obtained contact, control or authority over each listed domain, and the supplied purchasing details. Simply receiving an email from the submitted address is insufficient.
Approved profiles show the company name and number, reviewed official domains, any approved public purchasing numbers, and review and expiry dates. Private delivery sites and verification notes are not public. Profiles expire no later than 90 days after the underlying request; renewal requires a fresh review. “Verified” describes the profile review, not creditworthiness or authority for any particular order.
Applicants cannot publish or amend approved data directly. Corrections and replacement profiles require operator review. A new claim cannot overwrite an active profile. The operator can withdraw a profile while a challenge is investigated.
Member intelligence
No live member reports are used today. The proposed service uses privately verified reporters and evidence-backed moderation before matching. See the reporting policy. Counts must exclude duplicates, expired records and restricted or unreviewed reports. A shared delivery site or recycled phone number requires context; an exact match is not proof of a common offender.
No invented precision
We describe each observed indicator individually. We do not issue scam probabilities, reputation ratings or “safe to trade” scores. Missing data stays missing; it does not become a risk indicator. No match means no match within the stated coverage, not a clean history.
Privacy by audience
Searches of our editorial notices run in your browser. The live domain checker submits only domain names and an optional company number. Public profiles contain only approved business information. A future private matching service must use access controls, keyed identifier fingerprints and limited results; fingerprinting does not make personal data anonymous. Public regional trends must be coarse enough to avoid identifying private delivery sites and will need a separate disclosure review.
Challenge information
Request a correction or appeal without an account or fee. Include the company, page or reference. We review the underlying source and explain our decision. Our privacy notice describes your rights.
Basis for these standards
Our approach draws on the ICO’s fraud-prevention data-sharing guidance and right to rectification guidance. This is our operating policy, not ICO certification or approval.