Codat
Codat standardises small business financial data behind one integration for lenders, commercial banks, neobanks and card issuers. Its Underwriting and Monitoring product connects to a borrower's accounting, banking and commerce platforms through consented authorisation, then delivers standardised statements, enriched transactions and liability summaries on demand for initial underwriting, periodic review and portfolio monitoring. Machine learning trained across more than 100,000 businesses categorises transactions using business rather than consumer categories and standardises charts of accounts so ratio analysis can run automatically. A newer Insights tier sells working capital, spend and foreign exchange analysis to bank card and treasury teams.
Capability Axes
Capability grades
15 of 15 axes rated · 7 graded A or B
Machine learning is real, shipped and material, and it is a layer on a pipe. Models trained across more than 100,000 businesses categorise bank transactions into spend and income classifications using business rather than consumer categories, and standardise charts of accounts so ratio analysis can run automatically, which is what turns a raw accounting feed into something an underwriter can use.
Strip the models and the company's identity survives whole: a universal integration to more than 20 accounting, banking and commerce platforms, a standardised schema, bidirectional write back and bank feeds. That was the original product and it remains most of what a lender buys.
Same position as LeapXpert, where the models supervise a messaging platform that worked before them, and clearly above the floor that rejected 10X Banking because this enrichment is inside the delivered product rather than tooling beside it.
Autonomy exposure is structurally low because the product supplies inputs rather than making decisions, and the company is explicit that analysis ready data flows into the customer's existing underwriting systems and decisioning models.
The judgement that does happen automatically is categorisation, and it is unsupervised in the published account: no confidence score is exposed on a classified transaction, no review queue exists for ambiguous entries, and no mechanism is described for a lender or a business to correct a miscategorised item.
Data integrity checks are named as a feature, which is a genuine control on completeness and consistency, but that checks whether the data holds together rather than whether the model read it correctly.
One genuine mechanism and one clear absence. Data integrity checks are offered as a named product feature, which gives an underwriter a way to test whether the delivered financials are complete and internally consistent before relying on them, and that is more than most data suppliers provide.
What is missing is any measurement of the model itself: no categorisation accuracy rate, no error analysis by platform or business type, no confidence exposure on individual classifications and no validation documentation. A lender using this output inside a credit model inherits an unmeasured component, and its own model risk function will be asked to validate a categorisation layer it cannot see.
One institution is named and it is a substantial one: BMO as launch partner for the Insights suite when the advisory intelligence tier for commercial banking launched in May 2026. The training corpus is a second checkable scale figure, with models trained across more than 100,000 businesses, and integration timelines are stated concretely at four to eight weeks for most lenders, which a reference call falsifies immediately.
Against that, no other institution is named, no volume of businesses connected or loans underwritten is published, and no outcome figure exists for approval rates, time to funding or underwriting cost, despite those being the stated benefits. The company has been operating since 2017, so the absence of measured customer outcomes is a choice rather than a stage of life.
The training arrangement is disclosed in passing and never governed. Models are stated to be trained across more than 100,000 businesses, which means categorisation improves for every customer using financial data supplied through other customers' borrowers, and that is cross customer learning by construction.
Nothing published states whether the training corpus is aggregated and de identified, whether a lender can opt its connected businesses out, whether the consenting business is told its data trains a shared model, or what a competing lender on the same platform benefits from. This is the CLARA Analytics contributory database shape without CLARA's candour about it, since CLARA markets the pooling openly while here it appears as a capability statement about model quality.
The strongest privacy position in this lane and it rests on architecture rather than policy. Connections run through authorisation flows requiring the business's explicit consent, and the company states plainly that it never stores banking credentials, so the access token model replaces credential custody entirely. Encryption is named and the general data protection regime is named as applying.
The property that distinguishes this from almost every vendor in this index is who consents: the small business whose accounting, banking and commerce data is pulled authorises the connection itself and can withdraw it, so the data subject is a party to the arrangement rather than an unwitting one. Compare the recurring shape elsewhere here, where the person being profiled has no relationship with the vendor and no knowledge of it. Held at B rather than A because no retention schedule, subprocessor list or deletion commitment was located.
The strongest vendor published security position in this index and the second A on this axis after TRM Labs, which reached it through a third party compilation rather than its own material. Two frameworks are named rather than gestured at: the international information security standard in its current revision, described as held with a current certificate of registration, and a service organisation control type two certification, alongside 256 bit encryption and the general data protection regime.
The consent architecture reinforces it, since credentials are never stored and access runs through revocable authorisation, which removes the highest value target from the vendor's estate entirely. A buyer can name and check both frameworks without entering a sales conversation, which is the bar this axis sets.
The general data protection regime is named as applying and no other supervisor, statute, rule or admission process appears. The gap is specific for this vendor type: a business supplying bank feeds into accounting software and pulling banking data on consent operates adjacent to the regulated data access regimes in its two main markets, and those regimes carry their own authorisation and conduct requirements.
Nothing published states which of those apply, whether any registration is held, or how the consent flow maps to the standards those regimes impose. Codat holds no lending or banking licence and needs none, which is the correct posture for a technology supplier under the index convention.
This vendor supplies the inputs to credit decisions rather than making them, which is why it does not sit with Alloy, Taktile and their peers on this axis, but the exposure is real and one layer removed. A model that categorises revenue and expenses determines the ratios an underwriter reads, so a misclassification changes an approval outcome without anyone seeing a model in the decision.
Accuracy of categorisation will not be uniform: models trained across a corpus of businesses perform worst on the business types least represented in it, which correlates with sector novelty, size, informal record keeping and non standard accounting conventions, and those are the same businesses already least well served by credit. No per sector or per platform accuracy is published and no analysis of where categorisation degrades was located.
No guarantee or indemnity on categorisation quality was located, so the vendor makes no commercial commitment to its output. What earns the grade is a real control held by the party whose data is at stake, which is uncommon in this index. The business grants access through an authorisation flow it initiates and understands, and that connection can be withdrawn, so the subject can end the data relationship unilaterally rather than petitioning anyone.
On the buyer side, data integrity checks give a lender a way to detect defective input before acting on it. What neither reaches is the borrower whose ratios were computed from a miscategorised ledger and who was declined on that basis, since nothing describes correction of a classification or notification that one drove an outcome.
The data half of the chain is enumerated in unusual detail, with more than 20 source platforms named individually across accounting, commerce and payments, so a buyer can establish exactly where each field originates and which upstream systems its underwriting depends on. That is the disclosure this axis exists to elicit and it is published rather than offered on request.
The models are described as the company's own, trained on its accumulated corpus, which shortens the chain at the point that matters. What is not stated is whether any external model provider participates in categorisation or in the newer analytical products, and no subprocessor list was located, which is the remaining question a bank examiner would put.
Integration is the product and it is documented to a standard nothing else in this index matches. More than 20 platforms are named individually across accounting, commerce and payments, including the major small business ledgers and marketplace and commerce systems, reached through one integration. The connection is bidirectional rather than read only, with write back of bills, payments and expenses into the connected platform and bank feeds pushing transactions the other way.
Software development kits are published in five named languages alongside full public documentation and machine readable interface specifications, and typical lender integration is stated at four to eight weeks. A buyer can evaluate the entire integration surface without contacting sales, which is rare here and is what an A on this axis should mean.
No hosting provider, region selection, residency commitment or private deployment option was located. The general data protection regime is named as applying, which implies European handling arrangements exist, but naming a regime is not a residency statement.
The question is live for a vendor headquartered in the United Kingdom selling to United States lenders while holding small business accounting and banking records on both sides, and nothing published tells a buyer where connected business data rests or whether it can be constrained.
No pricing, packaging or basis of charge is published for either tier. The question matters more than usual for this product because the natural units, per connected business, per data pull or per platform, produce very different economics for a lender monitoring a portfolio continuously rather than pulling data once at application. Continuous monitoring is explicitly marketed, so a buyer cannot tell whether the cost of the product scales with the frequency of the behaviour the vendor is encouraging.
The buyer set is wide and the documentation states that the lending solution caters to financial institutions of any size, naming digital lenders, banks, neobanks, corporate card providers and payment providers. The Insights tier adds a second buyer inside the same institution, selling working capital, spend and foreign exchange analysis to commercial bank card and treasury teams rather than to credit.
Serving both the credit function and the treasury function of the same bank is genuine breadth. What is not evidenced is geography: the company operates from the United Kingdom with an evident United States presence, and no coverage in other regions is demonstrated, which matters because the underlying accounting platform mix differs sharply outside those markets.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Codat
The closest documented capability profiles to Codat in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents AI Centrality and AI Safety and Data Stewardship, among others where Codat does not
Documents AI Centrality and Autonomy and Oversight Model, among others where Codat does not
Documents AI Centrality and Autonomy and Oversight Model, among others where Codat does not
A lighter documented profile than Codat
Documents Commercial Transparency and AI Safety and Data Stewardship, among others where Codat does not
Documents AI Centrality where Codat does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.