I

Inca Digital

Inca Digital argues that understanding digital asset risk requires more than the chain, and it assembles the widest input set in this lane to prove the point: real time trading data across more than 300 markets, blockchain transactions, dark web material, social media named down to the individual platforms, and proprietary client data. Learned analytics are applied to the unstructured portion to detect trends, anomalies and emerging threats, with custom models built to identify the tactics, techniques and procedures affecting a particular client.

The output set is unusually broad as a result. The platform detects market manipulation, wash trading, fake volume and front running across exchanges; maps tokens, smart contracts and cross chain activity linked to a client's ecosystem to surface impersonators and misleading contracts; monitors exchange health and alerts financial regulators when risk rises; watches social media for early signs of a bank run; and identifies the geographic location of users of financial products without relying on address attribution. A bank facing product, stated to have been designed with United States regulators, addresses risk reaching institutions through banking as a service platforms and fintech partnerships.

Delivery is as much human as technical. Each client is assigned a military intelligence expert, and the company sells outsourced data collection and analysis alongside tailored intelligence reports, citation backed raw data feeds, automated threat flags and interactive dashboards. Its stated path to outcomes runs through collaboration with law enforcement and regulators, support for regulatory filings, takedown requests and asset recovery through its own litigation division.

The named client base is the strongest in this lane, spanning a federal derivatives regulator, securities and monetary authorities in three other jurisdictions, a major asset manager, and defence and special operations agencies. The company is veteran owned, founded by a former air force judge advocate, headquartered in Washington and backed by a 2022 Series A led by GTS Venture Capital and Galaxy Digital.

Last VerifiedAugust 25, 2026
Compare Inca Digital with other vendors
Founded
2017
Headquarters
Washington, District of Columbia, United States
Website
inca.digital
Categories
crypto-and-digital-assets, compliance-and-surveillance, aml-kyc-financial-crime
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

Real model work sitting inside a business whose centre of gravity is data and people. The learned component is genuine and specific: the company states it applies artificial intelligence driven analytics to unstructured data to detect trends, anomalies and emerging threats, and builds custom models identifying the tactics, techniques and procedures affecting a given client, which is meaningful work across social media, dark web and news text that rules cannot do.

But the delivery model tells against centrality. Each client is assigned a military intelligence expert, the company sells outsourced data collection and analysis as a service, and outputs arrive as tailored intelligence reports as often as as automated flags. An investor's own description of the differentiation names the dataset paired with the analysis and consultative approach of military trained security experts, which is data plus analysts with models between them. Strip the models and a very large multi source aggregation business with a strong analyst bench remains, and that is much of what clients buy.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Human judgement is structural here rather than promised. Every client is assigned a military intelligence expert, the company sells analysis as a service alongside the platform, and the primary outputs are tailored intelligence reports and dashboards built for a person to read and interrogate.

Automated threat flags exist but feed analysts rather than triggering action, and the stated route from insight to outcome runs through processes that are human adjudicated by law: collaboration with regulators and law enforcement, support for regulatory filings, takedown requests and litigation. Nothing in the published material describes the platform acting on a transaction, blocking a flow or reaching a disposition unattended. The reservation is that the company itself acts.

Pursuing takedowns and litigation means allegations founded partly on its own analysis are advanced against parties who are not its customers, and no published standard describes what threshold of confidence or internal review precedes that step.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

One structural transparency mechanism, no measurement at all. The mechanism is citation backed raw data feeds, which let a client trace a finding to the source material behind it. That matters more here than at most vendors because the intended uses are evidentiary, and a regulator or court will ask where a conclusion came from, so traceability is arguably worth more than an accuracy percentage for this particular buyer. It is nonetheless not a measure of whether the models are right.

Across two passes no accuracy figure, false positive rate, precision or recall measure, validation methodology, sample, observation period, benchmark or drift disclosure was located for any capability, including the market manipulation detection, the impersonation identification and the geolocation. For outputs used to support enforcement, the absence of a published evidentiary standard or error rate is the gap a defence would attack first.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

The named client list is the strongest in this lane and the public sector standing behind it is independently verifiable. Clients named in company announcements include a federal derivatives regulator, a major asset manager, and defence and special operations agencies, alongside securities and monetary authorities in three further jurisdictions named elsewhere.

Corroboration does not rest on the company's own word: the chief executive was appointed to that federal regulator's technology advisory committee and appears by name in the regulator's own press release alongside senior figures from exchanges, index providers and technology firms, and a former commissioner of the same regulator joined as an advisor. A 2022 Series A was led by named institutional investors including a listed digital asset firm. Two reservations matter.

The client list dates from an April 2022 announcement and includes an exchange that collapsed seven months later, so currency is not established, and across two passes no customer count, no quantified outcome figure and no funding amount was located.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One genuinely good provenance practice, and no boundary on a plainly dual use capability. The good practice is citation backed raw data feeds, meaning a client receives findings with the underlying source traceable rather than as an opaque conclusion. For intelligence intended to support regulatory filings and litigation that is the right design, because a finding that cannot be traced to its source cannot be defended, and few vendors in this index offer anything equivalent.

The absent boundary is the concern. The same platform, the same data collection and the same analysts serve commercial banks, financial regulators, law enforcement and defence and special operations agencies, and the company operates a litigation division and pursues takedown requests, meaning it takes action against third parties on the strength of its own analysis. Across two passes no acceptable use policy, no statement of work the company declines, no model card, no evaluation methodology and no incident disclosure was located.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

Nothing is published, and one stated capability makes the silence more consequential than at any other vendor in this lane. The company states that it identifies the geographic location of users of financial products without relying on address attribution.

Determining where a person physically is, by means other than the network address they connect from, and associating that with their financial activity, is a surveillance grade capability, and it sits alongside monitoring of four named social platforms and ingestion of dark web material. Together those describe assembling location, behaviour and identity linkage about individuals from sources they did not publish for that purpose and cannot inspect.

Across two passes no privacy policy content, data processing description, retention schedule, subprocessor list or legal basis was located, and nothing states what technique underlies the geolocation claim, which is the first question a buyer's counsel should ask.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

A disclosure gap rather than a security one, and here the inference rests on named customers rather than on assumption. Across two passes no trust centre, named certification, attestation report, penetration test summary or subprocessor list was located on any public surface.

What distinguishes this from the smaller vendors in this lane with the same empty page is who has already examined the company: a federal financial regulator, the defence department and a special operations command do not onboard an intelligence supplier without security review, and the company stated after its Series A that proceeds would fund hiring security experts alongside developers and analysts.

The controls therefore almost certainly exist and have been tested by unusually demanding parties. None of it is establishable from outside, which leaves a commercial bank or exchange running its own third party assessment with nothing to start from.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

No licence, and the strongest verifiable regulatory standing of any unregulated vendor in this lane. Three pieces of evidence sit outside the company's own marketing. Its chief executive was appointed to a federal derivatives regulator's technology advisory committee and is named in that regulator's own press release alongside senior figures from exchanges, index providers and a major technology company.

A former commissioner of that same regulator subsequently joined the company as an advisor. And the bank facing risk product is stated to have been designed hand in hand with United States regulators, a claim made credible by the regulator client relationships alongside it.

That is access and standing rather than authorisation, and the distinction should be stated plainly: advising a regulator is not being supervised by one, and none of it constrains the company or gives a customer recourse. No registration, examination outcome or position on emerging artificial intelligence regulation was located across two passes.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The determinations here carry heavier consequences than anywhere else in this lane and nothing published governs them. The platform surfaces previously undetected violations for regulators, independently verifies whether a platform is complying with jurisdictional rules, confirms whether an entity prohibited from serving users in a market is doing so anyway, identifies impersonators and scam networks, and geolocates individual users.

Those outputs feed enforcement action, regulatory filings, takedowns and litigation, so an error does not produce a declined transaction but an investigation, a public allegation or a legal claim against a party who never had a relationship with the company.

Across two passes nothing was located describing the accuracy of these attributions, the evidentiary threshold applied before a finding is passed to a regulator, who reviews an inference drawn from social media or dark web material before it becomes an allegation, or what recourse a wrongly identified entity or individual has.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

No commercial instrument is published and the third party exposure is the most serious in this lane. Across two passes no terms of service, master agreement, warranty, indemnity, liability cap or service level was located, and nothing states what a client is owed if an intelligence product proves wrong. The uncovered party is again not the customer.

The company's stated outcomes include surfacing violations to regulators, supporting regulatory filings, pursuing takedown requests and bringing claims through its own litigation division, all founded partly on its own analysis of social media, dark web material and behavioural inference.

A firm or individual wrongly identified by that process faces an investigation, a removed service or a legal claim, has no relationship with the company, receives no notice of the underlying analysis, and has no published route to see it, challenge it or have it corrected.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

The input side is described with more precision than anything else in this lane. The company enumerates its sources by type and, unusually, by name where it counts: real time trading data across more than 300 markets, blockchain transactions, dark web material, proprietary client data, and social media identified down to the four individual platforms it monitors rather than left as a category.

Saying which platforms are watched lets a buyer reason about coverage and blind spots in a way that the phrase social media never does. Citation backed feeds extend the same principle to the individual datum, since a client can trace a specific finding to the specific source it came from, which is provenance disclosure at the finest granularity offered by any vendor graded here. What is absent is the model layer and the vendor layer: no data supplier, aggregator, technique, architecture or third party model provider is named anywhere.

Core Systems and Integration Depth
CC on Core Systems and Integration DepthIntegration claimed through standards or connectors with no system named and nothing to verify.
Vendor Published

Flexible delivery described, nothing inspectable published. The company offers several routes into a client's environment rather than one, covering raw data feeds, automated threat flags, interactive dashboards, customised dashboards built to the client's choice of visualisation, real time alerts and scheduled intelligence reports, and investors specifically cite highly flexible product delivery methods as a differentiator.

Custom dashboards and bespoke solution building indicate the company will meet a client's stack rather than requiring the reverse. What a buyer cannot do is evaluate any of it beforehand. Across two passes no public interface documentation, developer portal, sandbox, code repository or connector catalogue was located, and no compliance platform, case management system, market surveillance tool or data warehouse is named as a supported destination. For a product delivering feeds into a client's existing analytics environment, the absence of a published schema or specification is the practical gap.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Not addressed publicly, in a company whose customer base implies it must have good answers privately. Across two passes no hosting arrangement, cloud provider, region list, tenancy description or data residency commitment was located, and no customer hosted or classified environment option is described.

The inference available is indirect but real: serving defence and special operations agencies and a federal financial regulator ordinarily requires deployment arrangements meeting government standards, and the company stated after its funding round that it was hiring security experts. So capability very likely exists and is simply undocumented in public.

That leaves commercial buyers unable to establish anything about where their own data rests, which matters because the platform ingests proprietary client data alongside its own collection, and because the regulator clients span four jurisdictions with differing expectations about where supervisory material may be processed.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No price, unit or tier is published, and two passes across the company's site, its product and client pages, its news archive and third party directories produced nothing. The published entry route is a demonstration request. The shape of the business makes a rate card unlikely rather than merely absent, and a buyer should understand why: investors describe the company's differentiation partly as a willingness to build proprietary solutions for clients, the platform offers custom models and customised dashboards, each client is assigned a dedicated analyst, and the company sells outsourced data collection and analysis alongside the software.

That is a bespoke intelligence engagement, closer to a consulting retainer than to a subscription, and such arrangements are priced per client by construction. What is still unpublished is any indication of the basis or the order of magnitude, so a prospective buyer cannot tell whether this is a data feed with analyst support attached or an analyst team with data attached.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Coverage extends well beyond crypto native buyers, which distinguishes this record from others in the same lane. The stated client base spans exchanges, banks, financial institutions, hedge funds, family offices and trading firms on the commercial side, and financial regulators, law enforcement, national security and defence agencies on the public side, with named regulatory clients in the United States, Bermuda, British Columbia and Ontario.

A dedicated bank product addresses risk arriving through banking as a service platforms and fintech partnerships, which is a traditional banking problem rather than a digital asset one, and social media monitoring for early signs of a bank run is aimed squarely at deposit taking institutions. Market coverage is quantified at more than 300 trading venues. What holds it below the top band is the absence of scale evidence: no customer count is published for any segment, and the geographic footprint beyond North America and Bermuda is not described.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing, tier or contract term appears on any vendor surface
Not published on any vendor surface. The offering combines a data and analytics platform with substantial human delivery, spanning market surveillance across more than 300 venues, ecosystem and token threat mapping, bank and fintech partner risk, social media and dark web monitoring, geolocation of users, and an assigned analyst per client, and nothing published indicates whether charging follows data feeds, monitored entities, seats, analyst time, modules or an annual retainer. The pattern described by the company and its investors, involving proprietary solutions built per client and custom models, points toward negotiated engagements sized individually rather than a standard commercial structure. No tiered data protection terms are published. Across two passes no privacy policy content, data processing agreement, retention schedule, subprocessor list, hosting location or security credential was located. The platform ingests proprietary client data alongside dark web material, social media across four named platforms and behavioural signals, and states a capability to identify the geographic location of users of financial products without relying on address attribution, none of which is described in privacy terms publicly. Named defence and federal regulator clients imply private assurance arrangements that are not disclosed. No implementation, onboarding or professional services fee is published, and the distinction between product and services is deliberately blurred in this offering rather than separated. The company sells outsourced data collection, advanced analysis and clear actionable intelligence as part of what it delivers, assigns a military intelligence expert to each client, and builds custom models and customised dashboards to a client's specification, so a substantial share of what a customer pays for is human work that would sit under professional services at most vendors. Its litigation division and support for takedown requests and regulatory filings extend that further into engagement work with its own economics. None of it is priced publicly, and nothing describes whether analyst time is included in a subscription, drawn from a retainer or billed separately. Delivery flexibility is claimed as a strength, with feeds, dashboards, alerts and reports all available, but no implementation timeline is stated. Vendor Published

Two passes across the company's site, its product and client pages, its news archive and third party directories produced no price, unit or tier. The commercial model is bespoke by design rather than merely undisclosed, and the evidence for that is in how the company and its investors describe it: a willingness to build proprietary solutions for clients, custom models tuned to a client's own threat picture, customised dashboards, an assigned analyst per account, and outsourced collection and analysis sold alongside the platform.

Engagements of that shape are scoped and priced individually. Two consequences for a buyer. There is no anchor at all, not even an order of magnitude, so budgeting requires entering a sales process. And the mix matters more than the number, since a data feed with analyst support attached and an analyst team with a data feed attached would cost very differently and nothing published indicates which this is.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746