Middesk
Middesk is a business identity platform that verifies companies rather than people, and takes that verification through to a decision. It pulls from primary government sources first, with direct connections to the Internal Revenue Service and all fifty Secretary of State offices, then layers alternative sources and network signals across a stated four hundred data providers, covering business name and address verification, taxpayer identification matching, beneficial ownership, sanctions screening, uniform commercial code filings and ongoing monitoring.
An orchestration layer routes each case through specialised agents that investigate discrepancies, pull additional sources and return a resolved outcome, while purpose built models detect shell companies, synthetic businesses and entity relationship patterns that indicate coordinated fraud. Institutions configure rules for straight through approval and send the remainder to human review, or run rules and agents in parallel. A separate registration product files with state and federal agencies on a client's behalf so businesses can be set up for payroll and tax.
The company states more than five hundred customers across financial technology, banking, lending, marketplaces, insurance and payroll, naming Plaid, Bluevine, Rippling, Novo and Fora Financial, with a published integration into a major engagement banking platform used by banks and credit unions. Coverage is United States only, with international verification stated as a future addition.
Capability Axes
Capability grades
15 of 15 axes rated · 7 graded A or B
Remove the models and a substantial product survives, because direct connections to the tax authority and all fifty state registries are data engineering rather than model work, and a deterministic verification interface over those sources was the original business.
What the models add is the step the company now sells hardest, moving from data to a resolved decision: specialised agents that investigate discrepancies and pull further sources rather than returning an unresolved case, and purpose built detection of shell companies, synthetic businesses and relationship patterns that only surface through inference across a graph. That is the same pattern as the identity decisioning peers in this index, where a working orchestration product sits underneath and the models carry the judgement.
The autonomy model is published in the terms this axis exists to reward, naming what runs unattended, what constrains it and where a person enters. Institutions set their own rules for straight through approval, low risk applications are auto approved while complex ones route to human review with the assembled context attached, and agents handle edge cases.
The strongest element is the option to run rules and agents in parallel, which lets an institution compare an autonomous outcome against its existing policy before trusting it, a shadow mode control almost nobody in this index offers. Outputs carry timestamped decisions, source attribution and explainable results, stated as built for examiner review and credit committee defensibility.
Traceability is designed in rather than promised. Every decision is described as carrying a timestamp, attribution to the source that supported it and an explainable result, framed explicitly for examiner review and credit committee defensibility, which means a reviewer can reconstruct why a business was approved or rejected and which record drove it. That is the evidence base supervisory guidance actually asks for and it is stronger than most in this index.
It stops short of an A because performance is never quantified: no accuracy figure, no false positive or false negative rate for shell and synthetic detection, no validation methodology and no drift monitoring cadence appears anywhere.
A named customer appears with numbers attached to it. A small business lender is described as having deployed four billion dollars to more than fifty five thousand businesses while approving loans in under twenty four hours, with the specific contribution stated as automated industry classification and digital fraud signals that its previous providers did not surface.
Four further customers are named across payments infrastructure, digital lending, workforce software and digital banking, against a stated base of more than five hundred customers spanning financial technology, banking, lending, marketplaces, insurance and payroll. A published integration with an established engagement banking platform extends reach to banks and credit unions, and the company has placed on a national financial technology ranking.
One published phrase raises the question and nothing answers it. Where primary sources are insufficient, the platform is described as layering in alternative sources and network signals automatically, and a network signal in this context means information derived from activity across the customer base. That is the same consortium shape several vendors in this index rely on, and it is genuinely useful for detecting coordinated fraud rings, which is exactly why the boundary matters. Nothing published states what a network signal is built from, whether contribution is a condition of use, or whether one institution's application flow informs decisions served to a competitor.
The framing as business verification understates the personal data involved. Customer identification and due diligence work on a business requires identifying its beneficial owners, which means names, addresses and identifiers for private individuals, assembled alongside relationship graphs connecting people across entities.
Searched the platform, product and documentation material for a privacy statement covering that personal information, how long it is retained, what happens on termination and how an individual named in an ownership graph could learn of or correct it, and located none. Sole proprietors are explicitly in scope, and for a sole proprietor the business record and the person are the same record.
Searched the company site, product pages, developer documentation and third party review material across two passes for an enumerated attestation, an information security standard, a penetration testing statement or a trust centre, and located none. An independent review of the platform published in 2026 discusses pricing opacity and international coverage as the principal constraints without citing a security credential either.
For a vendor holding beneficial ownership records and verification decisions on behalf of banks and credit unions, which are institutions contractually obliged to assess vendor security, the absence of any public position is the widest gap in this profile.
No licence is required for the verification business and none is claimed, which is not penalised. What lifts this above the norm is that products are built against named regulatory programmes rather than compliance in the abstract, addressing customer identification, customer due diligence and enhanced due diligence as distinct workflows, screening against the federal sanctions list, matching taxpayer identifiers directly with the tax authority, and handling uniform commercial code filings.
The registration product goes further and performs actual filings with state and federal agencies on a client's behalf, which is a regulated activity conducted as agent rather than software sold to someone else to use.
The fairness question for business verification is which businesses fail, and the company deserves credit for addressing part of it: it states that sole proprietors, new formations and businesses trading under assumed names are verified where legacy tools return nothing, and those are precisely the applicants most often rejected for absence of record rather than for risk. The unaddressed half is the detection side.
Shell company identification and relationship graphs that flag coordinated rings will also flag legitimate clusters, including family businesses at shared addresses, immigrant owned business networks and firms using shared registered agents. A false shell flag costs a real business a bank account or a loan, and no error rate by business type, size, geography or ownership is published.
What this product decides is access. A business that fails verification does not open the account, does not receive the loan and frequently never learns which signal caused it, and the company markets autonomous resolution as the point of the platform. Nothing published states a service level, a warranty, a correction obligation or any allocation of responsibility between the vendor and the institution when a verification outcome is wrong. There is also no published route by which a wrongly flagged business reaches the vendor at all, since the commercial relationship runs to the institution and the affected party is its applicant.
The architecture is described with more precision than most, naming an orchestration layer, specialised sub agents each trained for a particular task, and purpose built detection models, which tells a buyer how the system is arranged. It stops short of saying whose models perform the work.
No provider, model family or hosting arrangement is identified, nothing separates models developed in house from services called externally, and nothing states whether business records and ownership information leave the environment during agent investigation. Describing an agent architecture is not the same as disclosing what sits behind it.
Depth runs in both directions and the specifics are published. Inbound, direct connections to the federal tax authority and all fifty state business registries sit alongside postal and sanctions sources and a stated four hundred data providers, which is primary source access rather than resold aggregation.
Outbound, the platform is interface first with documented integration paths, ships an integration with an established engagement banking platform serving banks and credit unions, and embeds business registration inside a client's own product rather than referring it elsewhere. The documentation surface is also unusually machine addressable, publishing an index for artificial intelligence agents and a markdown rendering of every page.
Delivery is a cloud hosted interface with a web application alongside it, and the published material goes no further. Searched for hosting regions, a residency commitment, a single tenant option or any description of where verification records and ownership graphs are stored and processed, and located none.
Residency pressure is lower than for a global vendor since the data is United States sourced and the customer base is domestic, but the company states international coverage is coming, which will make the question live rather than academic.
No rates, tiers or unit of charge are published and every engagement begins with a sales conversation, a point third party reviewers make directly. The gap is compounded by a product surface that spans verification calls, ongoing monitoring, agent driven investigation and per filing registration services, four things that would naturally price on entirely different units. A buyer cannot tell whether cost scales with applications submitted, businesses monitored, agent investigations run or filings made, which are the four questions that decide the annual number.
Buyer breadth is real, running across financial technology firms, banks, credit unions, lenders, marketplaces, insurers and payroll providers at more than five hundred customers, and the banking platform integration reaches institutions of a size the company would not sell to directly. Geographic coverage is what holds this to a B rather than higher.
Verification is United States only, built on domestic registries and the federal tax authority, with international coverage described as forthcoming rather than available. An institution onboarding businesses outside the United States needs a second vendor today, and that is a structural limit rather than a gap in disclosure.
Alternatives to Middesk
The closest documented capability profiles to Middesk in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Institution and Segment Coverage
Documents Security Certifications and Trust Center where Middesk does not
Documents Model Supply Chain Disclosure where Middesk does not
Documents Model Supply Chain Disclosure where Middesk does not
Documents AI Safety and Data Stewardship where Middesk does not
Documents Deployment Model and Data Residency where Middesk does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.