Customer & Banking Agents
Q

Q2 Holdings

Q2 Holdings sells the digital engagement layer that banks, credit unions, alternative finance companies and fintechs put in front of their customers, spanning retail, small business and commercial banking on a single platform. That single platform claim is the commercial thesis rather than an architecture note, because running consumer and commercial banking on one system gives the company behavioural signal across both, which it uses to argue a data advantage in detecting account takeover.

The company describes its position as a system of context, capturing real time digital signals across logins, transactions, alerts, messages and user decisions at the engagement layer, while also operating at the execution layer where workflows run and transactions complete. Artificial intelligence is concentrated in three stated areas: banker efficiency, fraud prevention and personalisation.

Three named artificial intelligence products arrived during 2026. Q2 Code, announced 16 April 2026, is a governed development environment turning natural language prompts into extensions compliant with the company's software development kit, built for teams working through Q2 Innovation Studio, and stated openly to be built with Anthropic's Claude Code running on Amazon Bedrock. Q2 Assistant, launched 2 June 2026, is a unified conversational layer embedded across the product portfolio that connects to product specific agents which execute tasks, beginning with a Customer Care Agent inside Digital Banking, and is stated to run under the same data isolation, audit logging and compliance controls the platform applies elsewhere. A separate account takeover product using behavioural signals reported double digit early adopters in its first quarters.

Security is documented at unusual length for this segment. The company publishes a service organisation control assessment of the second type covering security and confidentiality for its software platform, a dedicated enterprise security risk and compliance function, several external reviews each year, a cybersecurity mesh architecture in which one tool informs the others, zero trust, behavioural anomaly detection, and a data protection capability that fragments payment card data across a private blockchain network. Its platform migration moved online banking stacks for more than 450 financial institutions onto Amazon Web Services.

Scale is reported under securities law. Second quarter 2026 revenue was 219.8 million dollars, up 13 percent, with subscription annualised recurring revenue of 826 million dollars, total annualised recurring revenue of 971 million, backlog of 2.8 billion up 17 percent, and the balance sheet debt free after repaying convertible notes. More than 1,200 financial institutions run on the platform, with average customer contract length above ten years and initial commitments averaging more than five. Listed on the New York Stock Exchange and headquartered in Austin, Texas.

Last VerifiedAugust 26, 2026
Compare Q2 Holdings with other vendors
Founded
Headquarters
Austin, Texas, United States
Website
www.q2.com
Categories
customer-banking-agents, fraud-and-transaction-risk
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The removal test settles this with the rest of the digital banking platform tier. Strip the models out and a retail, small business and commercial banking engagement platform keeps running, serving more than 1,200 institutions on contracts averaging over ten years, which is what customers actually buy and what the backlog of 2.8 billion dollars represents.

The company's own framing supports the reading rather than contradicting it: artificial intelligence is described as embedded into the flow of banking activity, applied to banker efficiency, fraud prevention and personalisation, which are three improvements to an existing platform rather than the platform itself.

Management characterises the current phase as a pivot from artificial intelligence as a broad concept to practical application on real workflows, and separately notes that the new artificial intelligence products reach revenue materially faster than core platform installs, which is a statement about how small and additive they still are.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

The autonomy claim is stated plainly and the boundary around it is not. Product specific agents are described as executing tasks and supporting operations, beginning with a customer care agent inside digital banking, and executing tasks is an autonomy claim rather than an assistance claim. The published control is audit logging, which records what happened and supports reconstruction afterwards, and that is a different thing from a gate that stops something happening.

Two passes located nothing naming which actions an agent may complete without a person, what requires approval, what confidence threshold triggers escalation, or what a banker sees before an agent acts on a customer account. The development environment raises a parallel question, since it generates code compliant with the software development kit and nothing published describes the review a generated extension passes before it reaches production in a regulated institution. Governed is used repeatedly across the product line without being defined.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Two passes located no accuracy rate, false positive rate, validation methodology, benchmark, drift monitoring, revalidation cadence or model documentation for any capability. The fraud and account takeover products are where the omission matters most, because detection systems live and die on the ratio between catches and false alarms, and the company competes explicitly on having better behavioural signal than rivals, which is a performance claim that a published false positive rate would either support or undermine.

Nothing of the kind appears. The conversational agents carry the same gap, with no containment, resolution or escalation figures published, and the segment's own buyer standard asks what share of interactions resolve without escalation and how many contained customers came back within a week. The company does report double digit early adopters for the account takeover product, which describes demand rather than performance.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Regulatory Filing

Evidence is audited and current, which is what separates this from most of the segment. The company reports to the United States securities regulator, so scale and trajectory are examined rather than asserted: second quarter 2026 revenue of 219.8 million dollars up 13 percent, subscription annualised recurring revenue of 826 million up 15 percent, total annualised recurring revenue of 971 million, backlog of 2.8 billion up 17 percent, and gross margin improvement of 480 basis points following completion of a cloud migration.

Durability is quantified in a way buyers can use, with more than 1,200 institutions, average contract length above ten years and initial commitments averaging more than five. Named commercial evidence includes an expansion tied to the merger of two named regional banks and what the company describes as its largest fraud agreement to date.

Artificial intelligence adoption is reported as double digit early adopters for the account takeover product, which is candid about being early rather than inflated, and no accuracy or outcome figure is published for any model.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The strongest published element is a clause rather than a document, and it is worth naming precisely because it points at the right control: the conversational layer and its agents are stated to run under the same data isolation, audit logging and compliance controls that regulated institutions require. Data isolation is exactly the assurance a bank needs before letting an agent reach its customer records, and naming it alongside audit logging is more than most of this segment offers.

What is absent is everything that would turn it into a commitment. Two passes located no statement on whether institution or account holder data is used to train or improve any model, no retention position for prompts or conversation content, no subprocessor list, and no description of what crosses the boundary to an external model provider during inference.

The company's own positioning sharpens the question rather than answering it, since a platform that markets itself as a system of context is by definition accumulating behavioural detail about individuals.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The published audit scope is precise and the precision shows what is left out. The service organisation control assessment covers security and confidentiality for the software platform, which means the privacy criterion, the one addressing collection, use, retention and disclosure of personal information, is outside the scope of the report a buyer will be handed.

Confidentiality protects designated information from unauthorised access, which is adjacent to privacy without being the same commitment. Two passes located no data processing agreement, retention schedule or subprocessor list. Specific technical protections are published and do bear on this axis, including encryption at rest, and a capability that fragments payment card data across a private low latency blockchain network rather than holding it centrally. The data at stake belongs to account holders who are not the customer, and it now passes through conversational agents and behavioural scoring as well as through the banking workflow itself.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Security is documented substantively rather than gestured at. A service organisation control assessment of the second type is held for the software platform, covering security and confidentiality, meaning operating effectiveness over a period rather than design at a point in time. A dedicated enterprise security, risk and compliance function is named, several external reviews are stated to occur each year, and security is described as built through the development lifecycle.

Technical detail goes further than the segment norm, publishing a cybersecurity mesh architecture in which one tool detects a threat and informs the others, zero trust perimeter controls, behavioural anomaly detection, endpoint interrogation, continuous monitoring, and a capability that fragments payment card data across a private blockchain network rather than holding it in one place. Availability has a named executive owner.

Three things keep it below the top band: no self serve portal from which reports can be obtained, a maturity level claim that is self assessed against a federal framework rather than certified, and availability sitting outside the stated audit scope despite being a headline commitment.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

The company holds no banking licence and does not claim one, supplying software to the institutions that do, which is the ordinary position in this segment. Its regulatory posture is framed around serving examined customers rather than being examined itself, with repeated references to the governance, security and resilience requirements of regulated financial institutions and to helping customers adopt artificial intelligence responsibly and at scale.

Two passes located no description of how the platform supports a customer's own supervisory obligations, no statement on examination support or regulator facing documentation, no position on the artificial intelligence guidance issued by United States banking supervisors, and no model documentation an institution could place before its own examiner. Audit logging is the one published feature a supervisor would find directly useful, and it is described as a control rather than as a regulatory artefact.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Two passes located no responsible artificial intelligence statement, governance framework, fairness testing, bias evaluation or model card. The exposure here runs through two products rather than one and both touch individuals directly.

Fraud and account takeover detection works on behavioural signals, and a false positive locks a named person out of their own money at a moment they may urgently need it, which is a consequential error with an obvious fairness dimension since behavioural baselines vary with how people actually bank. Personalisation runs the other way, inferring circumstances from transaction data an account holder provided for a different purpose and changing what they are shown as a result.

Neither is addressed by anything published, and the company markets itself on holding real time behavioural context across retail, small business and commercial customers, which is precisely the asset that makes the fairness question worth asking.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Accountability is clearer here than in the underwriting segments because the institution owns the customer relationship and the decision, and it is undefined wherever a model acts in real time. Two passes located no liability allocation between vendor and institution, no error handling policy and no artificial intelligence specific service commitment.

The exposure that matters runs through fraud and account takeover, where the product intervenes as an event happens rather than recommending something to a banker afterwards, and a wrongly blocked account holder experiences an immediate loss of access to their own money with no knowledge that a behavioural model produced it and no route to the vendor that built it.

Audit logging means the event can be reconstructed after the fact by the institution, which is more recourse structure than an unlogged system offers and is not a mechanism the affected person can reach.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

One dependency is disclosed about as plainly as a vendor can disclose one, with the development environment announced under a headline naming both the model and the hosting service it runs on, identifying Anthropic's Claude Code running through Amazon Bedrock. Putting a supplier's model in the product announcement title rather than in a technical appendix is uncommon, and it lets a buyer diligence that supplier on its own terms and understand where inference occurs.

The rest of the estate is unattributed. Two passes located no provider, model family or version for the conversational layer and its agents, for the fraud and account takeover models, or for the personalisation capability, and no commitment to notify customers when any underlying model changes. Having demonstrated willingness to name a supplier once, the silence across the remaining products is the specific question to put.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

This vendor is the engagement platform rather than something layered onto one, and the extensibility story around it is unusually concrete. Retail, small business and commercial banking run on a single platform rather than on separate products stitched together, which is the architectural fact the company builds its data argument on.

Extension is handled through a developer programme with a published software development kit, a partner ecosystem for adding third party capability, and from April 2026 a generative development environment that produces extensions compliant with that kit, turning a partner integration from a services engagement into a build task.

The platform is stated to be core agnostic in the sense that it sits above the ledger rather than replacing it, and a formal certification programme exists to train customer staff on building within it. What a buyer should hold onto is that the ledger, cards and payments systems remain someone else's, so this is the customer facing layer of a wider stack.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

Infrastructure is named openly and the migration to it is documented at scale rather than announced as an intention. Online banking application stacks for more than 450 financial institutions were moved onto a named public cloud provider, described as one of the larger migrations of its kind in this market, and the financial effect is visible in reported results through a 480 basis point gross margin improvement attributed partly to its completion.

Architectural detail is published rather than summarised, including active hosting, a distributed cloud architecture for availability, encryption at rest implemented through the provider's native services, network firewall controls governing both inbound and outbound traffic, and configuration monitoring for drift and patch compliance.

What holds it below the top band is residency rather than architecture, since two passes located no region list, no processing location statement, no residency commitment a customer could contract for, and no tenancy description.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Regulatory Filing

No price, unit or tier is published for the platform or for any of the artificial intelligence products, consistent with this segment. What does reach the market through securities reporting is the shape of the commercial relationship rather than its cost, and it is genuinely informative: average customer contract length above ten years, initial commitments averaging more than five, subscription annualised recurring revenue separated from total, and a committed backlog figure.

A buyer can therefore see that this is a decade long architectural commitment before seeing a number, which is the single most important commercial fact about the category. Two questions remain unaddressed. Whether the artificial intelligence products released in 2026 are included with the platform or licensed separately is not stated, and management's observation that they reach revenue faster than core installs implies separate commercial terms without confirming them.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

Coverage is wide on both institution type and banking segment, which is the combination this axis rewards. Institution types run from community credit unions through regional and enterprise banks, and extend past deposit takers to alternative finance companies and fintechs, meaning the platform serves both regulated institutions and the firms distributing through them.

Banking segments span retail, small business and commercial on one platform rather than through separate products, and the company treats that unification as its structural advantage, arguing that behavioural signal across both sides of the house is what makes account takeover detectable. Recent named business reaches the enterprise tier, including an expansion arising from the merger of two regional banks onto commercial digital banking and commercial fraud management. The qualification worth recording is geographic: the customer base is predominantly United States, with international presence stated in general terms rather than evidenced by named deployments.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing or tier appears on any vendor surface, though securities filings disclose average contract length above ten years and initial commitments averaging more than five
Not published at unit level, and securities reporting establishes the model as multi year subscription with the majority of revenue recurring, since subscription annualised recurring revenue of 826 million dollars sits inside a total of 971 million with the balance in services and other lines. Nothing published indicates the unit inside that subscription, whether charging follows registered users, active users, accounts, assets, institution size or module selection. The platform spans retail, small business and commercial banking with separate fraud, treasury, relationship pricing and account opening capabilities, and no packaging or module pricing is described for any of them. No tiered data protection terms are published. Platform level assurance is real and its scope is stated: a service organisation control assessment of the second type covering security and confidentiality for the software platform, a dedicated enterprise security, risk and compliance function, and several external reviews each year. The privacy criterion sits outside that scope, so the report a buyer receives does not address collection, use, retention or disclosure of personal information, and two passes located no data processing agreement, retention schedule or subprocessor list to cover it. The artificial intelligence specific commitment worth obtaining in writing is the one the company states in announcements rather than in terms, namely that the conversational layer and its agents operate under data isolation and audit logging, together with an answer on whether institution or account holder data is used to train or improve any model. No implementation or professional services fee is published, and the company reports professional services as a distinct revenue line, so the function is material and separately charged without being priced publicly. Management describes discretionary professional services revenue as under ongoing pressure, which tells a buyer that this line is negotiable and currently a soft market. Implementation duration is characterised rather than committed: digital banking implementations are described by management as complex, against which the newer fraud and assistant products are said to reach revenue materially faster than core platform installs. Independent market commentary places cloud native engagement platforms at three to six months to a first production journey, which is an outsider's figure rather than a vendor commitment. The development environment cuts a different cost, with extension delivery claimed to move from weeks to days, and that claim carries no baseline or measurement basis. Regulatory Filing

Two passes across the company's site, its investor materials, its press archive and third party coverage produced no price, unit or tier for the platform or for any artificial intelligence product. What securities reporting does supply is unusually informative about the shape of the commitment even without a figure: subscription annualised recurring revenue of 826 million dollars separated from a total of 971 million, backlog of 2.8 billion, average customer contract length above ten years, initial commitments averaging more than five years, and gross margin of roughly 59 percent.

Those tell a buyer that this is a decade scale architectural decision sold on multi year subscription rather than a product trial. Two commercial questions remain open. Whether the 2026 artificial intelligence products are bundled or separately licensed is unstated, and management's remark that they reach revenue materially faster than core platform installs implies separate terms without confirming them.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746