Fraud Detection & Transaction Risk
I

Incandor

Incandor builds behavioural intelligence infrastructure for banks, fintechs, neobanks and digital banks, on the argument that institutions verify identity at account creation but have no continuous signal for who is actually operating an account afterwards, while identity itself has become a commodity attackers buy in bulk. It constructs a behavioural map of every user from physical interaction signals including mouse dynamics, keystroke timing, scroll patterns and how a phone is held, requiring no fraud labels or historical data, so detection works from the first session.

Each individual forms a unique cluster regardless of which account they use, which surfaces account takeovers, mule handoffs, shared operators and coordinated rings, and supports bot detection and identification of sessions under stress or coercion. Rather than returning a risk score, it exposes the map as a programmable interface so a fraud team combines behavioural signals with its own transaction and customer data. It collects only behavioural signals, not what users type, read or view.

Last VerifiedAugust 16, 2026
Compare Incandor with other vendors
Founded
2025
Headquarters
San Francisco, California, United States
Categories
fraud-and-transaction-risk, compliance-and-surveillance, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

Unsupervised behavioural clustering is the whole product. The system learns each user's physical interaction pattern from mouse dynamics, keystroke timing, scroll behaviour and device orientation, and places every session in a map where an individual forms a distinct cluster regardless of which account is used.

Crucially it requires no fraud labels or historical data, so it functions from the first session rather than after a training period, which is a genuine architectural distinction from supervised fraud scoring.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The design deliberately withholds the automated verdict, exposing the behavioural map as a composable programmable interface rather than a black box risk score, so the institution's own fraud team combines behavioural signals with its transaction history, customer records and business rules to express investigation logic the vendor could not replicate. That leaves judgement with the bank by construction. Held at B because one path runs the other way, since banned operators can be blocked during onboarding automatically, with no described review of that exclusion.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

The architectural choice supports inspection: because the output is a navigable map rather than a score, an investigator can examine why sessions cluster together and follow an operator's activity across accounts rather than accepting a number. Working without historical labels also removes dependence on a bank's past fraud tagging, which is itself often incomplete.

Held at B because the above 99 percent accuracy figure is published without methodology, sample or false positive rate, and for a system that can lead to account blocking the false positive rate is the number that matters.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

The company states it is onboarding early customers and no institution is named. Its accuracy claim of above 99 percent for account takeover detection carries no sample, baseline or false positive rate. An independent assessment notes that the founders are described only as two engineers from a named university with no verifiable work history available, and observes that university affiliation alone is the weakest possible signal. The company is a 2026 accelerator cohort member at pre-seed stage, so the record is appropriately thin rather than concealed.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

No boundary statement was located. The behavioural map is described as covering every user on the customer's own platform, which implies per-institution scoping, while the ability to block a previously banned operator when they return implies persistence beyond any single account or credential.

Nothing states whether behavioural clusters are isolated per customer or whether an operator identified at one institution is recognisable at another, which is the question that determines how powerful and how dangerous the system is.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

The collection boundary is stated explicitly and narrowly, capturing only behavioural signals and not what users type, read or view, with the company arguing that behaviour alone is sufficient for operator-level reconciliation and therefore keeps user data private by design. Drawing that line deliberately, and explaining why the excluded data is unnecessary, is better than most vendors here manage.

Held at B because no data protection agreement, retention schedule or subprocessor register was located, and continuous behavioural telemetry on every session is still a substantial personal data flow.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No attestation, certification, trust centre or enumerated control set was located, which is expected at this stage and remains the practical barrier to a first bank deployment, since the vendor is asking to receive continuous session telemetry from every customer of a regulated institution.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

No regulator, statute or supervisory expectation is named. Identity verification pipelines are referenced as the existing control the product supplements, without engaging the customer due diligence rules that govern them, and continuous behavioural monitoring of banking customers raises consent and biometric data questions in several jurisdictions that published material does not address.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness testing or bias disclosure was located, and the exposure is inherent to the method rather than incidental. Classifying people by mouse movement, typing rhythm, scroll behaviour and how they hold a device means motor control, age, disability, assistive technology and device quality all shape the signal, so a user with a tremor, one navigating by screen reader, or one on older hardware may cluster as anomalous for reasons unrelated to fraud. Detection of sessions under stress or coercion compounds it, since distress is inferred from physical behaviour. Nothing addresses differential performance across those populations.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity or correction process was located, and the recourse gap is the sharpest consequence of the design. An operator flagged after a confirmed fraud case can be blocked at onboarding when they return, and because the identifier is behavioural rather than documentary, that exclusion follows the person across accounts, devices and credentials. Someone wrongly clustered has no identity document to correct, no score to dispute and no described route to learn that a behavioural profile is why they cannot open an account.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

No base model, provider, hosting arrangement or subprocessor is identified. The signal source is the company's own telemetry rather than licensed data, which removes external data dependency, and the modelling approach behind the clustering is described only at concept level, so an institution cannot document what is producing the behavioural identities it acts on.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Integration is lightweight and clearly described: deploying a software development kit that sends behavioural telemetry, after which the interface for querying the map becomes live, with the map designed to be navigated inside the institution's existing workflows alongside transaction linking and other signals it already runs. Held at B because no fraud platform, case management or core system is named individually.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting provider, region, residency commitment or self-hosted option was located. The architecture sends behavioural telemetry from every customer session to the vendor for mapping, which makes processing location a live question, particularly where behavioural biometric data attracts specific handling requirements.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging or basis of charge was located. Delivery is by software development kit and interface access, which usually implies usage-based pricing, and nothing indicates whether charge follows sessions, users or platform volume.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

The target market is named as commercial and consumer banks, fintechs, neobanks and digital banks, and it is a statement of intent rather than coverage, since the company is actively soliciting introductions to those buyers. No institution type, size band or geography is evidenced as served.

Alternatives to Incandor

The closest documented capability profiles to Incandor in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Operational and Outcome Evidence and Institution and Segment Coverage where Incandor does not

Documents Operational and Outcome Evidence and Institution and Segment Coverage where Incandor does not

Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Incandor does not

Documents Operational and Outcome Evidence and Institution and Segment Coverage where Incandor does not

A lighter documented profile than Incandor

Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where Incandor does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746