Bretton AI
Bretton AI, which operated as Greenlite until its 2026 rebrand, supplies agents that carry out financial crime compliance work rather than tooling for humans to do it faster. The agents clear first line sanctions, politically exposed person, adverse media and transaction monitoring alerts, run customer and enhanced due diligence including financial statement and web presence analysis, and hand enriched cases with drafted narratives to human analysts for the judgement calls. Its distinguishing layer is a trust framework built around named United States banking supervisory guidance on model risk and transaction monitoring.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
The agents are the product, not an assistant layered over one. What the company sells is the completion of compliance work that was previously done by outsourced analyst teams, clearing first line alerts, running due diligence on customer documentation, financial statements and web presence, and drafting the narrative record.
Apply the removal test and nothing is left except the outsourced human workforce this explicitly replaces, which the founding thesis names directly as the problem: months of training, difficult quality assurance and low productivity from offshore review teams.
The division of labour is stated in the industry's own vocabulary, which makes it unusually legible. Agents fully remediate first line alerts, clearing false positives across sanctions, politically exposed person, adverse media and transaction monitoring queues, while second line analysts receive enriched data, pre analysis and drafted narratives and retain the risk based decisions that require judgement.
That is an explicit map of which determinations are automated and which escalate, drawn along a boundary compliance functions and their examiners already recognise, and human in the loop testing is described as part of how agents are validated before they run.
The first top grade on this axis anywhere in this index, and it is earned by naming the instruments every other vendor avoids. Bretton AI builds its agents on a trust framework that embeds federal supervisory guidance on model risk management and the New York transaction monitoring regulation into their foundation, and states that this exists to meet requirements for validation, testing and accuracy with transparent model governance and auditability.
The state instrument is Part 504 of the Superintendent's Regulations (3 NYCRR Part 504), Banking Division Transaction Monitoring and Filtering Program Requirements and Certifications, effective 1 January 2017, which requires a covered institution to certify annually by 15 April, signed by its board or a senior officer, that its transaction monitoring and OFAC filtering programs meet the prescribed attributes.
Every other vendor assessed here leaves the buyer to work out unaided how a machine learning component will survive model validation. The grade is held, and one material qualification is now on the record, decided 23 August 2026.
The federal half of that mapping points at instruments that no longer exist: on 17 April 2026 the Federal Reserve, OCC and FDIC issued SR 26-2, superseding SR 11-7 and OCC Bulletin 2011-12 and the 2021 interagency statement on model risk for BSA and AML systems (SR 21-8, OCC Bulletin 2021-19, FDIC FIL-27-2021), and SR 26-2 expressly excludes generative and agentic AI from its scope while disclaiming its own enforceability. This vendor's product is generative and agentic.
The grade is held because this axis measures what a vendor has published about how its models are governed, and mapping an architecture to a named instrument remains a materially stronger disclosure than naming none; downgrading the only vendor in the lane that named anything would penalise the disclosure rather than assess it, and supersession four months ago is a market wide condition rather than this company's failure. The New York certification is untouched by any of it.
One falsification condition is pre registered against the grade: if the vendor's own material still presents SR 11-7 as current at the next re verification, with no acknowledgement of SR 26-2, that becomes a currency problem in the disclosure rather than a supersession problem in the guidance, and the grade moves. Two questions belong in diligence.
The framework is described rather than published, so ask to see the validation and testing artifacts it produces rather than accept the architecture claim on its own, and ask what the mapping points at now.
Outcomes are attributed to named customers rather than aggregated, which is what this grade requires. A payments customer reports a 90 percent reduction in alert processing time and 95 percent fewer false positives; a corporate card platform, a digital bank and a wealth manager are cited returning three to four times investment within twelve weeks.
The named roster spans fintech, banking and professional services, and includes a chartered bank scaling due diligence on small business and startup clients, which is the hardest version of that problem. The company states plainly that it serves banks and broker dealers under federal and securities supervision, a claim those regulators' examinations would test.
Agents are configured against the institution's own risk policies, standard operating procedures and compliance guidelines rather than generic templates, which scopes their behaviour to the customer and implies learning that does not pool across the base, and human in the loop testing is named as part of the deployment method. The completed security attestation supports the operational side.
Two gaps remain: the claim that agents achieve lower error rates than human analysts is offered without any published measurement, and nothing identifies which model providers sit behind the agents or how customer documentation is handled when it reaches them.
The company holds a service organisation control type two attestation and describes it as covering security, availability, processing integrity, confidentiality and privacy, which is a completed multi month audit rather than a policy statement and is more privacy assurance than most vendors in this index offer. That matters given what the agents read: customer identity documentation, financial statements, adverse media and web presence for individuals and businesses under review.
What is not published is the framework beneath the attestation, with no privacy policy detail on agent data handling, no retention schedule and no subprocessor list identifying which model providers process customer material.
A service organisation control type two attestation is publicly announced and named specifically, with the trust criteria it covers identified, and the company frames it as the signal regulated institutions require before allowing generative systems near their data. That is a completed independent audit rather than an unreadable badge or an unnamed claim of maintaining certifications, which puts it ahead of most of this index. What is missing is the surrounding surface: no trust centre, no report request path, no stated audit period and no further framework coverage such as an international information security standard.
Bretton AI supplies software and holds no licence, the expected posture, and its regulatory grounding is the most specific in this index. Rather than referring to anti money laundering obligations generally, the company names the two supervisory instruments its architecture is built against: the federal banking guidance on model risk management, and the New York state transaction monitoring regulation that requires an annual certification by a senior officer that the monitoring system is compliant. Building to that second instrument means the vendor is addressing an obligation a named executive signs personally, which is a materially different design constraint from generic compliance.
Governance is genuinely well handled and fairness is not addressed, and the two should not be confused. Adverse media screening and name based sanctions and politically exposed person matching carry a structural error asymmetry: matching accuracy varies by naming convention, transliteration and script, and adverse media corpora are dominated by English language sources, so customers with non Western names or from less covered media markets attract different false positive rates as a property of the method. An agent clearing first line alerts at scale inherits that asymmetry. No demographic or per population error analysis, no fairness testing and no correction route were located.
Bretton AI comes closer to structural accountability than any peer without a contractual guarantee. Its agents are built on a framework that embeds the federal model risk guidance and the state transaction monitoring rule, the latter requiring a senior officer to certify annually that the monitoring system is compliant, so the vendor is designing to support an obligation a named executive signs personally. A completed independent security audit backs the operational side. Still missing: no accuracy guarantee, no published error rate, and no correction route for a customer whose alert an agent cleared or escalated wrongly.
Agents are configured against the institution's own policies, procedures and guidelines rather than generic templates, which scopes behaviour to the customer and implies the chain does not run through other customers' data. The integration posture is additive, connecting to existing case management, screening and core banking rather than displacing them, so the institution keeps its own data suppliers. What is absent is the model layer itself: no provider named, and no statement on where customer due diligence documentation is processed.
The integration posture is deliberately additive and is a stated differentiator against the incumbent platforms: agents connect to the case management, screening and core banking systems an institution already runs, so a compliance team keeps its existing queues and adds automation inside them rather than replacing a monitoring platform. For a regulated buyer that avoids revalidating a system of record, which is the real cost of switching in this category. What was not located is the outward facing surface the strongest integrators publish, with no named connector directory, no public developer documentation, no status page and no changelog.
Delivery is cloud hosted software as a service. The customer base is largely domestic but includes at least one United Kingdom professional services firm, which brings European data protection expectations into scope for that engagement.
No public material identifies hosting regions, residency options, transfer mechanisms, tenancy separation or the subprocessor chain, and the last of those matters more than usual here because agent processing of customer documentation implies material passing to third party model providers wherever they operate.
No rates, tiers, billing unit or minimum are published. The pricing question is more interesting than usual for this product because the value proposition is replacing outsourced analyst headcount, which has a known and comparable unit cost, so a published per review or per agent price would let a buyer run the comparison directly. Instead the return figures are offered without the denominator that would make them checkable.
Coverage spans fintechs, federally supervised banks, securities regulated broker dealers, large corporates and at least one professional services firm, with work covering customer due diligence, enhanced due diligence, sanctions and politically exposed person screening, adverse media and transaction monitoring alerts, and business onboarding.
The breadth of institution type is real but narrower than the widest vendors in this lane, with no dedicated treatment of credit unions, insurers, sponsor bank partner oversight or capital markets, and the geographic centre of gravity is domestic with limited non United States material.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Bretton AI
The closest documented capability profiles to Bretton AI in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Model Supply Chain Disclosure where Bretton AI does not
Documents Model Supply Chain Disclosure where Bretton AI does not
Documents Model Supply Chain Disclosure where Bretton AI does not
Documents Model Supply Chain Disclosure where Bretton AI does not
Stronger documented coverage on Institution and Segment Coverage
Documents AI Governance and Bias Disclosure and Model Supply Chain Disclosure where Bretton AI does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.