C

Credora

Credora, operating as Credora by RedStone since its September 2025 acquisition by the oracle network RedStone, produces credit risk ratings for on chain lending markets on a single A plus to D scale covering tokens, lending pairs and vaults. Its methodology maps to the probability of default curves used in traditional structured credit analysis, runs one hundred thousand Monte Carlo simulations per market, and is stated as calibrated on more than thirty years of credit data. The firm publishes each rating framework openly while stating plainly that the underlying algorithm remains proprietary.

Ratings are distributed through RedStone's oracle infrastructure alongside price feeds, so a protocol can query price and risk in a single call, with named integrations at the lending markets Morpho and SparkLend and public application programming interface endpoints. Its privacy preserving architecture, documented publicly, runs the real time data unit and key management inside Intel Software Guard Extensions enclaves using the open source Gramine runtime, chosen so that its security can be independently verified, alongside zero knowledge proofs in the credit scoring pipeline.

Founded in 2019 as X-Margin by Darshan Vaidya and Matt Ficke, it raised 14 million dollars from backers including Coinbase Ventures, S&P Global and HashKey before the acquisition, and relaunched public ratings in November 2025.

Last VerifiedAugust 19, 2026
Compare Credora with other vendors
Founded
2019
Headquarters
Categories
crypto-and-digital-assets, capital-markets-ai, credit-decisioning
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test leaves nothing at all. There is no product underneath the rating: the entire output is computed, with one hundred thousand Monte Carlo simulations run per market and scores updating continuously as collateral mixes and liquidity conditions shift. No analyst writes a report here and there is no prior non modelled business, unlike the ratings houses this firm is measured against. Strip the quantitative layer and what remains is an empty distribution rail. The consensus ratings protocol and the probability of default engine are the company.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

This is the most fully automated decision chain encountered in this pocket and no control anywhere in it is described. A rating is computed without human involvement, delivered through an oracle without human involvement, and consumed by lending markets that use it to inform credit decisions and automated controls and to adjust parameters dynamically rather than on static assumptions. Every stated benefit of the design depends on taking people out of the loop.

Nothing describes a materiality threshold before a score change propagates, a delay or confirmation step, a circuit breaker if inputs behave anomalously, an override route for a consuming protocol, or any review of a rating before it moves capital. A published methodology explains how a score is reached; it is not a control over what the score then does.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

The boundary of disclosure is drawn explicitly and in the vendor's own words, which is rarer in this index than disclosure itself: every rating framework is publicly documented covering what is measured, why, and what the output means, while the underlying algorithm is stated to remain proprietary. Naming precisely where transparency stops is a more honest posture than the vague assurances that are the norm on this axis.

The methodological anchoring is described rather than gestured at, mapping to the probability of default curves used in traditional structured credit analysis with a stated calibration on more than thirty years of credit data. Held off the top grade because that calibration is asserted and never evidenced: no back test, no realised default comparison, no accuracy figure and no artificial intelligence management system certification, and no validation pack is offered to an institution that would have to defend the rating internally.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Named counterparties with real capital behind them, and no named customer with a measured result. The integrations at Morpho and SparkLend are substantial lending markets and are corroborated by independent trade press rather than only by the vendor.

Named executives are quoted on the record, including RedStone's co-founder and Credora's own co-founder, and the investor base carries weight of its own, with Coinbase Ventures, HashKey and S&P Global having taken positions before the acquisition and RedStone having done acquisition diligence with money at stake.

The outcome claim that rated vaults on Morpho grow faster and retain capital better than unrated peers points the right way and arrives without a single figure attached, and no default study, calibration result or back test has been published against a methodology that asserts thirty years of credit data behind it.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The dual position shape appears here in its sharpest form yet in this index, and unusually the commercial motive is stated by the owner in writing rather than inferred. The rater is owned by the oracle network that distributes the ratings and sells price feeds to the same protocols being rated, and the acquisition rationale published by that owner describes price, ratings and collateral intelligence as together forming a strong competitive moat that makes it the most differentiated oracle in the market.

A protocol's rating and its choice of data infrastructure therefore sit inside one commercial relationship. Nothing describes what separation exists between the rating judgement and the infrastructure sales interest, whether a protocol's oracle spend is visible to the rating process, or whether a market can be rated at all without consuming the owner's feeds.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The privacy engineering is real and its relevance to the current product is unestablished, which is why it is not credited here. The original design used zero knowledge proofs alongside enclave computation so that a borrower's positions could be scored without being revealed to the scorer, which is privacy by construction of a kind this index rarely sees.

That architecture was built for an institutional credit scoring business that the acquisition substantially reshaped, and today's published product rates vaults, pools and tokens largely from public chain data, where the privacy question barely arises. No privacy policy, data processing agreement, subprocessor list or retention schedule was located, and nothing states what confidential counterparty data, if any, the platform still ingests.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

No certification or attestation was located, and what stands in its place is more technically checkable than most certified vendors provide. The privacy preserving architecture is documented publicly at component level: the real time data unit and the key management system run inside Intel Software Guard Extensions enclaves under the Gramine runtime, with the published reasoning stating that Gramine was selected partly because it is open source and its security can therefore be neutrally verified rather than taken on trust.

That is a disclosure act rather than a badge, and a buyer can inspect the claim independently. Held at this grade rather than higher because no audited attestation exists, and because the architecture documentation predates the September 2025 acquisition and the subsequent product relaunch, so whether it describes the current rating platform is not established anywhere. Worth confirming on a later pass.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

The firm publishes letter grade ratings on an A plus to D scale and holds no credit rating agency registration. Independent research covering this category records the established agencies alongside it as registered under the United States nationally recognised statistical rating organisation regime and on the European securities regulator's register, and records no equivalent standing here.

One structural detail is worth stating plainly rather than drawing a conclusion from: S&P Global, itself a registered rating agency, took an investment position in this unregistered one. No sandbox participation, supervised test or regulator programme admission was located.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness testing, differential outcome analysis or coverage bias assessment is published, and the vendor's own evidence establishes why it would matter. The claim advanced for the product is that rated vaults grow faster and retain capital better than unrated ones, which is an assertion that a rating causes allocation rather than merely describing risk.

On that account, which market gets rated first, which is left uncovered, and how the rated universe is selected are decisions that move capital, and none of them is described. The consensus ratings protocol is named repeatedly without stating whose views form the consensus, how they are weighted, or what happens when they diverge.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No liability position, error rate, correction path or appeal route is published, against a consequence chain that is automated end to end. A computed score propagates through an oracle into a lending market that adjusts parameters on it, so a wrong rating reaches capital without passing any person, and the party who bears the loss is a lender in a vault who has no relationship with the rater and may not know a rating was involved.

Oracle delivered data driving automatic financial action is a well documented failure surface in this market, and the ratings were themselves relaunched in the weeks after a liquidation event of roughly twenty billion dollars. Nothing states where responsibility sits between the rater, the oracle network that distributes the score, the protocol that acts on it and the allocator who relied on it.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The disclosure here runs the opposite way to the index norm and still lands in the same place. Most vendors describe their models in some form and say nothing about the infrastructure beneath them. This one names its silicon and its runtime precisely, down to Intel Software Guard Extensions enclaves and the open source Gramine runtime with its manifest based configuration, and names nothing about the models themselves: no provider, no family, no version, no statement of whether any component is licensed from a third party or built in house. The execution layer is unusually well disclosed and the modelled layer is not disclosed at all.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

The distribution architecture is the strongest thing about this vendor and it is specific, named and live. Ratings travel through RedStone's oracle infrastructure alongside price feeds, so a consuming protocol queries price and risk in a single call rather than reconciling two sources, and the stated design intent is that risk data becomes a default property of the data layer rather than a separate lookup.

Named integrations at Morpho and SparkLend are live, public application programming interface endpoints are available to partners, and Spark surfaces both real time ratings and risk profiles inside its own front end. Reaching dozens of protocols through infrastructure that is already installed is a materially deeper integration position than a data feed a buyer must wire up.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting regions, residency commitments or tenancy model are published. Delivery is through a public application programming interface and through oracle feeds that publish scores on chain, which is a stated and deliberate design rather than an omission, and it is the only part of the deployment picture described anywhere.

The enclave based architecture implies specific hardware requirements and therefore constrains where computation can run, and no statement connects that to any jurisdiction. The question is sharpened by an unresolved corporate one: the operating entity's location after the acquisition is not stated in any material reviewed.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, tier structure or billing basis is published, which is the index norm, and the more consequential omission is who pays for a rating. Whether a protocol or vault curator commissions and funds the assessment of its own market, or an allocator subscribes to independent coverage, determines where the conflict sits in any ratings business, and nothing states which model applies.

The published material describes ratings as freely propagating to protocols through infrastructure those protocols already pay for, which suggests a third arrangement again and describes none of them.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

The stated buyer set is broad and the evidenced one is not. Published positioning addresses institutional allocators directly, and independent coverage adds custodians, insurers and institutional desks mapping scores to capital and margin frameworks, but no institution of any type is named as a customer. What is evidenced is a single segment: on chain lending markets, with Morpho and SparkLend as the named integrations and distribution to protocols already consuming RedStone oracle feeds. That is genuine reach inside one narrow slice of one asset class rather than coverage across institution types, and the grade reflects the evidence rather than the ambition.

Alternatives to Credora

The closest documented capability profiles to Credora in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not

Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not

Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not

Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not

Documents Institution and Segment Coverage and Autonomy and Oversight Model, among others where Credora does not

Documents Institution and Segment Coverage and GLBA and Data Privacy Posture, among others where Credora does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746