CredoLab
CredoLab scores creditworthiness from smartphone device metadata for banks, consumer finance companies, auto lenders, online and mobile lenders, insurers and retailers, aimed at applicants with no credit file. A white labelled app or embedded kit collects behavioural signals only after explicit opt-in, covering application ownership patterns, device model and age, contact and message counts, file sizes and interaction habits, and the company states no personally identifying information leaves the device and that it never learns an applicant's name, address or number.
Models built on more than 21 million loan applicants across 70 lending partners have supported over a billion dollars of lending in more than 20 countries, with behavioural patterns learned across 50. A 2025 income prediction model estimates earnings from thousands of anonymised signals, and institutions can train it on their own local populations.
Capability Axes
Capability grades
15 of 15 axes rated · 9 graded A or B
The removal test leaves device metadata with no meaning attached, which is the entire proposition. Models convert application ownership patterns, device characteristics, contact and message counts and interaction habits into a creditworthiness signal, and a 2025 addition estimates income from thousands of anonymised behavioural signals shown to correlate with earnings. Institutions can retrain those models on their own populations. Deriving a credit assessment from the shape of someone's phone use is achievable no other way.
The company positions itself as an addition rather than a replacement and its chief product officer states the limit clearly, that banks still carry out their ordinary income and identity verification while this provides a complementary assessment conducted at a behavioural level rather than a compliance or transactional one. The score enters an existing decision rather than becoming it.
Held at B because nothing describes what weight lenders give the signal, whether a low behavioural score alone can decline an applicant, or what review applies when it contradicts conventional evidence.
The training base is unusually large and stated, over 21 million loan applicants across more than 70 lending partners and roughly a trillion data points, which matters because behavioural scoring is only as good as the outcome data behind it. Per client retraining on local populations addresses model transfer, the failure that undermines imported scorecards. A partner reports up to 40 percent uplift when the signal is combined with fraud detection.
The company is also candid that earlier alternative data attempts failed on predictiveness, which frames the claim honestly. What is missing is any accuracy, lift or validation figure for the models themselves, and no explanation is offered of how a behavioural score can be reasoned about by the lender relying on it.
The volume figures are among the largest in this index: models built on more than 21 million loan applicants across over 70 lending partners, more than a billion dollars of lending supported, roughly a trillion data points analysed, and behavioural patterns learned across 50 countries having started from 21.
Two customers are named publicly, a Philippine bank's digital lending business from 2019 and a regional financial comparison platform, and a partnership with a listed fraud and identity company reports up to 40 percent uplift in combined credit and fraud protection. The company has operated since 2016 and notes plainly that its banking clients have generally declined to be named.
One explicit control exists and it is a good one: individual institutions can train models on their own datasets and customise them to the characteristics of their local populations, so a lender's scoring is not simply inherited from other people's borrowers. Against that the company also markets behavioural patterns learned across 50 countries as an immediate advantage applied to new markets, which is a shared layer by definition.
Both are stated and the boundary between them is not, so nothing describes what a client contributes, what it draws from the pooled patterns, or what happens to a scored applicant's signals afterwards.
The privacy position is stated in architectural terms and it has to be, given the data source. Collection occurs only after explicit opt-in, expressed by the company as no consent, no collection, full stop, under a stated data processing agreement.
What leaves the device is metadata rather than content: the company states no personally identifying information ever leaves the handset and that it does not know an applicant's name, email, address or telephone number, and that its income model never accesses identifying data. Messages are not read and contacts are counted rather than captured. For a product that asks permission to inspect a person's phone, defining the boundary at the device is the strongest available answer.
No attestation, certification, trust centre or enumerated framework was located. One control is described, use of a one time password as a unique identifier to confirm the applicant is the handset's owner, which addresses a specific fraud vector rather than constituting an assurance programme. Banks in more than 20 markets have completed supplier assessment on a product that reads device data, so the underlying review has been demanding and none of it is published.
A data processing agreement is cited and no regulator, statute or supervisory framework is named anywhere, which is a notable gap for a product operating across more than 20 jurisdictions with materially different rules on device permissions, consent validity and alternative data in credit decisions.
The regulatory environment for this specific technique has moved, with a major platform operator restricting the permissions personal loan applications may request in several of the markets where such scoring is most used, and none of that context appears in published material.
This is the sharpest two sided case in the index. The inclusion argument is genuine: around two billion adults lack formal financial access, conventional scoring cannot assess them at all, and income prediction addresses precisely the missing proof of earnings that excludes people with no payslip. Local model calibration reduces the risk of importing one market's assumptions into another. The unaddressed side is severe.
Consent is borrowed rather than independent, as the company itself describes, noting that its application is downloaded only during a specific credit application and that if the user trusts the bank they trust the vendor, and it is sought from first time borrowers under time pressure in markets where literacy varies.
More fundamentally the signals include device model and age and application ownership, which are proxies for wealth: the price of an applicant's phone becomes an input to their credit decision. No fairness testing, no analysis by device tier and no adverse outcome data is published.
No guarantee, indemnity or correction process was located. The applicant's only real control is at the point of consent, where they may decline, though declining during a credit application carries an obvious cost. Beyond that they have nothing: someone scored down because of an older handset, an unusual application mix or sparse contacts will not be told that device metadata influenced the outcome, cannot see which signals counted, and has no route to contest or correct a behavioural inference about themselves.
The input side is described with more candour than most vendors manage, since the source is the applicant's own device and the company enumerates what it reads, covering application ownership patterns, device model and age, message and contact counts, file sizes and interaction habits, while stating what it does not read. That specificity lets a buyer and in principle a regulator assess the method. There is no external data dependency to disclose, which is itself the point of the approach. No model provider, hosting arrangement or subprocessor list appears.
Delivery is deliberately flexible, offered as a white labelled application the lender brands, as an embedded development kit inside an existing journey, and through a partner's orchestration layer that performs data callouts to the scoring service, with the company describing the product as modular and fitting into existing workflow. That variety matters because the collection point must sit inside the lender's own application flow to obtain consent credibly. No named core banking, origination or bureau system appears.
No general hosting, region selection or residency policy was located. One instance is documented through a partner arrangement, where the scoring service is described as hosted locally in the market being served, which suggests in country deployment is available. That is a single example rather than a stated policy, and for a vendor operating across more than 20 jurisdictions collecting device derived data, a published residency position would matter considerably.
No pricing, packaging or basis of charge was located. The delivery model spans a white labelled application, an embedded kit and interface access through a partner's orchestration layer, which would ordinarily price differently, and nothing indicates whether charge falls per scored applicant, per approved loan or by subscription.
Buyer coverage is unusually wide and precisely enumerated, spanning banks, consumer finance companies, auto lenders, online and mobile lenders, insurance companies, retailers and, through a partner integration, mobile wallets. Geographic reach is genuinely global for a company of this size, with lending supported across more than 20 countries and behavioural patterns calibrated across 50, concentrated in emerging and digital first markets where the underlying problem is most acute. The signal is applied to underwriting, fraud and income estimation.
What Changed
Material product, regulatory, evidence and commercial changes at CredoLab, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
CredoLab's behavioural credit scoring is now live as an integration on the FICO Marketplace.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to CredoLab
The closest documented capability profiles to CredoLab in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Regulatory Status and Licensure and AI Governance and Bias Disclosure where CredoLab does not
Documents Security Certifications and Trust Center where CredoLab does not
Documents Deployment Model and Data Residency where CredoLab does not
Documents Regulatory Status and Licensure and AI Governance and Bias Disclosure where CredoLab does not
Documents AI Governance and Bias Disclosure where CredoLab does not
Documents Regulatory Status and Licensure and AI Governance and Bias Disclosure where CredoLab does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.