Skip to content
Gurdx

Docs / Platform

Events and alerts

An event is the record Gurdx creates whenever an API request produces a risky result, and it is what drives dashboard monitoring, webhooks and chat alerts.

When an event is raised#

Events are created after the API response has been sent, so they never slow down your requests. They are not raised in test mode. By default an event is raised when a result reaches these thresholds:

Source Threshold
IP checks risk 50 out of 100
Payment fraud score 50 out of 100
Email scoring score 2 out of 3
Profanity risk 0.5 out of 1

Blacklist matches and invalid IBAN, BIN or phone results also raise events. Every event stores its risk score normalised to a 0 to 100 scale.

Event types#

EventDescription
suspicious_ipSuspicious IP
fraud_paymentFraudulent payment attempt
spam_emailSpam email
spam_phoneFake phone number
profanityProfane content
invalid_ibanInvalid IBAN
invalid_binInvalid card BIN

Webhooks deliver the VPN and proxy type under the public event name proxy_detected. See Webhooks.

What an event contains#

  • The event type and its risk score (0 to 100).
  • The subject: the IP, email, phone, BIN, IBAN or text that was checked.
  • The IP and country, when known.
  • The user identifier you passed with the userID parameter.
  • The result details and whether the request was blocked.
  • A timestamp in your account time zone.

User identifier#

Add userID to any request to tag it with your own identifier, such as a user ID or email. It lets you search the Events page for everything linked to one customer and shows up in webhook and chat payloads as user_identifier.

curl "https://gurdx.cretip.com/api/lookup/ip/threats?ip=203.0.113.42&userID=user_1042" \
  -H "Authorization: Bearer $GURDX_KEY"

Note: Use an opaque ID rather than raw personal data where possible. You can erase a person's data with the user deletion endpoint.

Filtering and exporting#

On the Events page in https://gurdx.cretip.com/app you can filter by event type, risk range, date range and user identifier, and open any event to see its full details. Use the export option to download the filtered list for audits or for loading into your own tools. Team members need the Events and alerts permission.

Alerts#

Events fan out automatically:

  1. Every enabled webhook that subscribes to the type receives a signed delivery. See Webhooks.
  2. Every enabled integration (Slack, Telegram, Discord) that subscribes to the type and whose minimum risk score is met receives a short message. See Integrations.

Retention#

Raw API request logs are kept for 90 days by default and are then pruned. Daily usage counters are kept permanently. Use exports or webhooks to archive events you need for longer.

Tip: Start with a low minimum risk score on a quiet channel, watch for a week, then raise it until the alert volume is something your team will actually read.

Found a mistake? Tell us on the contact page. Contact