Cotribute
Cotribute sells a digital growth platform to credit unions and community banks that layers onto the core, loan origination and digital banking systems an institution already runs rather than replacing them. Its modules cover consumer and business account opening, consumer and business lending applications, fraud screening and decisioning with more than 70 configurable rules, and a back office portal with analytics. Accounts write back in real time to Jack Henry, Corelation and Fiserv cores, and account opening typically goes live in about 30 days.
Since June 2025 three AI Growth Agents have run on top: one for acquisition targeting, one for cross sell during onboarding, and one that re engages single product members using credit and income data. Every agent recommendation needs staff approval before it reaches a member. A read only connector lets staff query origination data from the AI assistants they already use.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
The removal test leaves almost the whole platform standing, and the precedent is the one applied to MeridianLink. Strip out the three AI Growth Agents and the read only assistant connector, and consumer and business account opening, lending applications, a fraud engine of more than 70 configurable rules, real time core integrations and the back office portal all still work.
The vendor's own framing agrees: it describes itself as a growth platform that layers onto existing systems, and the agents arrived in June 2025 on top of a business with clients of eight years or more. The agents are real and in production, which makes this a platform with an AI layer rather than an AI product.
Oversight is a property of a path here, and the two paths differ. On the agent path the control is stated as a hard rule and placed before the member: every recommendation needs staff approval, there are no autonomous actions, agents are validated in a sandbox on real data before promotion, and the assistant connector is read only. That path clears the A bar.
On the decision path, 89.5 percent of applications at one client are decisioned instantly by configurable rules, with staff reviewing the exceptions. Those rules are the institution's own policy rather than a model, which is legitimate control, but nothing states whether an applicant can be declined without a person seeing the file, and that knockout is the point this axis weighs most.
A testing step is described and sits in the right place, but it measures the business result rather than the model. Agents deploy first to a governed sandbox on the institution's real data for about ten days and are promoted to production with dashboards for lift, savings and audit trails, so an institution sees outcomes before members see anything.
Lift is not accuracy: no error rate, validation method or false positive rate is published for any agent, and the headline claim of 5X faster growth rates states no baseline and cannot be checked. The same distinction held Personetics at C.
The A bar met several times over, with named institutions carrying quantified outcomes and a chief executive quoted by name. Capitol Credit Union of Texas reports about 10,000 dollars in new deposits per account opened, a 70 percent cut in processing time and a 59 percent lift in memberships. Nutmeg State FCU automated 97.6 percent of manual origination steps and decisions 89.5 percent of applications instantly.
CPM FCU, at 650 million dollars in assets, cut manual review effort 82 percent while opening 32 percent more accounts in 90 days, and Red River Credit Union reports a 28 percent lift in monthly loan applications. One attribution problem is worth recording: the Capitol figures are credited to the account opening product on its own page and to the AI Growth Agents on the agents page, so none of this evidence isolates what the agents themselves add.
The published commitment answers a narrower question than this axis asks. No member data in public models addresses exposure to consumer AI services, and it is stated consistently across the site. Nothing states whether one institution's data improves agent outputs for other clients, several of which compete for the same members, and the acquisition agent is described as showing how an institution's products compare in the market, which implies a data source it does not name.
The assistant connector also passes masked origination data into third party assistants such as Copilot, Claude and ChatGPT, so whether that counts as member data in a public model is left for the buyer to work out.
Specific commitments are published where the AI touches member data. The vendor states that no member data goes into public models, the assistant connector masks personal information by default, and every connector query is audited and retained for seven years. The trust center is described as carrying the due diligence package a risk team will request.
Held at B because no data processing terms, subprocessor list or general retention schedule was located in the pages swept, and masking by default means it can be switched off, with nothing stating who decides.
A standing trust center and an ungated report, with the noun wrong. The vendor states that its SOC 2 Type 2 report and security documentation are available at its trust center without a gate, alongside a public status page, and the trust center itself is live on a compliance automation platform. It calls the report a certification, which it is not, since a SOC 2 examination produces an attestation over a period.
The badge row beside it mixes the security claim with partner programmes (Jack Henry VIP, Corelation Preferred, Banno Certified, Fiserv AppMarket, FIS GKYC), none of which is a security certification. The report period and scope were not visible in the pages swept. Held at B, below the A bar of dated reports per product line.
Not licensed and not claiming to be; it supplies software to institutions that are. What lifts it above the usual supplier position is that it names the rules its product puts into practice: FinCEN customer due diligence beneficial ownership collection, OFAC screening, KYC and KYB checks, and Secretary of State verification in business account opening. It also addresses NCUA's supervisory attention to AI directly and maps its agent architecture to what examiners ask. Held at B because no regulator engagement of its own is described.
A governance posture is published and a bias position is not, on agents where the bias exposure is concrete. The relationship growth agent re engages members using credit and income data, the cross sell agent surfaces the next best loan product with offers already computed, and the acquisition agent chooses which personas an institution targets.
Credit offers and marketing targeting both sit inside fair lending and unfair practices law, and nothing published covers fairness testing, disparate impact analysis or how personas are built. Staff approval of every output is the mitigation on offer, and it is real, but a reviewer approving one campaign cannot see how the targeting falls across groups.
No indemnity, warranty or correction commitment was located. Accountability is reconstructable, since every agent output is approved by staff and connector queries are audited for seven years, and requiring approval before anything reaches a member keeps responsibility with the institution that holds the charter. Nothing covers the vendor's own failure, and nothing describes a route for a member who receives a wrong offer or is wrongly screened out.
The architecture is described in categories and the suppliers are not named. The agents are said to combine deterministic, generative and agentic components with human review, and the promise that member data stays out of public models implies private or contracted model access, but no model provider, family, hosting arrangement or subprocessor is identified. The assistant connector names the third party assistants it works with, which is the customer's own supply chain rather than the vendor's.
Integration is named down to the product, which is the A standard. Real time connections run to Jack Henry Symitar, SilverLake, CIF 20/20 and Core Director, to Corelation KeyStone, and to Fiserv DNA, XP2, Portico and Premier, among more than 36 direct API integrations, with accounts written back to the core without manual re entry and nothing about the core environment changed. Partner standing is stated with each of those providers, including Banno certification. The assistant connector adds read only access from Copilot, Claude, ChatGPT and other assistants built on the Model Context Protocol.
Hosted software with a documented time to live and nothing on where it runs. Account opening goes live in about 30 days and lending modules in 45 to 60 depending on core, and a public status page reports uptime without a gate. No hosting provider, region, residency commitment or dedicated deployment option was located, which is the question an examiner asks about member data.
The basis of charge is published in full, which this axis rarely sees. An annual platform subscription is tiered by assets under management rather than application volume, each module is a separate line item with a one time implementation fee, core integrations are included with no connector charge, applications are not metered inside a tier, and bundles lower the per module cost.
Two list prices are public: the assistant connector's Plus tier at 9,600 dollars a year, with its Starter tier included alongside the AI Growth Agents, and a half day executive seminar at 5,000 dollars. Held at B because no platform fee or tier boundary is published, so a buyer can model the structure but not the number.
Two institution types, each served in its own terms. Credit unions get field of membership eligibility, SEG onboarding and member language throughout, and community banks get business account opening with KYB checks and beneficial ownership collection. Deployments are described from 100 million dollar credit unions to enterprise scale, and functional coverage spans consumer and business deposits and consumer and business lending. Held at B because coverage is domestic and the institution range stops at credit unions and community banks.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Cotribute
The closest documented capability profiles to Cotribute in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Cotribute
Documents AI Liability and Recourse where Cotribute does not
A lighter documented profile than Cotribute
Stronger documented coverage on Institution and Segment Coverage
Stronger documented coverage on Institution and Segment Coverage
Stronger documented coverage on Institution and Segment Coverage and Security Certifications and Trust Center
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.