Detected
Detected is a London business verification and onboarding platform founded in July 2020 by Liam Chennells and Nathan Kelleher, positioning itself as a trust platform answering whether a business or individual can be trusted, across onboarding, screening, monitoring and decisioning. It has raised roughly 10.1 million dollars across seven rounds from investors including EmergeVest, Love Ventures and Thomson Reuters Ventures.
The platform is built around three areas: case management holding risk profiling, forms, documents and screenings, an orchestration engine that routes, validates and sequences the outputs of third party providers, and a no code workflow builder that lets compliance teams change onboarding journeys by customer type, product, jurisdiction or risk tier.
It integrates directly with more than 190 company registries, maps beneficial ownership to natural person level through multi layer structures, verifies business domains against WHOIS records, screens entities and associated parties against sanctions, politically exposed person and law enforcement databases, and onboards not only companies but charities, trusts, funds, partnerships, sole traders, syndicates, clubs and associations. Individual verification covers more than 16,000 document templates with passive liveness and biometric matching.
Eleven named providers run natively inside the platform, among them ComplyAdvantage, Dun and Bradstreet, LSEG, Moody's, Trulioo, GBG, OpenCorporates, Kyckr, AsiaVerify, Resistant AI and Anthropic. Named customers include Zelis, DailyPay, Gumtree and Purolator, with Visa and GBG as partners, GBG jointly marketing a co branded product called GBG Detected.
Its published AI position is unusually specific: every AI feature is opt in, the AI is stated to act in an advisory role surfacing insights rather than verdicts with human sign off enforced at every point, reasoning is presented as explainable so analysts can challenge it, and six named controls cover guardrails, prompt injection protection, hallucination controls, continuous monitoring with anomaly detection and quality scoring, consumption management and full audit logging of what was asked, what was returned and who acted. It also runs a Model Context Protocol server letting customers connect their own agents to its data.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
An orchestration platform with a genuine agentic layer built on top, graded the same way as the other orchestration shaped vendor in this pocket for consistency. The company describes its own engine plainly as routing, validating and sequencing the outputs of eleven third party providers, and strip the models and that engine survives, along with case management, the no code workflow builder and direct integrations to more than 190 registries.
What the models add is real and growing: a managed compliance agent that works a case and prepares a full profile before a human sees it, real time validation as a customer submits, and document translation with side by side review. Held above a C because the agentic layer performs analytical work rather than decorating a form, and below an A because the platform was a working compliance product before the agents arrived and would remain one without them.
The clearest human adjudication statement in this pocket, published as a principle rather than inferred from a product diagram. The company states that its AI performs an advisory role, surfacing insights and not verdicts, and that human sign off is enforced at every point. That names the adjudication layer and places it in the execution path, which is the route to an A this index established on idenfy. Three further elements support it.
Every AI feature is opt in and configurable, so the institution decides whether any autonomy applies at all rather than inheriting it. Reasoning is presented as explainable by default, with the stated purpose of letting an analyst challenge a recommendation rather than merely read it. And every AI interaction is logged with what was asked, what was returned and who acted, which makes the human sign off auditable rather than assumed. The limitation, recorded rather than deducted: none of this is independently attested, so a buyer is trusting a published design principle.
Measurement is clearly happening and no result is published, which is the same call made on the other agentic vendor in this pocket and is applied here for consistency. The company states that all AI outputs are logged, reviewed and monitored, with anomaly detection and quality scoring for ongoing reliability and accuracy, so an evaluation practice exists internally.
None of it surfaces: no accuracy rate, no false positive or false negative figure, no benchmark, no evaluation methodology, no model documentation and no validation pack for a customer's own model risk function. Explainability is offered at the level of an individual recommendation, which helps an analyst working a case, and does not tell an institution how the system performs across a population.
Four customers named and quoted directly about what they bought and why, plus a named executive at a partner speaking on the record and attributed quotes from Visa and ComplyAdvantage. That comfortably clears the B bar. It misses an A because not one quantified outcome appears anywhere: no onboarding time reduction, no completion rate, no volume, no cost figure, and no independent measurement. The testimonials describe efficiency and configurability in qualitative terms only. This is the fourth vendor in this session to name real customers and publish no number against any of them.
The two halves of this axis pull in opposite directions here and the grade reflects the stronger one. On safety, this is the most developed disclosure located anywhere in this index: six named controls, and one of them, prompt injection protection described as architecturally rejecting adversarial inputs that attempt to hijack AI behaviour with validated input handling at every layer, is the first named instance of that control found in this index at all.
The hallucination control entry is equally notable for its wording, describing structured prompts, constrained outputs and grounded data references that minimise the risk of fabricated output, which is the honest inverse of the elimination claims catalogued elsewhere in this pocket.
On stewardship there is nothing: no statement of whether customer data, uploaded documents or case outcomes train or improve models, and no statement of what the named external model provider may retain from material routed to it.
A privacy policy and a cookie policy, and nothing beyond them. No subprocessor list, which is a conspicuous gap for a platform whose entire architecture is routing customer and director personal data through eleven named third party providers, since each of those providers is a processor in the chain and the buyer would need them enumerated with terms. No retention schedule, no deletion commitment, no data processing agreement terms and no statement of how long verification records or collected identity documents are held.
No certification, attestation or trust portal was located. The platform material does carry engineering level security detail that is unusual to publish, including WCAG 2.1 AA accessibility conformance, rate limiting, cross site request forgery protection and stated sub 200 millisecond median response times, and the AI section describes prompt injection defence and input validation at every layer.
That is genuine technical hygiene and it is more than most vendors show, but none of it is an audited credential and this index has consistently declined to read engineering description as assurance. No SOC 2, no ISO certification, no penetration test disclosure and no report request route.
A software supplier outside the regulatory perimeter. No licence, registration, supervised sandbox participation or regulator run scheme was located. Its customers carry the anti money laundering obligations and the supervisory relationship. The co branded arrangement with a listed identity group and the collaboration with a card network are commercial partnerships and confer no regulatory standing, and this index has consistently kept commercial validation and supervisory status separate.
A published AI governance framework that is specific enough to hold a vendor to, which is rare here, set against a complete absence of fairness disclosure. The governance side states three principles, advisory rather than deciding, built with the industry, and transparent by default, then names six operating controls: guardrails on input and output, prompt injection protection, hallucination controls, continuous monitoring with anomaly detection and quality scoring, consumption management, and full audit logging.
Held at B rather than A on two grounds. None of it is independently audited, unlike the ISO 42001 holder in this same pocket, so it is a self published design description. And bias is not addressed at all: nothing examines whether registry matching, domain age checks, shell company risk indicators or high risk jurisdiction flags fall unevenly on businesses in markets with thinner or newer public records, which is the exposure this pocket carries.
Nothing states who bears the cost when a verification is wrong or how a business contests one. The enforced human sign off is meaningful here and worth recording, because it means a person at the regulated institution makes the decision rather than a model closing a case alone, which places responsibility more cleanly than an autonomous path would. But that helps the institution, not the business being judged.
A company flagged as a shell structure, marked dormant, or failed on a domain age or hosting anomaly has no relationship with the vendor, no notice that an automated indicator produced the finding, and no described route to challenge or correct it, and nothing says whether a correction reaches other institutions that ran the same check.
The model provider is named. Anthropic appears in the published list of providers running natively inside the platform, alongside the data and screening suppliers, which puts this vendor in the minority of this index that identifies where its inference comes from rather than calling the capability proprietary.
Naming it in the same list as the data suppliers is also the more honest presentation, because it treats the model as a dependency of the same class as the registry and screening feeds rather than as an internal capability. Off an A for the usual omissions: no model or version named, no country of processing, no statement of which content categories are routed to the provider, what that provider may retain, or whether any other model provider is used.
The deepest integration disclosure in this pocket by a clear margin, and it is specific rather than asserted. Direct integrations to more than 190 company registries worldwide for data at source. Eleven providers named individually as running natively inside the platform, covering screening, corporate data, identity and document fraud: ComplyAdvantage, Dun and Bradstreet, LSEG, Moody's, Trulioo, GBG, OpenCorporates, Kyckr, AsiaVerify, Resistant AI and Anthropic.
The routing behaviour between them is described rather than implied, with an orchestration engine that sequences and validates provider outputs under one policy set. It also exposes a Model Context Protocol server so a customer's own agents can reach its data with auditing, which is a forward integration surface almost nothing in this index offers. The usual caveat still applies and is recorded rather than penalised: no core banking, lending or customer system on the buyer's own estate is named as a connection target.
A hosted multi tenant platform with a white label customer portal, and no published residency or deployment choices. No region selection, no cloud provider named in the vendor's own material, no single tenant or private option, and no statement of where verification records or the identity documents of directors and beneficial owners rest. The published sub 200 millisecond global median response time is a performance characteristic and says nothing about where data sits. The gap matters because the architecture routes personal data through eleven named providers across several jurisdictions.
No pricing published at any level, and no indication of the charging basis, which is a live question for an orchestration platform because each of the eleven bundled providers is separately metered and the buyer cannot tell whether cost follows checks, entities, seats or subscription. The one commercial claim made is a deployment promise rather than a price, that the platform is live in weeks. Every route terminates in a contact form.
Four named customers with attributed testimonials, Zelis, DailyPay, Gumtree and Purolator, alongside a wider logo wall spanning money transfer and foreign exchange, open banking, gaming, travel expense and logistics. Coverage breadth is genuine in an unusual dimension: the platform onboards not only companies but charities, trusts, funds, partnerships, sole traders, syndicates, clubs and associations across more than 190 jurisdictions, and entity type breadth of that kind is rare in this pocket.
Held at B for two reasons. The confirmed customer count is small, and the logo wall mixes customers with suppliers and cloud vendors, so the apparent breadth is larger than the evidenced breadth. Two of the four named customers are also a marketplace and a logistics company rather than regulated financial institutions.
Alternatives to Detected
The closest documented capability profiles to Detected in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Model Risk Management and Transparency and AI Liability and Recourse where Detected does not
Stronger documented coverage on Operational and Outcome Evidence
A lighter documented profile than Detected
Stronger documented coverage on AI Centrality
Documents Regulatory Status and Licensure and Model Risk Management and Transparency where Detected does not
A lighter documented profile than Detected
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.