Fraud Detection & Transaction Risk
C

Charm Security

Charm Security sells scam and social engineering defence to banks, fintechs, payment providers and credit unions. Rather than scoring transactions or devices, the platform assesses what the company calls human vulnerability exposure, analysing customer risk patterns using psychological insight to identify who is susceptible to manipulation, then deploys agents that intervene in real time while a scam is unfolding across digital, voice and in person channels. It was created inside Team8's venture creation fund and its stated regulatory driver is the shift of authorised push payment fraud liability onto banks.

Last VerifiedAugust 12, 2026
Compare Charm Security with other vendors
Founded
2024
Headquarters
New York, New York, United States
Categories
fraud-and-transaction-risk, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 3 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test leaves nothing. The company describes an agentic artificial intelligence workforce in which agents assess risk levels, analyse alerts and deploy real time countermeasures while a scam is unfolding. The thesis is that traditional fraud systems intervene too late because they read transactions and devices rather than the manipulation of the person, so the entire product is a model reading human behaviour and acting on the reading within the window of an active attack. Strip the models and there is no rule set, no case management system and no archive left behind, which distinguishes this from the orchestration platforms elsewhere in the lane.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

The product acts on a live customer in the moment and no boundary on that action is published. Agents are described as intervening in real time to disrupt deception and manipulation while a scam is unfolding, transforming a scam in progress and deploying countermeasures.

Whatever the intervention is, interrupting a payment, injecting a warning, escalating a call, it happens at machine speed inside a customer interaction, and no approval gate, confidence threshold, escalation path, analyst review or sampling regime appears in public material. Nor is there any description of what the customer experiences or is told.

The contrast within the index is Federato, which publishes which decisions are automated, what constrains them and how they are audited, and Sardine, which states in writing that models work alongside human judgement rather than replacing it.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy figure, detection rate, false positive rate, validation evidence or model documentation was located. The supervision asymmetry recorded across this index applies in an unusual direction here. A scam prevention product is naturally measured by scams stopped, and the cost that goes unmeasured is legitimate payments delayed or blocked and customers wrongly treated as compromised, which the institution absorbs as service failure rather than as fraud loss.

That means the metric the market rewards and the metric that protects the customer diverge, and nothing published addresses the second. For a system making a psychological inference, no account of how the inference is validated or how often it is wrong is the whole gap.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

Founded 2024, one funding round of 8 million dollars led by Team8, and no financial institution named anywhere. The credentials are genuine: the chief executive is a third time founder with two decades in cyber intelligence including ten years in a national signals unit, the chief technology officer led data science at Transmit Security and built fraud detection for global banks, and Team8's managing partner on the deal is a former chief executive of Israel's largest bank.

Three named relationships exist, a deepfake detection partnership with Reality Defender, a credit union member protection initiative with Curql, and a partnership with a mental health organisation. One award was won at an anti scam summit. None of that is measurement. The Norm Ai principle applies directly: buyer calibre and founder pedigree describe who is interested, not whether the product works. No customer, no volume, no detection rate, no case study.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Nothing published defines a data boundary. Scam intelligence has a strong natural pull toward pooling, because a manipulation script or a mule network seen at one institution is immediately useful at the next, and the index has already recorded that shape at BioCatch through an inter bank intelligence network.

Charm describes analysing customer risk patterns and continuously adapting to evolving scam tactics without stating whether patterns learned at one institution inform protection at another, whether any customer level signal crosses the boundary, or whether participation in any shared intelligence is optional. The stewardship question is heavier here than in most of the lane because the material being learned from is behavioural and psychological rather than transactional.

Regulatory and Compliance
GLBA and Data Privacy Posture
DD on GLBA and Data Privacy PostureNothing published, on a product that handles consumer financial data.
Vendor Published

This is the most sensitive inference in the index and there is no published privacy account of any kind. The product assesses human vulnerability exposure and customer risk patterns using psychological insight, which means the institution comes to hold a machine derived judgement about how susceptible a named individual is to manipulation.

That is an inference about cognitive and emotional state, not about a device or a transaction, and the BioCatch precedent recorded that inferring confusion, hesitation or coercion is categorically more sensitive than behavioural signals. Charm makes that inference the product.

No privacy policy detail, retention schedule, data protection agreement, subprocessor list or deletion commitment was located, nothing states whether a vulnerability assessment persists in the institution's customer record or expires, nothing states whether the customer is told a susceptibility judgement exists about them, and nothing addresses lawful basis for profiling of this kind under European or state privacy law. The grade reflects exposure against disclosure, not company age.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No attestation, certification, trust centre or dedicated security page was located, and no service organisation control report or international information security standard certificate is announced or offered on request. That gap is conspicuous for a company founded by cyber intelligence specialists and selling into bank vendor risk reviews, and it is the first item any financial institution's third party programme would request. The Kobalt Labs irony applies in a softer form: a security company that has not yet published the evidence its own buyers demand of everyone else.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

One named regime is identified correctly and it is the right one. The company states that banks face growing regulatory scrutiny and liability for authorised push payment fraud, which is the reimbursement regime that shifted the cost of scam losses onto payment firms and is the single change that created this market. Naming the specific liability shift rather than gesturing at fraud regulation generally is what earns the grade.

Against it, nothing maps the product to any other instrument: no United States regime covering error resolution or unfair and deceptive practices, no elder financial exploitation reporting duties despite vulnerability being the core subject matter, and no admission process or accreditation. Charm holds no licence and needs none, which is the correct posture for a technology supplier under the index convention.

AI Governance and Bias Disclosure
DD on AI Governance and Bias DisclosureNothing published on a product where the bias risk is concrete, such as credit decisioning or underwriting with no fair lending, disparate impact or adverse action disclosure.
Vendor Published

The core mechanism is a susceptibility judgement about individual people and nothing is published about how it is tested. Vulnerability to social engineering correlates directly with age, cognitive decline, bereavement, social isolation, digital literacy, neurodivergence and operating in a second language, so a model built to identify who can be manipulated will concentrate its flags on older, disabled and less digitally fluent customers as a property of the technique rather than as a defect.

Two failure modes follow and neither is addressed. A false positive means a customer is treated as incapable of managing their own money, subjected to friction or intervention on legitimate payments, which is paternalistic exclusion dressed as protection. A false negative means the customer the product exists to protect is not protected.

No demographic error rates, no accessibility analysis, no statement of what a vulnerability score contains, how long it persists or whether it influences any other decision the institution makes about that customer, and no route for a person to know they carry one. Sixth grade at this level on the axis, and the first where the protected characteristic is not a proxy but the thing being modelled.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

No guarantee, indemnity, falsifiable commitment or correction path was located. The reimbursement regime the company names does give a scam victim a real route, but it addresses the harm the product prevents rather than any harm the product causes, and the two harms specific to this system have no route at all. A customer carrying a vulnerability assessment is not told it exists and cannot see, correct or contest it.

A customer whose legitimate payment is interrupted because a model read manipulation into an ordinary interaction has no notice that an automated judgement was involved. Both parties are the institution's customers and neither has any relationship with Charm, which is the recurring shape in this index, sharpened here because the judgement is about the person rather than the transaction.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

A genuine and uncommon disclosure sits at the centre of this grade. Charm publicly names Reality Defender as the deepfake detection component embedded in its agentic workforce, announced as a partnership in March 2026, which identifies a specific third party model in the decision path and is more than most vendors in this lane offer.

It is also the third recorded instance of an indexed vendor depending on another indexed vendor, after Quantifind and ComplyAdvantage appearing inside Sumsub's screening chain, which is exactly the supply chain depth this axis exists to expose.

What holds it at B is that the rest of the chain is undisclosed: no foundation model provider, hosting arrangement or subprocessor is named, and nothing states whether customer interaction content passes to an external model provider during real time analysis.

Core Systems and Integration Depth
CC on Core Systems and Integration DepthIntegration claimed through standards or connectors with no system named and nothing to verify.
Vendor Published

Protection is stated across digital, voice and in person channels, which necessarily implies integration into online banking, contact centre and branch systems, and that spread would be a genuine differentiator if evidenced. Nothing is named. No core banking platform, digital banking provider, contact centre platform, case management or existing fraud engine appears anywhere, and no developer documentation or application programming interface reference was located.

A buyer cannot determine what deploying this into a live branch or call centre involves, which is a material question for the credit union segment the Curql initiative targets, where integration effort decides adoption.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting model, cloud provider, region selection, residency commitment or private deployment option was located. The question carries weight for this product because real time intervention in a voice channel implies live processing of customer interaction data, and because the company operates across the United States and Israel while naming a United Kingdom originated liability regime as its market driver, which puts three jurisdictions in play with no published account of where anything runs.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging, basis of charge or trial route is published and every path into the product is a contact request. Nothing indicates whether charging is per protected customer, per intervention, per channel or as a platform fee, which matters for a product sold to institutions ranging from a small credit union to a national bank. Category norm rather than a specific failing.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

The stated buyer set is broad and reads correctly for the problem: banks, fintechs, payment providers, and credit unions through the Curql initiative, with protection extending across digital, voice and in person channels. The distinction the index draws with Argos Identity applies here, and it is the reason for the grade. Published breadth describes what the platform is built to address, not who relies on it.

No institution of any size or type is named as a deployment, so the coverage claim cannot be checked at a single point. Channel breadth across voice and in person is a real differentiator if evidenced, since most scam controls in this lane sit only in the digital channel.

Alternatives to Charm Security

The closest documented capability profiles to Charm Security in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Core Systems and Integration Depth where Charm Security does not

Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Charm Security does not

Documents Operational and Outcome Evidence and Commercial Transparency, among others where Charm Security does not

Documents GLBA and Data Privacy Posture and Autonomy and Oversight Model, among others where Charm Security does not

Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Charm Security does not

Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Charm Security does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746