Kobalt Labs
Kobalt Labs automates third party and partner due diligence for banks and fintechs, a compliance function distinct from customer monitoring. Its reasoning engine ingests an institution's own policies, procedures, legal commitments and prior assessments, syncs against external regulation and security standards, then reads a counterparty's contracts and documentation to surface missing clauses, risky language, security gaps and regulatory shortfalls, pulling in beneficial ownership, financing history, adverse news, litigation and enforcement records alongside. It is aimed at community, regional and sponsor banks scaling partner volume, and at fintechs diligencing their own partners.
Capability Axes
The reasoning engine is the entire product. It reads a counterparty's contracts and documentation against the institution's own policies, procedures, legal commitments and prior assessments, and against external regulation and security standards, then surfaces the gaps. That comparison is a judgement about unstructured text and cannot be expressed as rules. Apply the removal test and what remains is a document repository and a checklist, which is precisely the manual diligence process the product exists to replace.
The posture is advisory by construction and the product name says so. The engine surfaces and tracks risks, flags missing clauses and risky language, extracts security information and suggests next steps, while the diligence decision, whether to onboard a partner and on what conditions, stays with the risk officer who signs it. That is the right division for a function where accountability is personal and examinable.
What is not described is the surrounding process: no confidence indication on a flag, no escalation path, no sampling or quality assurance over the reviews, and no account of how a reviewer knows what the engine did not surface.
The published measurement is throughput and the risk is correctness, which is the same asymmetry seen across the supervision vendors in this index. Capacity improved fourfold tells a buyer how much faster reviews complete; it says nothing about what proportion of genuine contractual, security or regulatory gaps the engine actually detects, which is the only number that matters when the output supports an onboarding decision an examiner will later question. No model documentation, evaluation methodology, detection or recall figures, or stated support for a customer's own validation were located.
No customer is named anywhere located in this pass, and the efficiency claims, more than four times internal diligence capacity and partner diligence completed in a tenth of the usual time, are described by a co founder as initial benchmarking, meaning self run and early.
The real validation signal is distribution rather than testimonial: an embedded banking platform admitted the company to the partner marketplace it offers its own bank network, and a second technology marketplace lists it, both of which involve a vetting step by a party with its reputation at stake. Team size is reported in single figures, which bears on both evidence depth and delivery capacity for a regulated buyer.
One claim in the marketing needs testing rather than accepting: the platform is described as synchronised with every existing financial regulation, regulatory guidance and security standard. That is a totalising assertion about a corpus that changes weekly across dozens of federal, state and international sources, and nothing public describes how the corpus is maintained, who verifies an interpretation, how quickly a rule change propagates, or what the platform does when a regulation is ambiguous. For a product whose entire output depends on the currency and correctness of that corpus, its maintenance is the central stewardship question and it is unaddressed.
What this platform ingests is unusual and deserves attention: not customer records but the institution's own internal policies, procedures, legal commitments and previous privacy and compliance assessments, which taken together are among the most sensitive non customer documents a bank holds and would be highly valuable to an adversary or an examiner's counterparty. Consumer data exposure is correspondingly low, which counts in its favour. No published privacy framework, retention schedule, subprocessor list or statement on how third party documentation is handled after review was located.
No trust centre, certification list, attestation scope or audit period was located in this pass, and the absence has a particular edge here. The platform includes a module that extracts and reviews the security posture of third parties on a bank's behalf, so the vendor performs security diligence on others while publishing nothing a buyer can use to perform the same diligence on it. Any bank running its own third party programme would ask this vendor for exactly the evidence the vendor helps it demand elsewhere.
Kobalt Labs supplies software and holds no licence, the expected posture. The function it automates sits directly under interagency expectations for managing third party relationships, which were tightened substantially and which fall hardest on exactly its target buyer, the sponsor bank responsible for oversight of fintech partners it does not control. The product exists because that supervisory pressure made manual partner diligence unscalable. What is absent is the specificity the strongest vendors in this lane now show, naming the particular guidance the platform is built to satisfy rather than referring to regulation in general.
The subjects assessed are companies rather than individuals, so consumer fairness is not the frame, but two exposures still apply. The platform surfaces adverse news and enforcement history on counterparties and their beneficial owners, and adverse media corpora are dominated by English language sources while name matching varies by convention and transliteration, so a counterparty with non Western ownership can draw a different risk picture as a property of the method. Separately, a diligence engine that misses a gap causes a bank to onboard a partner it should have declined. Neither error profile is disclosed.
No accuracy commitment, no remediation term and no correction route were located. The exposure runs in an unusual direction for this index: the party harmed by a missed gap is the bank itself, which onboards a partner it should have declined and answers to its examiner for that decision, while the counterparty wrongly flagged as risky loses a banking relationship with no visibility into why. Nothing published addresses either outcome.
No model providers are named for the reasoning engine, no subprocessor list is published, and nothing describes where a bank's internal policy library and a counterparty's contracts are processed once ingested. The regulation corpus the engine matches against is itself an undisclosed supply dependency, since the platform claims synchronisation with every existing financial regulation and security standard without identifying where that content is sourced or how it is kept current.
Two integration paths are evidenced and both are commercially meaningful for a company this size. Distribution runs through an embedded banking platform's partner marketplace, which places the product inside the procurement path of that platform's bank network rather than requiring each bank to find it, and a second technology marketplace adds another channel.
On the data side the engine connects to business intelligence sources covering beneficial ownership, financing history, adverse news and litigation, so a diligence file assembles itself. No named connectors into governance, contract or vendor management systems, and no public developer documentation, were located.
Delivery is cloud hosted software as a service aimed at domestic institutions, so the cross border complexity facing the global vendors in this index does not arise in the same form. That does not remove the question, since the platform holds a bank's internal policy library and counterparty documentation. No hosting regions, tenancy model, residency options or subprocessor chain were located in this pass.
No rates, tiers, billing unit or minimum were located in this pass. The gap is more consequential for this buyer than most, because the target customer is a community, regional or sponsor bank weighing compliance cost against partnership revenue, and the product is sold explicitly as a way to scale partner volume without adding headcount. That is an arithmetic argument that cannot be run without a price on one side of it.
The focus is deliberate and narrow: community, regional and sponsor banks scaling partnership and vendor volume, plus fintechs running diligence on their own partners. Sponsor banks are the sharpest fit, since partner oversight is where supervisory attention has concentrated hardest. Beyond that the coverage stops.
There is no material for large banks, credit unions, insurers, asset managers or capital markets, no evidence of non domestic regulatory coverage, and the use case itself is a single compliance function rather than a programme.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.