Linkurious
Linkurious sells the investigation layer rather than the detection engine. Its premise is that financial crime hides in relationships rather than in single records, so a shell company, a shared address, a repeated device or a chain of intermediaries only becomes visible when the data is traversed as a network. The product renders that network for an analyst, lets them expand outward from any node, and holds the resulting judgement in a case.
The estate splits into two editions and the split matters to a compliance buyer. Linkurious Enterprise Cloud is fully managed, priced publicly per user, and covers search, visual exploration, a no code query builder, geospatial and temporal analysis, collaboration and export. It explicitly does not include entity resolution, alerts, case management or the interface. The Linkurious Decision Intelligence Platform is the self managed edition, deployed on premise or in the customer's own cloud, and it carries the four capabilities the managed edition omits. A financial crime team therefore buys the quoted edition rather than the priced one.
Underneath, the product is deliberately not a database. It reads from graph stores the customer already owns, supporting Neo4j, Amazon Neptune, Azure Cosmos DB, Memgraph, Google Spanner Graph and Google BigQuery Graph, and it publishes a per store feature map showing which capabilities work against which. That posture is the reason this record exists rather than being screened out as infrastructure: the graph database is the substrate, and Linkurious is the application over it.
Financial lines are separately developed, with distinct published material for banking, anti money laundering and counter terrorist financing, and counter fraud, alongside case management, alerting and machine learning that adjusts anti money laundering scoring from analyst decisions. Named financial customers include a French digital bank in the Credit Agricole group, a global money transfer business and a global insurer. The platform is also the software behind the Panama Papers investigation.
The company is Linkurious SAS of Paris, founded 2013 by Sebastien Heymann and Jean Villedieu. Nuix Limited, listed in Australia, announced its acquisition on 4 December 2025 and closed on 20 April 2026 at up to 20 million euros following French foreign investment approval. The brand, website, product names, pricing and legal entity all continue, presented as a Nuix company.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
The vendor's own rate card performs the removal test and the result goes against it. Linkurious Enterprise Cloud is sold as a complete commercial product at a published per user price, and its feature comparison marks entity resolution AI as unavailable in that edition.
So the version with the models stripped out is not a thought experiment, it is a shipping product with a price on it, covering search, visual network exploration, a no code query builder, geospatial and temporal analysis, collaboration and export.
What the models add is additive rather than constitutive: entity resolution deciding whether two records describe the same party, a natural language feature that drafts graph queries, and machine learning that tunes anti money laundering scoring from analyst decisions. Those are real and they are the capabilities a financial crime team specifically needs, which is why this does not sit lower. The load bearing technology is graph traversal, rendering and indexing, none of which is learned. The vendor's own language is consistent with this reading, describing itself as providing data visualisation and analytics solutions powered by graph technology rather than as a model company.
A conservative position established by the shape of the product rather than by policy, which is worth more than it might sound. Nothing here closes an alert, files a report, scores a customer for automatic action or reaches a conclusion without a person.
The product surfaces alerts for review, gives an investigator a canvas to expand a network outward from any node, and captures the resulting judgement in a case, so the analyst is the decision maker at every point and the software is the instrument they use. The machine learning runs in the direction that supports this: the vendor describes scoring adjusted from the insights of analysts, meaning human decisions train the system rather than the system displacing human decisions.
Against the pattern elsewhere in this lane, where agentic layers close alerts automatically at volume, this is a materially safer construction and the record should say so plainly. It stops short of the top band for one reason. The position is inferred from how the product works rather than stated as a commitment, and nothing published describes an autonomy boundary the vendor holds to, what it would refuse to automate, or how that stance might change as the alerting and scoring features develop.
Software documented thoroughly, models documented not at all, and the distinction is the whole grade. The product documentation is among the better examples in this index and is public without registration: a versioned administration manual, release notes recording behavioural changes down to session timeout defaults and browser support removals, deployment requirements, and a feature map stating which capabilities are available against which graph database.
A buyer can therefore understand exactly what the software does and where it is limited. None of that touches the models. Across two passes no accuracy, precision or recall figure for entity resolution was located, no validation methodology, no benchmark against a deterministic alternative, no false positive or false negative characterisation, no drift or retraining disclosure, and no model documentation of the kind a bank's own model risk function would require before putting a learned resolution decision into an anti money laundering process.
The absence is more conspicuous here than at a vendor that documents nothing, because this company plainly knows how to publish technical material and has chosen to do so everywhere except the models.
Named customers, named executives and quantified outcomes across three distinct financial subsegments. A French digital bank in the Credit Agricole group is quoted on the record through its chief compliance officer, reporting detection of several dozen fraud cases and complex fraud rings within months, a 20 percent increase in identified fraud cases and investigations ten times faster. A global insurer reports a 30 percent reduction in fraud case triage time.
A global money transfer business is published on anti money laundering investigation. A major professional services firm is quoted through its named director of data analytics. Independent corroboration is unusually good: reviews sit on a major analyst peer platform including critical ones, and the platform is the software behind the Panama Papers investigation, a deployment involving more than 350 journalists that is externally documented rather than vendor asserted.
Financial scale is now disclosed through the acquiring parent's exchange filings, at roughly 7 million euros annualised contract value as at June 2025 with positive earnings and operating cash flow for the 2024 year, which is more verifiable scale disclosure than almost anything in this lane offers. The ceiling is that the marquee reference is journalism rather than finance, no tier one bank is named, and no count of financial institution customers is published.
Good general stewardship, no AI specific safety material, and one unanswered question that matters more here than usual. On the general side the vendor publishes a trust centre, terms of service, a privacy policy and a stated deletion window, and the on premise deployment option means a customer can keep the vendor out of its data path entirely, which is the most substantive stewardship control available.
On the artificial intelligence side, two passes located no evaluation methodology, red team result, model card, incident disclosure or acceptable use boundary. The specific question concerns the natural language query feature, which builds and previews graph queries from plain English. That implies a language model, and the public material does not say whose, where it runs, or what leaves the customer environment when it is used.
For a buyer who selected on premise deployment precisely so that sensitive investigation data stays inside its own perimeter, whether that feature calls out to a hosted model, and whether it transmits schema, query text or results in doing so, is the question that determines whether the deployment choice actually achieves what it was made for.
The strongest privacy position available to a vendor, because it is architectural rather than promissory. The self managed edition runs on the customer's own premises or in the customer's own cloud, reading from a graph database the customer owns and controls, which means the vendor need never hold the customer's data at all. A commitment not to misuse data is a promise that requires trust; an architecture in which the data never arrives does not.
For the managed edition the vendor states hosting in European Union data centres and publishes a deletion commitment of 45 days after cancellation, which is a specific retention term rather than a general assurance. Supporting documents are unusually complete for this index: a privacy policy, a cookie policy, terms of service and a dedicated trust centre are all publicly reachable without contact. What is missing is the American frame and one model question.
The Gramm Leach Bliley Act appears nowhere, no safeguards rule position or state privacy programme was located across two passes, and nothing published states whether customer data or analyst decisions inform the vendor's models, which matters because the product advertises machine learning that adapts to analyst judgements.
A real trust centre on its own subdomain, reachable without contact, which is the artefact this axis asks for and which most of this lane lacks. Alongside it the vendor publishes terms of service, states an attestation covering Linkurious Enterprise Cloud, carries a data protection regulation mark, and documents its access controls concretely: directory services, single sign on and federation, fine grained access rights, and behavioural detail down to a default three hour session timeout and the censoring of passwords in configuration files.
Three deductions, all specific. The scope is the important one: the attestation covers the managed cloud edition, and the self managed platform, which is the edition a financial crime team actually buys, is not covered by it, so the credential and the relevant product do not overlap.
The credential is also described as a certification, where this control framework produces an independent attestation report rather than a certification, and neither the type nor the observation period is stated. And the pricing page contradicts itself in adjacent answers, one saying the company is in the process of obtaining the attestation and the next saying it holds it, a stale entry left live beside the current one. No information security management certification was located.
An unregulated software vendor whose regulatory visibility improved through ownership rather than through anything it did. Linkurious SAS is a French private company selling software into obligations its customers hold, with no financial services authorisation, no claim of one, and no overstatement, which is worth crediting.
Since April 2026 it is a subsidiary of an Australian listed parent, and that brings two concrete pieces of external scrutiny that a private vendor does not carry: continuous disclosure obligations at group level, under which the vendor's own contract value and profitability were published to an exchange, and a completed French foreign direct investment review, which is a state assessment of the company as a sensitive technology asset rather than a commercial formality.
Neither is a financial services licence and neither should be presented as one. What remains absent across two passes is any published position on regulatory examination outcomes at customers, any statement on the European Union AI Act despite being a European vendor selling learned entity resolution into anti money laundering decisions, and any description of how the product is positioned relative to the obligations it is bought to serve.
The governed decision here is quieter than an alert closure and carries the same exposure. Entity resolution decides whether two records describe one party, and inside an anti money laundering workflow that determination is what links or fails to link a customer to a sanctioned entity, an adverse media subject or a known network.
Resolution does not fail evenly across name traditions, transliterations and corporate naming conventions, so the probability of a wrong link and the probability of a missed one both vary by where a name comes from. The consequence then propagates through a graph rather than stopping at a record, because a single wrong resolution creates a false edge and every subsequent traversal treats it as real, which is how an analyst arrives at a network that does not exist.
Two passes located no accuracy figure for resolution, no breakdown by script or language, no fairness testing, no model card, no governance page and no published position on the European Union AI Act. The vendor's own framing offers the mitigating point that the analyst sees the underlying data and can reject a link, so the error is visible in a way a closed alert is not.
Contractual documents exist in public, which distinguishes this from the silence common in this lane, but they are not the ones that govern the product. Terms of service, a privacy policy and a cookie policy are published and reachable, and the managed edition carries stated commercial terms a customer can rely on without negotiation: cancellation at any time, no charge during the 30 day trial, charging for the remainder of the signed term if cancelled after it, and deletion of data within 45 days.
Those are real, specific and unusually concrete. What they are not is product liability. The published terms govern use of the website rather than the software, and across two passes no master subscription agreement, warranty, indemnity, liability cap, service level commitment or uptime credit was located for either edition.
Nothing addresses the consequence that matters here, which is what is owed if entity resolution creates a false link between a customer and a sanctioned party, or fails to create a true one, and the institution acts on the resulting picture. The on premise option shifts part of the operational risk to the customer by design, and the allocation of the rest is not public.
Exhaustive disclosure of one supply chain and none of the other. The data layer is documented to a standard almost nothing here matches: every supported graph store named, a public compatibility matrix showing which features work against each, a named analytics platform partner, and a clear statement that the customer supplies and controls the store. A buyer knows precisely what the product depends on to run. The model layer is a blank.
Three learned capabilities are named as marketing terms, entity resolution, a natural language query feature and graph analytics with artificial intelligence, and none carries an architecture, a technique, a provider or a statement of whether any third party foundation model is involved.
The natural language feature is the sharpest instance, because generating graph queries from plain English implies a language model, it is available only against two of the six supported stores in a way the material does not explain, and nothing says whether it executes locally in a self managed install or calls a hosted service. That last question is not academic for the on premise buyer, since it determines whether an air gapped or sovereign deployment remains so when the feature is used.
The best documented integration posture located in this lane, and what earns the grade is that the documentation discloses limits rather than capabilities. The product reads from graph stores the customer already owns, supporting Neo4j, Amazon Neptune, Azure Cosmos DB, Memgraph, Google Spanner Graph and Google BigQuery Graph, and the vendor publishes a per store feature map plus footnotes on its own pricing page stating plainly which features are unavailable against which database.
Data editing works on four of the six, the no code query builder on three, the natural language query feature on two. Publishing that a headline feature does not work on a third of the supported stores is disclosure against commercial interest and is exactly what an integration axis should reward.
Around it sits a genuine developer surface: an interface and webhooks, custom plugins and applications, a public JavaScript graph library, versioned documentation, and delivery as a container image or native builds for three operating systems. Authentication covers directory services, single sign on and federation. Delivery partners include a global professional services firm and a specialist risk consultancy. One counter point belongs on the record: a reviewer on an analyst peer platform reports the interfaces are complex enough that their integration teams could not get full value from them.
The full range, published clearly, with the choice left to the buyer rather than to the vendor. Three genuine models are offered: fully managed and hosted by the vendor in stated European Union data centres, self hosted inside the customer's own cloud tenancy, or installed on the customer's own premises.
Delivery for the self managed editions is a container image or a native build for Linux, Windows or Mac, with hardware, database and search dependencies documented publicly so an infrastructure team can size the deployment before entering a sales conversation.
Because the product reads from a graph store the customer selects and controls, the residency of the underlying data is a customer decision in every configuration rather than a vendor commitment to be trusted, and in the on premise configuration the sensitive investigation data never reaches the vendor at all. For a regulated buyer facing residency, sovereignty or sensitivity constraints, that combination answers the procurement question rather than deferring it.
Two qualifications sit below the grade rather than against it: no named region list is published for the managed edition beyond the European Union, and no availability, resilience or recovery commitment was located for it.
A published rate card with the terms attached, which is rare here, undercut by which edition carries the price. The managed edition is listed at 490 euros per user per month with a monthly or yearly toggle, a stated 8 percent saving for annual commitment, and a currency switch between euros and dollars. A 30 day free trial is offered on both editions.
Cancellation terms are stated rather than implied: a customer may cancel at any time, is not charged during the trial, is charged for the remainder of the signed term if cancelling after it, and data is deleted within 45 days. A full feature comparison matrix runs the length of the page with footnotes disclosing which capabilities are unavailable on which graph databases, which is disclosure of limitation rather than of feature.
The material qualification is that the priced edition is not the one this record grades. Entity resolution, alerts, case management and interface access all sit in the self managed platform, which is quoted only, and the published questions answer the cost question for it by directing the reader to sales. A buyer in financial crime therefore gets an anchor price for an edition their team cannot use, and one analyst platform reviewer describes licence cost as very high.
Four separately developed financial pages rather than one vertical page, covering banking, anti money laundering and counter terrorist financing, counter fraud, and financial crime investigation as a whole, each with its own argument rather than shared copy.
Named customers span three different financial subsegments, a retail bank inside a major European banking group, a global money transfer and remittance business, and a global insurer, which is genuine breadth for a company of this size and covers three quite different risk shapes. Delivery partners include a global professional services firm and a specialist risk consultancy, both publicly announced, which extends reach into institutions the vendor would not sell to directly.
Geographic spread is stated across North America, Europe and Asia Pacific. Two things hold this below the top band. Financial services is one of several use case families the company sells, alongside cybersecurity, law enforcement and intelligence, supply chain, and network and information technology, and the same product serves all of them.
And no institutional scale claim is published anywhere, no count of financial institution customers, no tier one or systemically important bank named, so the depth at the top of the market cannot be assessed.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
490 euros per user per month for Linkurious Enterprise Cloud; the self managed Decision Intelligence Platform is quoted only
$490 baseline
|
Two editions on different commercial models. Linkurious Enterprise Cloud is fully managed and published at 490 euros per user per month, with a currency toggle offering the same figure in dollars, a monthly or yearly billing choice, and a stated 8 percent saving for annual commitment. The Linkurious Decision Intelligence Platform, self hosted on premise or in the customer's cloud, is quoted only and carries no published figure, basis or term. Both offer a 30 day free trial. Cancellation terms for the managed edition are published: cancel at any time, no charge during the trial, charged for the remainder of the signed term if cancelling after it, access ends and data is deleted within 45 days. A full feature comparison matrix is published across both editions, with footnotes disclosing that several capabilities including data editing, the no code query builder and the natural language query feature are unavailable against some of the six supported graph databases. | No tiered data protection terms are published. Data handling differs by deployment rather than by commercial tier, which is the more meaningful distinction here. In the self managed editions the customer hosts the software and owns the graph store, so the vendor holds no customer data. In the managed edition the vendor states hosting in European Union data centres, publishes a privacy policy, a cookie policy and terms of service, maintains a trust centre, and commits to deleting customer data within 45 days of cancellation. An attestation covers the managed edition only. No data processing agreement, subprocessor list or model training commitment was located without contact. | No implementation, onboarding or setup fee is published for either edition, and the managed edition is presented as requiring no deployment work at all: sign up, receive an instance link, supply graph database credentials and begin. The self managed edition is delivered after a sales call as a container image or a native build for Linux, Windows or Mac, with hardware, database and search dependencies documented publicly so a buyer can scope the work internally before committing. Support is included rather than sold separately: online documentation, an on demand training academy, a ticket system, a dedicated customer success manager for managed edition clients, and a dedicated solutions engineer additionally for self managed clients. Free trials run 30 days on both editions, with the self managed trial issued as a licence and decommissioned without obligation if the buyer does not proceed. The unpriced dependency is the graph database itself, which the customer must supply or ask the vendor to provide, and delivery partners including a global professional services firm and a specialist risk consultancy price their own services separately. | Vendor Published |
Two passes confirm a genuine published rate for the managed edition and no rate at all for the edition a financial crime buyer needs. The distinction is not a technicality: the vendor's own comparison matrix marks entity resolution, alerts, case management and interface access as unavailable in the priced edition, and those four are the capabilities that make the product a compliance tool rather than a visualisation tool.
A published question asking what the self managed platform costs is answered by directing the reader to sales. The anchor price is still useful, since it establishes an order of magnitude and a per user basis the quoted edition is likely to build from, and the surrounding terms on trial, cancellation and deletion are stated with a precision most of this lane never reaches.
Counterweight worth recording: a reviewer on an analyst peer platform describes licence cost as very high, which is the only external signal located on the quoted edition. Buyers should also note the graph database is a separate cost the vendor does not price, though it can be provided by the vendor on request.