Bureau
Bureau is a unified risk decisioning platform founded in 2020 by Ranjan Reddy, headquartered in San Francisco with offices in India, Singapore and Dubai. It sells across the whole customer lifecycle rather than at a single checkpoint, combining device, behavioural, identity, network and transaction signals into one decision layer spanning onboarding, authentication, payments, credit and compliance.
Six product lines carry it: Device ID, Behavioural Biometrics, Identity Verification, a Graph Identity Network that links users, devices, addresses and behavioural patterns across platforms to surface fraud rings and synthetic identities, Alternative Data for assessing thin file borrowers, and a runtime application self protection line that sits outside the scope of this record. Named use cases include account takeover, bot detection, credit underwriting, location spoofing, promotion abuse, business verification and a Money Mule Score launched in 2024 that flags probable mule accounts during onboarding.
Identity verification runs against government databases and business registries across a stated 195 countries and more than 2,000 document types, returning document checks in under two seconds and business profiles in under five, with deepfake, spoof and forgery detection the company puts at 99.9 percent accuracy. Compliance coverage spans know your customer, know your business, anti money laundering, politically exposed person screening and FATCA. The company states more than 200 signals, more than a billion verified identities, more than 200 customer brands and a 70 percent reduction in manual reviews.
It entered Saudi Arabia in 2023 to support the fraud framework mandated by the Saudi Central Bank, expanded into the Philippines and Indonesia in 2024, and partnered with M2P Fintech the same year. Total funding is reported at around 50.7 million dollars.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The removal test resolves against the product architecture rather than the marketing. Bureau's proposition is the combination of signals rather than any single check, drawing on a stated 200 or more device, identity, behavioural, email, phone, network and transaction attributes and resolving them in milliseconds through what the company calls a self learning system core. Three components could not exist without models.
The Graph Identity Network links users, shared devices, addresses and behavioural patterns across platforms specifically to catch synthetic and stolen identities, which is entity resolution over a graph rather than a lookup. Behavioural biometrics is inference by definition. Deepfake, spoof and forged document detection, which the company puts at 99.9 percent accuracy, is a discriminative model against an adversary actively producing counterfeits.
The Money Mule Score is a predictive judgement about future conduct at the moment of onboarding, before any transaction exists to inspect. Strip the models and what remains is document optical character recognition against government registries, which is a fraction of what is sold.
The oversight construction is real and the company leads with it. Explainable risk decisioning appears repeatedly as a positioning claim rather than as a footnote, with the company stating it delivers insights that drive decisions rather than a data dump, and offering what it calls decision visibility into the decision making process.
Around that sit customer held controls: a no code workflow builder giving what the company describes as full control over custom workflows, rule tuning available from day one, and orchestration branching so a single flow can route to different paths on verified data. The customer configures the logic and Bureau supplies signals and orchestration, so the decision belongs to the buyer. What is missing is any specification behind the explainability claim.
Nothing published describes what form an explanation takes, whether it identifies which of the 200 signals drove a decision, whether the graph linkage behind an adverse finding is visible to the customer, or what a reviewer sees when contesting a Money Mule Score. Explainable is asserted as a property rather than described as a method.
Several published performance figures and no way to assess any of them. The company states 99.9 percent accuracy on deepfake, spoof and forgery detection, document authentication in under two seconds, business verification in under five, user verification in under ten, and a 70 percent reduction in manual reviews.
Latency figures are checkable in a trial; the accuracy figure is not, since no methodology, population, adversarial condition or measurement period accompanies it, and it covers one sub capability rather than the risk decisions the platform actually produces. No validation report, precision or recall measure, false positive rate, model documentation or monitoring statement was located for the graph, the behavioural models, the mule score or the underwriting signals.
The explainability claim is the closest thing to model transparency on the record and is credited on the autonomy axis. For a platform whose output includes credit underwriting inputs and a money mule determination, both of which attract model risk scrutiny at any regulated buyer, that is thin.
Substantial scale claims and not one named customer. The company states more than 200 global brands, more than a billion verified identities, service across more than 195 countries and a 70 percent reduction in manual reviews, and it reported a sixfold increase in both customers and revenue in the year to its Series A extension with total funding now reported near 50.7 million dollars. What is entirely absent across repeated retrieval is attribution.
No customer is named anywhere in the material located, and the only quantified outcome carries no attribution at all, an unnamed customer reporting 20 percent more fake applications identified. That is a striking gap for a company of this size and it is the single thing separating this record from the vendors above it in this lane, all of which name customers on the record.
Corporate evidence does exist and is checkable: a partnership with M2P Fintech in 2024, market entries into the Philippines and Indonesia the same year, and entry into Saudi Arabia in 2023 tied to the central bank's fraud framework. A customers page exists on the site and its contents were not retrievable in this session.
The Graph Identity Network is the sharpest version of the shared network question found anywhere in this lane, and it is disclosed as the headline capability rather than governed as a boundary. The company states the graph links user identities, shared devices, addresses, internet protocol addresses and behavioural patterns across platforms, explicitly so that a person recognised at one customer can be connected to activity at another even where synthetic or stolen credentials were used.
That is a cross customer identity graph by design and it is the product's central selling point. Nothing published states whether a customer can decline to contribute to it, how one customer's contributed identities are separated from another's view, what a retained identity node contains, how long linkages persist, or what happens to a customer's contributed graph when they leave.
The stakes are higher here than for a device signal, because the entity being linked is a named person holding financial accounts, and an erroneous edge in that graph propagates a fraud association to an innocent identity across every customer on the network.
A privacy policy and terms are published and nothing further was located. No data processing addendum, subprocessor list, retention schedule, named supervisory authority or transfer mechanism was retrievable, and no privacy regime is named specifically, which is a notable silence for a platform operating across a stated 195 countries including jurisdictions with their own data protection statutes in India, Indonesia, the Philippines and Saudi Arabia.
The exposure is at the higher end of this lane. Bureau ingests identity documents, facial images for liveness and deepfake detection, and behavioural biometrics, which are biometric categories attracting heightened protection under most modern privacy regimes, and it retains identity linkages across customers in a persistent graph.
The compliance products address know your customer, anti money laundering, politically exposed person screening and FATCA, but those are regulatory obligations the customer carries rather than statements about how Bureau itself handles the personal data it processes to discharge them.
One credential clears the test substantially and the second does not. The company announced achieving SOC 2 Type 2 compliance in its own material, which supplies a verb and the stronger period based type, and states the report can be obtained by contacting its customer success team, so an actual audited artifact exists and is reachable. That is materially more than the vendors in this lane whose security claims rest on badges or on adherence language.
Against it, no auditing firm is named, no trust services criteria or scope statement is given, and no trust centre, penetration test summary or downloadable report exists. The second claim is weaker still: ISO/IEC 27001:2022 is described as compliance rather than certification, and while naming the 2022 revision is more precise than most, compliance with a standard is not the same as holding a certificate from an accredited body, and no registrar, certificate number or Statement of Applicability appears. Pre emptive negative finding: restating the ISO version will not move this grade. Naming the certification body, or publishing the SOC 2 scope, is what would.
The regulatory engagement here is more specific than most in this lane and is anchored to a named authority. The company entered Saudi Arabia in 2023 expressly to support the fraud framework mandated by the Saudi Central Bank, which is a product built to a particular supervisor's requirement rather than a general compliance claim, and a buyer in that market can check it against the framework itself.
Compliance products address named instruments across multiple regimes, covering know your customer, know your business, anti money laundering, politically exposed person screening and FATCA, with the company positioning hyper local regulatory compliance across 195 or more markets as a core capability.
Identity and business verification run against government databases and official company registries, so the product operates against authoritative state sources rather than commercial aggregators alone. Bureau holds no licence itself, which is correct for a technology supplier, no regulator appears as a customer, and no supervisory authority approves the models.
One narrow accuracy figure and no governance around it. The company publishes 99.9 percent accuracy for deepfake, spoof and forged document detection, which is a specific claim on a specific sub capability and is credited on the model risk axis. Nothing else this axis asks for exists. No error rate, false positive rate, confidence measure or calibration statement is published for the platform as a whole.
No fairness testing, disparate impact analysis or performance breakdown by demographic, document type or market appears anywhere. That absence is more consequential for this vendor than for most in this lane, because two of its core capabilities carry well documented demographic performance variation: facial liveness and deepfake detection vary by skin tone and lighting, and behavioural biometrics vary with age, disability and device quality, and Bureau operates heavily in exactly the emerging markets where the training data for both is thinnest. Nothing describes who approves a model change or what validation a new signal passes before it affects an onboarding decision.
No guarantee, indemnity, accuracy service level or falsifiable commitment was located, and the vendor does not make the final decision, so there is little it would be underwriting. The explainability claim gives the customer visibility into a decision, which is credited on the autonomy axis and is a benefit to the institution rather than to the person affected.
For that person the position is the weakest implied by any product in this lane, because of what the platform determines about them. Someone flagged by the Money Mule Score is judged likely to be laundering funds before they have transacted at all, on the basis of device, behavioural and network associations they cannot see.
Someone wrongly connected through the Graph Identity Network inherits a fraud association that follows them across every customer on the network rather than at the one institution that refused them. Nothing published describes notification, evidence disclosure, an appeal route, a correction mechanism, or how a corrected linkage propagates back to customers who already acted on it.
The most important input category is identified and no supplier within it is named. The company states that identity and business verification query government databases and official company registries across more than 195 countries, which tells a buyer the authoritative sources are state held rather than commercially aggregated, and that is a genuine and useful disclosure about provenance.
Everything else is characterised only by count or category: more than 200 device, identity, behavioural, email, phone, network and transaction signals, plus an alternative data product for thin file assessment whose sources are described only as alternative.
No third party data supplier, credit bureau, telecommunications provider, device intelligence vendor or email and phone enrichment service is named anywhere, which matters because alternative data underwriting turns entirely on what the alternative data actually is. No subprocessor list exists in public, no cloud infrastructure provider is named, and no model or foundation model provider is identified for any component including the deepfake detection.
The integration depth that matters most here is downward into authoritative data rather than sideways into business systems, and it is substantial. Identity verification connects to government databases across a stated 195 countries covering more than 2,000 document types, and business verification queries official company registries to return ownership and compliance profiles, which is a data integration estate that takes years to assemble and is not replicable by an API alone.
On the customer side, delivery spans APIs, software development kits and a no code workflow builder, with the orchestration platform explicitly consolidating multiple onboarding processes behind a single API call so a customer replaces several point integrations with one. A named partnership with M2P Fintech reaches banking infrastructure in South Asia.
What was not located is any enumerated connector catalogue: no named core banking, payment gateway, case management or customer relationship platform integration appears, and while the site carries a documentation link its contents were not retrievable.
Delivery is hosted software consumed through APIs, software development kits and a no code interface. The company refers to flexible deployment options balancing speed, customisation and control, without describing what those options are, so it is not possible to tell whether a private or single tenant deployment exists. On residency nothing is published: no cloud provider, region, data centre or country of processing is named, and no transfer mechanism appears.
That gap is unusually consequential for this vendor. It markets hyper local regulatory compliance across 195 or more markets and has entered Saudi Arabia, Indonesia, the Philippines and India, several of which impose data localisation or transfer conditions on precisely the identity and biometric data this platform processes. Claiming local regulatory precision while disclosing nothing about where processing physically occurs leaves the buyer carrying that obligation unable to evidence it.
No rate is published anywhere across two dedicated passes. What the company does disclose, in its own comparison material rather than on a pricing page, is the basis on which a quote is constructed: custom pricing determined by which modules are taken, which regions are covered, onboarding volume, the customer journeys supported and workflow requirements.
That is more informative than silence because it tells a buyer which levers move their cost, and it explains why no list price could exist for a platform sold as configurable orchestration across 195 markets. A third party directory describes the commercial model as per API hit pricing plus a platform fee, which is consistent with that shape but is not confirmed by the vendor.
The same directory contradicts itself on whether a trial exists, recording both that no free version or trial is available and that a trial is available, so neither statement is usable. No free tier, published trial, entry price or worked example was located on the vendor's own surface.
Coverage is wide on three dimensions at once. By buyer, the company addresses financial institutions and banks and fintechs as separate named segments, alongside marketplaces, gaming, ecommerce and online dating. By lifecycle stage, the platform is sold across onboarding, authentication, payments, credit underwriting and ongoing compliance rather than at one checkpoint, so it competes with identity vendors, fraud vendors and credit decisioning vendors simultaneously.
By geography the reach is genuine rather than asserted: a stated 195 or more countries, offices across San Francisco, India, Singapore and Dubai, and dated market entries into the Philippines, Indonesia and Saudi Arabia, with identity verification running against local government databases and business registries in those markets. Emerging market depth across South and Southeast Asia and the Gulf is the distinguishing feature and few competitors in this lane demonstrate it. What holds this below the top grade is that no customer is named in any segment, so the breadth is claimed rather than evidenced.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Custom quoted against modules taken, regions covered, onboarding volume, journeys supported and workflow requirements. No entry price, free tier or published trial was located on the vendor's own surface.
|
Custom quoted, with the variables disclosed but no rate attached. The company states that pricing is set against the modules a customer takes, the regions covered, onboarding volumes, the customer journeys supported and workflow requirements. That structure follows from the product: identity and business verification query government databases and official registries across more than 195 countries, and the cost of those queries differs by jurisdiction, so a single global rate would be meaningless. A third party directory characterises the commercial model as per API hit pricing plus a platform fee, which is consistent with a decisioning platform metering discrete checks on top of a subscription, though the vendor does not confirm it. Modules are sold separately across device identification, behavioural biometrics, identity verification, the graph network, alternative data and runtime application protection, so a customer's cost depends heavily on how much of the platform they adopt rather than on volume alone. | No data processing addendum or subprocessor list was located. A privacy policy and terms are published and nothing more specific was retrievable: no regime is named, no supervisory authority identified, no retention schedule stated and no transfer mechanism described. That is a thin position for a platform processing identity documents, facial images for liveness and deepfake checks, and behavioural biometrics across a stated 195 countries. On the assurance side the company announced achieving SOC 2 Type 2 compliance and states the report is obtainable through its customer success team, and separately describes ISO/IEC 27001:2022 compliance without claiming certification, naming a registrar or publishing a scope. A regulated buyer will get an audited security report by asking and will negotiate data protection terms from scratch. | Not published and not disclaimed. No setup, onboarding, integration or professional services fee appears anywhere. Integration effort should be low for a standard deployment, since the platform is offered through APIs, software development kits and a no code workflow builder, with the company stating customers can be running and tuning rules from day one and describing onboarding processes as consolidating behind a single API call. Against that, the company also advertises bespoke solutions built for a customer's specific challenges and states it handles the technical heavy lifting, which is professional services work in substance, and no rate, engagement minimum or inclusion boundary is stated for it. Per market data acquisition costs behind government database and registry checks are presumably embedded in the per verification price rather than billed separately, but this is not stated. | Third Party Estimated |
Two dedicated passes returned no rate from the vendor or from any third party. The useful finding is that the company does publish the basis on which a quote is built, though it appears in its own comparison writing rather than on a pricing page: cost is determined by which modules are taken, which regions are covered, onboarding volume, the customer journeys supported and workflow requirements.
That tells a buyer which levers move their number and explains why no list price could exist for orchestration sold across 195 markets with per market data costs behind it. A third party directory describes the model as per API hit pricing plus a platform fee, which fits that shape but is unconfirmed.
Pre emptive negative finding, and it is about source quality rather than the vendor: the same directory states both that no free version or trial is available and that a trial is available, in adjacent fields on one page. Third party pricing data on this vendor is internally contradictory and should not be used to move this grade in either direction without vendor confirmation.