Bretton AI
Bretton AI, which operated as Greenlite until its 2026 rebrand, supplies agents that carry out financial crime compliance work rather than tooling for humans to do it faster. The agents clear first line sanctions, politically exposed person, adverse media and transaction monitoring alerts, run customer and enhanced due diligence including financial statement and web presence analysis, and hand enriched cases with drafted narratives to human analysts for the judgement calls. Its distinguishing layer is a trust framework built around named United States banking supervisory guidance on model risk and transaction monitoring.
Capability Axes
The agents are the product, not an assistant layered over one. What the company sells is the completion of compliance work that was previously done by outsourced analyst teams, clearing first line alerts, running due diligence on customer documentation, financial statements and web presence, and drafting the narrative record.
Apply the removal test and nothing is left except the outsourced human workforce this explicitly replaces, which the founding thesis names directly as the problem: months of training, difficult quality assurance and low productivity from offshore review teams.
The division of labour is stated in the industry's own vocabulary, which makes it unusually legible. Agents fully remediate first line alerts, clearing false positives across sanctions, politically exposed person, adverse media and transaction monitoring queues, while second line analysts receive enriched data, pre analysis and drafted narratives and retain the risk based decisions that require judgement.
That is an explicit map of which determinations are automated and which escalate, drawn along a boundary compliance functions and their examiners already recognise, and human in the loop testing is described as part of how agents are validated before they run.
The first top grade on this axis anywhere in this index, and it is earned by naming the thing every other vendor avoids. Bretton AI builds its agents on a trust framework that embeds the federal supervisory guidance on model risk management and the state transaction monitoring regulation into their foundation, and states that this exists to meet requirements for validation, testing and accuracy with transparent model governance and auditability.
Every other vendor assessed here leaves the buyer to work out unaided how a machine learning component will survive model validation. One qualification belongs in diligence: the framework is described rather than published, so a buyer should ask to see the validation and testing artifacts it produces rather than accept the architecture claim on its own.
Outcomes are attributed to named customers rather than aggregated, which is what this grade requires. A payments customer reports a 90 percent reduction in alert processing time and 95 percent fewer false positives; a corporate card platform, a digital bank and a wealth manager are cited returning three to four times investment within twelve weeks.
The named roster spans fintech, banking and professional services, and includes a chartered bank scaling due diligence on small business and startup clients, which is the hardest version of that problem. The company states plainly that it serves banks and broker dealers under federal and securities supervision, a claim those regulators' examinations would test.
Agents are configured against the institution's own risk policies, standard operating procedures and compliance guidelines rather than generic templates, which scopes their behaviour to the customer and implies learning that does not pool across the base, and human in the loop testing is named as part of the deployment method. The completed security attestation supports the operational side.
Two gaps remain: the claim that agents achieve lower error rates than human analysts is offered without any published measurement, and nothing identifies which model providers sit behind the agents or how customer documentation is handled when it reaches them.
The company holds a service organisation control type two attestation and describes it as covering security, availability, processing integrity, confidentiality and privacy, which is a completed multi month audit rather than a policy statement and is more privacy assurance than most vendors in this index offer. That matters given what the agents read: customer identity documentation, financial statements, adverse media and web presence for individuals and businesses under review.
What is not published is the framework beneath the attestation, with no privacy policy detail on agent data handling, no retention schedule and no subprocessor list identifying which model providers process customer material.
A service organisation control type two attestation is publicly announced and named specifically, with the trust criteria it covers identified, and the company frames it as the signal regulated institutions require before allowing generative systems near their data. That is a completed independent audit rather than an unreadable badge or an unnamed claim of maintaining certifications, which puts it ahead of most of this index. What is missing is the surrounding surface: no trust centre, no report request path, no stated audit period and no further framework coverage such as an international information security standard.
Bretton AI supplies software and holds no licence, the expected posture, and its regulatory grounding is the most specific in this index. Rather than referring to anti money laundering obligations generally, the company names the two supervisory instruments its architecture is built against: the federal banking guidance on model risk management, and the New York state transaction monitoring regulation that requires an annual certification by a senior officer that the monitoring system is compliant. Building to that second instrument means the vendor is addressing an obligation a named executive signs personally, which is a materially different design constraint from generic compliance.
Governance is genuinely well handled and fairness is not addressed, and the two should not be confused. Adverse media screening and name based sanctions and politically exposed person matching carry a structural error asymmetry: matching accuracy varies by naming convention, transliteration and script, and adverse media corpora are dominated by English language sources, so customers with non Western names or from less covered media markets attract different false positive rates as a property of the method. An agent clearing first line alerts at scale inherits that asymmetry. No demographic or per population error analysis, no fairness testing and no correction route were located.
Bretton AI comes closer to structural accountability than any peer without a contractual guarantee. Its agents are built on a framework that embeds the federal model risk guidance and the state transaction monitoring rule, the latter requiring a senior officer to certify annually that the monitoring system is compliant, so the vendor is designing to support an obligation a named executive signs personally. A completed independent security audit backs the operational side. Still missing: no accuracy guarantee, no published error rate, and no correction route for a customer whose alert an agent cleared or escalated wrongly.
Agents are configured against the institution's own policies, procedures and guidelines rather than generic templates, which scopes behaviour to the customer and implies the chain does not run through other customers' data. The integration posture is additive, connecting to existing case management, screening and core banking rather than displacing them, so the institution keeps its own data suppliers. What is absent is the model layer itself: no provider named, and no statement on where customer due diligence documentation is processed.
The integration posture is deliberately additive and is a stated differentiator against the incumbent platforms: agents connect to the case management, screening and core banking systems an institution already runs, so a compliance team keeps its existing queues and adds automation inside them rather than replacing a monitoring platform. For a regulated buyer that avoids revalidating a system of record, which is the real cost of switching in this category. What was not located is the outward facing surface the strongest integrators publish, with no named connector directory, no public developer documentation, no status page and no changelog.
Delivery is cloud hosted software as a service. The customer base is largely domestic but includes at least one United Kingdom professional services firm, which brings European data protection expectations into scope for that engagement.
No public material identifies hosting regions, residency options, transfer mechanisms, tenancy separation or the subprocessor chain, and the last of those matters more than usual here because agent processing of customer documentation implies material passing to third party model providers wherever they operate.
No rates, tiers, billing unit or minimum are published. The pricing question is more interesting than usual for this product because the value proposition is replacing outsourced analyst headcount, which has a known and comparable unit cost, so a published per review or per agent price would let a buyer run the comparison directly. Instead the return figures are offered without the denominator that would make them checkable.
Coverage spans fintechs, federally supervised banks, securities regulated broker dealers, large corporates and at least one professional services firm, with work covering customer due diligence, enhanced due diligence, sanctions and politically exposed person screening, adverse media and transaction monitoring alerts, and business onboarding.
The breadth of institution type is real but narrower than the widest vendors in this lane, with no dedicated treatment of credit unions, insurers, sponsor bank partner oversight or capital markets, and the geographic centre of gravity is domestic with limited non United States material.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.