Compliance, Surveillance & RegTech
A

Aptus.AI

Aptus.AI converts financial regulation into a machine readable format and sells the result to compliance and legal functions at banks, insurers and other regulated firms. Its patented method turns legal documents of any format, including scanned files, into a structured standard that software can read, which is what allows automated impact analysis rather than keyword search across a document library.

The Daitomic platform, and the broader Next-OS product built on it, monitor more than 200 national and international authorities across seven or more countries, including the Bank of Italy, Consob, the Italian privacy authority and the European supervisory bodies, consolidate changes into continuously updated structured text, and notify users when something moves. Users query the corpus in natural language, upload their own internal documents into thematic workspaces so internal policies can be read against external rules, and generate drafts of policies, legal opinions and recurring documents.

Agentic orchestration is described as completing multi step workflows rather than only answering questions. The company was founded in Pisa in 2018 by two University of Pisa doctoral researchers, holds granted patents on its conversion methodology in Italy, Europe and the United States, and distributes partly through systems integrator partners.

Last VerifiedAugust 17, 2026
Compare Aptus.AI with other vendors
Founded
2018
Headquarters
Pisa, Italy
Website
aptus.ai
Categories
compliance-and-surveillance, insurance-ai
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test is decisive here and it separates this vendor from the two established platforms screened alongside it. The product is the conversion: a patented method that turns legal documents of any format, including scanned files, into a proprietary machine readable standard, which is what makes automated impact analysis possible at all.

Remove the models and there is no structured corpus, no consolidated always current text and no impact analysis, only links to more than 200 authority websites. No human analyst curation operation sits underneath, which is exactly what holds CUBE and Corlytics at B in the same category. Peer anchored against Ascent, Norm Ai, Hadrius and Acin, all at A for the same reason. The founders are two doctoral researchers and the core method is patented in three jurisdictions, which is unusually concrete evidence that the technique rather than the content library is the asset.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

This is the sharpest gap in the profile and it is widening rather than narrowing. The platform generates drafts of policies, legal opinions and recurring legal documents, and agentic orchestration is described as completing complex workflows and adapting to what it discovers along the way rather than simply answering a question.

Nothing published names a review gate, an approval step, a confidence threshold, or what a compliance officer sees to distinguish a machine drafted opinion from a human one. The vendor's stated philosophy is to empower rather than replace professionals, which is a position rather than a control. Compare Corlytics, which publishes a named role chain with a quality assurance step, and daappa, which earns an A by naming what is automated, the gate and the adjudicator.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy figure, benchmark, validation method or error rate was located for any stage of the pipeline, and this product has an unusually measurable one. Conversion of a scanned legal document into structured machine readable form either preserves the provision or does not, which is directly testable against the source text, and the vendor's own claim is that this conversion is the foundation everything else rests on.

An error there propagates silently into impact analysis, notifications and generated drafts. The company points to granted patents as evidence of technical substance, and a patent establishes novelty rather than accuracy. Same standard applied to Blue Fire AI and bondIT: a product making a checkable claim carries an obligation to publish the check.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Several named customers with named individuals quoted, which is the B bar met clearly: Banca Agricola Popolare di Sicilia, General Finance and the consultancy RbyC each provide an attributed testimonial. The strongest single signal is that Italy's largest bank by assets, Intesa Sanpaolo, formalised a partnership announced through its own corporate website in October 2023.

Held at B rather than A on the standard applied to CUBE in the same session: a bank announcing a partnership is not a customer reporting a measured result. No client publishes a time saving, error reduction or cost figure, no customer count is stated, and the partnership's scope and current status are not described. Backing came from a specialist Italian venture fund in a three million euro round in November 2023.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

No boundary statement was located on whether documents a customer uploads inform models, retrieval indexes or outputs served to anyone else. The exposure is concrete rather than theoretical: users are invited to upload internal policies and case material into workspaces, the customer base includes competing banks and the law firms and consultancies that advise them, and one plausible reading of a shared corpus is that a consultancy's analysis improves what a rival sees.

The vendor states its corpus is built from official public sources plus user uploaded documents, which makes the separation between the two the exact question that needs answering and is not answered.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No privacy statement, retention rule or handling commitment for customer uploaded material was located in this pass. The gap is more pointed than the grade alone suggests because the product explicitly invites institutions to upload their own internal documents into thematic workspaces so that internal policy can be analysed against external rules. That material is a regulated firm's own compliance posture and, for a law firm user, potentially privileged client work. European data protection law applies directly to this vendor and to those uploads, and nothing published describes how the obligation is met.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No information security certification, audit report, penetration testing statement or trust centre was located in this pass. Recorded as an absence found rather than a proven absence and worth rechecking, since the lesson from the 73 Strings correction is that product and use case pages sometimes carry compliance claims that no security page repeats.

The gap matters commercially rather than only editorially: this vendor sells to supervised banks and insurers whose third party risk assessments open with exactly this question, and it competes against a peer in the same analyst category that has published an independently audited certification.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

Selected for the Italian central bank's innovation centre programme and included in an associated accelerator, which is a real and checkable engagement with a supervisor rather than a generic compliance claim. Graded on the established bar: participation in a regulator run innovation or access programme is a B, in the same class as Socure's data programme enrolment, while an A requires a supervised live test of the AI product itself against transparency, explainability and bias standards, which is what CleverChain has and this vendor does not.

Also relevant and unusual in this index: the company argues publicly that authorities should publish regulation in machine readable form, which places it in the policy conversation about the format of the rules it processes.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No governance framework, fairness position, testing programme or independent assessment was located. The product specific exposure is coverage and salience rather than protected class discrimination, and it is worth stating for any legal or regulatory retrieval product: what the system surfaces determines what a compliance team believes the law requires, and coverage across more than 200 authorities in seven or more countries will be deepest for Italian sources and thinnest at the edges, where a user is least equipped to notice the gap.

A second exposure sits in the drafting layer, where a generated opinion inherits whatever the retrieval step happened to find. Recorded against the new ladder set by Corlytics in this same competitor set, where an independently audited artificial intelligence management system certification earns an A.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No accuracy warranty, service commitment or remedy was located. The consequence structure is heavier here than for a pure monitoring tool because the product drafts legal and policy documents. A generated policy draft or legal opinion that misstates an obligation can be adopted into a firm's own rulebook and relied on by staff who never see the source, and the resulting supervisory finding lands entirely on the regulated firm. Where the user is a law firm rather than an institution, a further party sits downstream: the client who receives advice shaped by a system it never selected and cannot examine.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

Unusual and partial. The core conversion technology is documented through granted patents in Italy in 2023, Europe in 2024 and the United States in 2025, covering the whole methodology that turns legal documents into the proprietary machine readable format. A granted patent is a published specification, which makes this the most externally checkable account of a core model in this competitor set, and it is the same reasoning that earned bondIT a B for unusually traceable model provenance.

The gap is the generative layer: retrieval augmented generation and chat over the corpus clearly involve a large language model, and no provider, base model or hosting arrangement is named anywhere located. A buyer can inspect how the corpus is built and cannot tell whose model reads it.

Core Systems and Integration Depth
CC on Core Systems and Integration DepthIntegration claimed through standards or connectors with no system named and nothing to verify.
Vendor Published

Delivered as cloud software with distribution partly through systems integrator partners, and document upload is the main route by which a customer's own material reaches the platform. No named integration with a governance, risk and compliance system, a policy management platform, a document management system or a core banking platform was located, and no application programming interface documentation or connector catalogue was found.

For a compliance function, regulatory intelligence that does not reach the system holding the firm's policies and controls leaves the mapping step to be done by hand, which is the step the category exists to automate.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

Earned on a specific published fact rather than a generic cloud claim: the company states its servers are cloud based and located in Ireland, within the European Union. Naming the hosting jurisdiction is what this axis asks for and most vendors here never do it, which is why 271 of 308 sat at C when the distribution was last measured.

Held at B rather than A because a single stated location is not a residency option: nothing describes region choice, tenancy model, subprocessor list, or what happens for a customer that must keep processing inside Italy. The disclosure is well matched to the buyer, since European data sovereignty is a live procurement question for the institutions this vendor sells to.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No rate card, tier list or billing basis was located, and the route to a number is a demo or contact request. Worth noting alongside the category pattern: every regulatory intelligence vendor screened in this sweep so far sits at C here, from the largest platform with a thousand customers to this one at pre Series A scale, so the opacity is a category norm rather than a size effect.

Distribution partly through systems integrator partners adds a second unpriced layer, since a buyer reaching the product through a reseller cannot see how the vendor's own economics translate into the quoted price.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Buyer breadth is genuine: banks, credit institutions, insurers, in house legal teams, law firms, accountants, labour consultants, consultancies and public administration, with regulatory coverage spanning more than 200 national and international authorities across seven or more countries. What holds it at B rather than A is geographic concentration.

The product is built around Italian and European regulation, its named sources are the Italian central bank, the Italian market authority and the Italian privacy authority alongside the European supervisory bodies, and every named customer is Italian. Compare Corlytics at A on this axis with more than 120 countries and 2,500 authorities. This is a deep national position rather than a global one, which is a legitimate strategy and a real limit on the axis as written.

Alternatives to Aptus.AI

The closest documented capability profiles to Aptus.AI in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Autonomy and Oversight Model and Core Systems and Integration Depth where Aptus.AI does not

Documents AI Safety and Data Stewardship and Autonomy and Oversight Model, among others where Aptus.AI does not

Documents Autonomy and Oversight Model where Aptus.AI does not

Documents Autonomy and Oversight Model and Core Systems and Integration Depth where Aptus.AI does not

Documents Autonomy and Oversight Model where Aptus.AI does not

Documents Autonomy and Oversight Model and Core Systems and Integration Depth, among others where Aptus.AI does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746