Heka
Heka assembles intelligence about individual consumers from outside an institution's own records, drawing on live open web data, digital footprint analysis, darknet sources and non reporting collections data across thousands of global sources, and structuring it into profiles that surface alias use, reputational exposure and behavioural anomalies. Banks, insurers, payment processors and pension schemes use those signals for fraud detection, credit and insurance underwriting, onboarding and consumer tracing, delivered through a single interface or in batch and returned inside 300 milliseconds for transaction decisions.
The company describes its approach as drawn from intelligence community tradecraft and positions explainability and auditability as central, on the argument that credit bureau files and velocity models miss what is happening online.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The removal test leaves the static databases and blacklists the company defines itself against. At the core is what it calls an analyst grade agent working in live conditions rather than against stored files, processing large volumes of web data through signal extraction pipelines to assemble digital profiles that surface alias use, reputational exposure and behavioural anomalies. Turning unstructured, unlabelled open web material about a named individual into a decision ready assessment inside 300 milliseconds is model work with no rules based equivalent.
The output is intelligence for an institution to act on rather than a decision, described consistently as decision ready signals and explainable insight supporting credit, fraud and onboarding judgements made by the customer. Explainability is treated as structural rather than decorative, with the engine described as traceable and audit ready throughout, which means an analyst can see why a signal was raised.
Against that, sub 300 millisecond latency exists precisely so the output can be consumed automatically inside transaction flows, and nothing describes what threshold triggers a decline, what confidence accompanies a signal, or when a case routes to a person.
One published result is stated in the two sided form this axis rewards: in a deployment with a global payment processor the engine detected 65 percent of account takeover losses without disrupting healthy customer activity, which pairs the detection figure with the false positive constraint that actually governs adoption, and the company identifies that pairing as the metric institutions care about.
Explainability and traceability are repeated as design properties rather than claims, and audit readiness is the product's stated posture. What is missing is precision: no false positive rate, no accuracy figure for the underlying identity resolution, and no validation of the signals themselves, which matters because a wrongly attributed alias or reputational flag is an error about a specific person.
The 14 million dollar Series A in July 2025 included a major British bank among its institutional investors alongside the lead venture firm, which is a significant validation from the buyer side. Two customer relationships are named on the pensions side, a professional trustee firm using the tools to trace victims of pension fraud, and appointment as technical partner to a United Kingdom network of pension scheme trustee boards.
Distribution runs additionally through a bank and insurer sandbox platform allowing supervised trials. Revenue is described as in the millions across banks, payment processors and pension funds. The founding team is unusually relevant, combining a former global head of equity trading at a major investment bank, a senior officer from a national intelligence service and a fintech lawyer. No bank or processor is named directly.
No data boundary statement was located. Profiles are built from external sources rather than from customer records, which limits the usual pooling concern, and the platform nonetheless learns which signals predict fraud across every institution querying it, and holds the record of who was investigated by whom. Nothing states whether a query itself is retained, whether one bank's investigation history informs the profile another bank receives, or how long an assembled profile persists between lookups.
This is the most invasive assembly of consumer data recorded anywhere in this index, and nothing is published to govern it. The stated inputs combine digital footprint analysis, darknet intelligence and non reporting collections data across thousands of global sources, drawn together into persistent profiles of named individuals that surface alias use, reputational exposure and behavioural anomalies, with the method described as drawn from intelligence community tradecraft.
The subject initiates nothing, is told nothing, and in the fraud and underwriting use cases has no relationship with the company at all. No consent basis, notice mechanism, retention schedule, source lawfulness statement, subprocessor list or deletion route was located, and darknet sourced material about a person raises provenance questions that ordinary open source collection does not.
No attestation, certification, trust centre or enumerated framework was located. A major bank has invested and institutions trial the engine through a supervised sandbox, so assessment has occurred, and for a company assembling darknet derived profiles of named consumers the security of that repository is a question its buyers, its investors and the subjects themselves would all want answered publicly.
Support for full auditability and regulatory compliance is asserted and no regulator, statute or instrument is named, which is a significant gap given what this product does. Assembling external information about individuals and supplying it to lenders and insurers for decisions about those individuals sits close to the consumer reporting regime in the United States, with its obligations on accuracy, dispute and adverse action, and profiles built from open web and darknet sources engage European data protection law directly for the United Kingdom pension work. Neither framework is identified anywhere.
One use case is directly favourable to the individual and deserves credit: tracing missing pension scheme members so a trustee can pay benefits owed, with a named trustee explaining that it wanted to pay all members correctly and needed to find people regardless of where they now live. That is the same capability as fraud detection pointed the other way. The exposures are substantial.
Assessment quality depends on the size of a person's digital footprint, so those with little online presence, typically older, poorer or more private people, generate thin profiles and unreliable signals. Reputational exposure and behavioural anomaly are subjective constructs applied to named individuals. And treating alias use as a risk signal misreads the many legitimate reasons people use other names, including abuse survivors, transgender people and professional pseudonyms. No population level accuracy analysis was located.
No guarantee, indemnity or falsifiable commitment was located. The institution is well served, since audit ready and traceable output means it can reconstruct why a signal was raised and defend the resulting decision. The consumer has nothing, and the asymmetry is wider here than anywhere else in this index: a person can be declined credit, refused onboarding or flagged as synthetic on the basis of a profile assembled from open web and darknet sources they never knew existed, containing inferences about their reputation and behaviour they cannot see, correct or contest.
Source categories are named with unusual candour, covering digital footprint analysis, darknet intelligence and non reporting collections data across thousands of global sources, so a buyer understands the kinds of material feeding a signal.
No individual provider is identified for any of them, and for the darknet component in particular provenance is not a technical detail but the question that determines whether the underlying data was lawfully obtained and whether an institution can rely on it. No model provider, subprocessor list or hosting arrangement was located.
Delivery is deliberately simple, through a single interface or batch processing, and stated to integrate into existing workflows without replacing them, which suits a signal provider feeding decisions made elsewhere. The most useful distribution detail is availability through a sandbox platform used by banks and insurers, letting an innovation team trial the engine in a controlled environment before procurement, which is how a young vendor reaches institutions that would not otherwise pilot it. No named core banking, fraud, underwriting or case management system appears, and no developer documentation was located.
No hosting provider, region selection, residency commitment or private deployment option was located. The question is live because the company operates from the United States and Israel while serving United Kingdom pension schemes and trustees, so personal data about British consumers is being processed across jurisdictions under a regime that regulates exactly that, and nothing published addresses where profiles are assembled or held.
No pricing, packaging or basis of charge was located. Delivery is described as a single interface or batch, which suggests per query and bulk models coexist and would ordinarily price differently, and nothing indicates whether charge falls per lookup, per profile, per decision or as a subscription. Availability through a sandbox platform lets institutions trial before committing, which addresses evaluation cost rather than price.
Five institution types are served, spanning banks, insurers, payment processors, pension funds and pension scheme trustees, and the functional spread is genuinely wide for a single signal set: fraud detection, credit underwriting, insurance underwriting, onboarding, account recovery and consumer tracing all draw on the same engine. Geographic reach covers the United States and United Kingdom with tracing explicitly extending beyond British borders. The limit is that coverage depends entirely on a subject's online presence, so the product works unevenly across populations rather than across markets.
Alternatives to Heka
The closest documented capability profiles to Heka in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on GLBA and Data Privacy Posture
Documents AI Safety and Data Stewardship where Heka does not
Documents GLBA and Data Privacy Posture where Heka does not
Stronger documented coverage on Operational and Outcome Evidence and GLBA and Data Privacy Posture
Documents AI Safety and Data Stewardship and Regulatory Status and Licensure where Heka does not
Documents AI Governance and Bias Disclosure and AI Liability and Recourse, among others where Heka does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.