Ripjar
Ripjar sells enterprise screening to institutions that already have a screening system and are drowning in what it produces. The argument it makes is architectural rather than featural: conventional screening treats every alert as a fresh event, so context is discarded, the same entity is investigated repeatedly, and analyst time is consumed by matches already resolved. Ripjar moves the unit of record from the alert to the entity. Each person or organisation is resolved once into a dynamic risk profile that carries sanctions, politically exposed person status, watchlist hits and adverse media together, retains every prior decision and its rationale, and re evaluates only on material change rather than on every list refresh. Once a link is rejected it stays rejected.
Underneath sits ULTRA, a proprietary engine the company traces to its founders' work at the United Kingdom signals intelligence agency. It carries the entity resolution, the multilingual name matching, and what the company calls specialised explainable AI. The name matching is the sharpest technical claim: over a million name variants across more than 20 scripts and more than 400 languages, resolving transliterations, aliases, diminutives and organisational name parts, benchmarked at 94 percent better than Levenshtein distance. Adverse media is a separate capability with separate coverage, natural language extraction across more than six billion articles in 22 or more languages, resolved into up to 14 million entity profiles and refreshed twice daily.
Three products sit on the engine. Ripjar Screening is the anti money laundering platform. Screening Assistant is an agentic layer that assesses alerts, closes low risk items without a person and escalates the rest with evidence. Ripjar Labyrinth is a threat investigation product sold into security and intelligence work, and a third party risk product called 3P60 extends the same screening to counterparties and suppliers.
Scale is stated precisely rather than vaguely: more than 300 customer deployments including six of the 29 global systemically important banks, alongside corporates and regulators. Dow Jones is both an investor and a published customer. The company is Ripjar Ltd of Cheltenham, founded 2012, majority backed by Long Ridge Equity Partners with Accenture and Winton also on the register.
Capability Axes
Capability grades
15 of 15 axes rated · 4 graded A or B
The vendor answers the removal test itself by publishing the benchmark. Its name matching is stated at 94 percent better than Levenshtein distance, and Levenshtein is precisely the deterministic string algorithm that a screening system uses when it has no model. Naming the non model alternative and quantifying the gap against it is the removal test performed in public, and the answer is that what remains without the models is a tool the vendor says is materially worse.
The rest of the estate points the same way. Adverse media coverage rests on natural language extraction across more than six billion articles resolved into up to 14 million entity profiles, which is not reachable by keyword rules, and the company is explicit that keyword noise is the thing it exists to remove. Entity resolution across more than 20 scripts and more than a million name variants is a learned matching problem rather than a lookup.
Screening Assistant is an agentic layer making close and escalate judgements. The engine is proprietary and named, and the founding team came from signals intelligence work where this class of analytics was the product.
The machine closes alerts, and the floor beneath that is not published. Screening Assistant is described as an agentic capability that assesses alerts, automatically closes low risk items and escalates edge cases with evidence and an audit trail, and the vendor quantifies the effect at 77 percent reduction in human effort and up to 91 percent fewer false positives reaching a person.
In anti money laundering an alert closed is a decision not to investigate, so the failure mode is not a bad recommendation a human overrides but an investigation that never happens, on a subject who will never know and cannot contest it.
The controls the vendor does publish are meaningful and should be credited: every automatic closure is recorded with its evidence and reasoning, the trail is built to be reconstructed for an examiner, and edge cases are routed to a person by design rather than as an option. What is absent is the boundary.
Nothing published states the confidence threshold governing automatic closure, whether it is customer configurable and to what floor, whether any human sampling of closed items is required or merely available, or what the vendor will not allow to be closed without a person. This lane's own guidance is to settle accountability for machine made filing decisions in the contract, and that question is not answered on the public record here.
One genuinely good disclosure and one conspicuous half of a number. The good disclosure is the benchmark: the vendor names Levenshtein distance as the comparison baseline and states a 94 percent improvement against it. Naming a reproducible, publicly understood baseline rather than claiming improvement against an unnamed legacy system is real methodological transparency and sits at the top of this grade. The conspicuous half is the headline.
False positive reduction is published at up to 91 percent with no accompanying true positive retention figure anywhere on the vendor's surface. A false positive reduction is trivially achievable by detecting less, so without the retention figure alongside it the number cannot be interpreted, and this index has already recorded a competitor in this lane publishing both sides precisely because one side alone is uninformative.
The gap matters more here than elsewhere because the mechanism generating the reduction is automatic alert closure. Also absent across two passes: validation methodology, recall against a known adverse set, drift or retraining disclosure, model documentation for a buyer's own model risk function, and any statement of who validates the models or how often.
Among the better evidenced records in this lane, and the institutional claim is falsifiable rather than decorative. Rather than referring to leading global banks, the company states more than 300 customer deployments including six of the 29 global systemically important banks, a count a buyer can interrogate against a published list.
Outcomes are quantified across several distinct dimensions rather than one headline: false positive reduction up to 91 percent, review time down 85 percent from 20 minutes to 3 minutes, 21 times faster processing at enterprise volume, a 500 percent increase in screening coverage on existing headcount, 80 percent reduction in analyst workload, and 77 percent reduction in human effort attributed to the agentic layer.
One customer case study is named, Dow Jones, taking screened names from under one million to over ten million. Independent standing is current and repeated: category leader placement in two separate Chartis quadrants covering adverse media monitoring and name and transaction screening, stated as the third consecutive year in both. Reported annual recurring revenue growth of 40 percent was published in May 2026. What holds the record short of perfect is that the two bank case studies are anonymised by tier, and the outcome figures are vendor reported without independent verification.
Strong on traceability, silent on the two commitments that matter most for a vendor whose models improve. The traceability is real and repeated across surfaces: every decision time stamped, source linked and traceable, a complete decision history held on the entity profile, recommendations described as evidence backed and auditable, and one case study reporting fully traceable decisions.
For a screening product that is a substantive safety control, because it lets a supervisor reconstruct why an alert was closed rather than take the outcome on trust. The first silence is training data. The platform ingests the customer's own internal datasets alongside public feeds, and no statement was located across two passes on whether customer data, analyst decisions or closed alert outcomes are used to improve the vendor's models, which is the question a bank's own risk function will ask first.
The second silence is the boundary on the agentic layer. Automatic closure of alerts is safety relevant by definition, and nothing published describes the confidence threshold at which it acts, what sampling of closed items is expected, or what the vendor considers an acceptable rate of wrongly closed alerts. No red team result, evaluation methodology, incident disclosure or acceptable use boundary was located.
A United Kingdom company with a United Kingdom frame and nothing published for the American one. A privacy notice, a cookie policy and a separate job applicant notice are published, which is baseline European practice. The architecture carries a genuine privacy virtue that is worth stating: the platform is data agnostic, so the customer brings its own sanctions, politically exposed person and adverse media feeds and its own internal datasets, meaning the vendor is not itself the source of the risk data and the customer retains its supplier relationships.
Against that, the Gramm Leach Bliley Act appears nowhere on the vendor's surface, no safeguards rule position, American state privacy framework or financial privacy programme was located across two passes, and the company sells into the United States market. The subject shaped gap is the same one the whole adverse media category carries and no better addressed here.
Every profile is a compiled record about a named individual who did not consent to it and will not see it, retained deliberately so that decisions persist, and the public surface says nothing about retention limits for that profile, correction of an erroneous adverse media link, or how a wrongly rejected or wrongly retained association is unwound for the person concerned.
Two badges in a footer, and nothing behind either of them. The site carries images asserting ISO 27001 certification and SOC 2, which is the correct pair of credentials for this buyer set and more than many in this lane display. What is not published is anything that would let a buyer act on them.
There is no trust centre, no downloadable certificate, no attestation report, no scope statement and no Statement of Applicability, so the boundary of the certified management system cannot be read from outside, and for a platform where the screening pipeline and the retained entity profiles are the sensitive assets, the scope is the question. One drafting point should not be read past.
The badge describes the second credential as SOC 2 compliant, and SOC 2 produces an independent attestation report rather than a certification or a compliance state, with the meaningful distinction being between a Type 1 point in time opinion and a Type 2 opinion over an observation period. The badge states neither.
A buyer should ask which type, over what period, under what scope, and whether the report is obtainable, before treating the mark as equivalent to the certificate sitting beside it. Encryption, access control and penetration testing practice are undescribed on the public surface.
An unregulated supplier that neither claims otherwise nor documents its standing. Ripjar Ltd is a United Kingdom private company selling software into obligations its customers hold, and it holds no financial services authorisation, presents itself as no kind of regulated data provider, and overstates nothing, which is worth crediting in a category prone to implied standing.
It carries a genuine adjacent credential in that its founders built systems for the United Kingdom signals intelligence agency and it counts regulators and government agencies among its customers, so it has been through public sector assurance of some form. That heritage is asserted repeatedly and never evidenced with a named accreditation, clearance level or framework.
On the financial side, published material engages the senior managers and certification regime and the Singapore individual accountability guidelines substantively rather than as decoration, which shows the company understands where accountability lands. Understanding a regime is not standing under it.
Across two passes nothing was located on regulatory examination outcomes at customers, supervisory review of the automatic closure behaviour, a position under the European Union AI Act despite profiling named individuals for regulated decisions, or any public data protection registration.
The exposure is unusually concrete here and the disclosure does not meet it. The product's central technical claim is name matching across more than 400 languages and more than 20 scripts, resolving transliterations, aliases and diminutives. Transliteration and alias resolution do not fail evenly.
They fail differently by script, by naming convention and by how well represented a name tradition is in the training material, which means the probability of being wrongly matched to a sanctioned or adversely reported namesake, and the probability of being wrongly cleared, both vary by where a person's name comes from. That variance is then compounded by an agentic layer that closes alerts automatically.
A person whose name transliterates poorly may be repeatedly matched to the wrong subject, or repeatedly cleared when they should not be, and under the entity model a rejected link is retained as rejected and carries forward. The 94 percent improvement over fuzzy matching is a single aggregate number across all of that.
Across two passes no per script or per language accuracy breakdown, fairness testing, bias statement, model card or governance page was located, and no published position addresses whether the persistence of a prior decision can entrench an error.
The public record is silent on every question this axis asks. Across two passes no terms of service, master subscription agreement, acceptable use policy, warranty, indemnity, liability cap, service level commitment, uptime credit or professional indemnity position was located on any vendor surface, and no statement describes what the vendor owes a customer if the platform automatically closes an alert that should have been escalated.
That silence lands harder here than it would on a passive tool. The product is sold on the strength of removing work from people, the agentic layer acts without a person on the majority of alerts, and the resulting exposure sits with a regulated institution facing an examiner and, under the accountability regimes the vendor's own material discusses, with a named individual inside it.
Adjacent to recourse but not a substitute for it, the platform does provide the evidence a customer would need to defend its own position, since every decision including every automatic closure is time stamped, source linked and reconstructable. That helps the customer answer for the outcome. It does not move any part of the outcome onto the vendor, and nothing published suggests any part of it is.
Half the chain is named and the half a buyer cannot audit is not. The proprietary half is disclosed clearly: the engine is called ULTRA, it is stated as the vendor's own, it carries the entity resolution, multilingual name matching and explainable analytics, and it is traced to the founders' signals intelligence background.
A buyer therefore knows the core analytics are built in house rather than resold, which is genuine disclosure and rules out the undisclosed third party dependency that this axis mostly exists to catch. The external half is acknowledged and then left blank. The company announced in 2023 that its summary capability would use large language model technology, and current material describes an agentic capability, so a foundation model dependency exists and the vendor has said so.
No provider is named anywhere across two passes, and no statement describes whether that model is hosted inside the vendor's own environment, whether screened subject data or customer material passes to it, or what the provider's own terms permit. Competitors in this lane already name their model provider outright, which makes this a choice rather than an oversight, and the buyer question is simply whose model reads the adverse media about their customer.
Data neutrality stated as an architectural commitment rather than a feature, which is the substantive point on this axis. The vendor describes itself as data agnostic by design and states there is no lock in to a single data provider, integrating United States, European Union, United Kingdom and Australian sanctions regimes, politically exposed person databases, any adverse media supplier the customer chooses, and the customer's own internal datasets.
That matters commercially as well as technically, because much of this category routes buyers onto a captive data feed and this vendor publicly declines to, leaving the buyer's supplier relationships and negotiating position intact.
Distribution reaches through partners rather than only direct: a market data and risk business is both investor and channel, a sanctions intelligence firm partnership is published, a regional anti money laundering partnership was announced in 2025, and a global consultancy sits on the share register. The product also appeared in a major cloud provider's security data lake launch. Holding it below the top band is the documentation.
Across two passes no interface reference, connector catalogue, developer portal or published integration specification was located, so a buyer assessing effort has the claim of neutrality without the artefact that would let an engineer verify it.
An unusual absence given who the customers are. The vendor sells to tier one banks, regulators and government agencies, buyers for whom hosting location and tenancy are gating procurement questions rather than details, and the public surface answers neither.
Across two passes no statement was located on the vendor's own site describing whether the platform is offered as multi tenant hosted software, single tenant, private cloud or customer premises, which hyperscaler or hyperscalers it runs on, which regions are available, or what data residency commitments are made to European, Asian or Middle Eastern buyers.
Indirect signals exist and are not sufficient to grade on: the company's national security heritage and its regulator and government customer base imply a private or isolated deployment capability, a third party aggregator describes options running on the customer's own hardware or delivered as a service, and a company profile lists American server infrastructure. Those are inference and hearsay respectively rather than vendor statement.
The architecture does reduce residency exposure at the margin, since the customer supplies its own data feeds and internal datasets, but the screened entity profiles and the retained decision history sit with the vendor and their location is unstated.
Two passes across the vendor's own site, its product and use case pages, its published questions and the software aggregator listings produced nothing on commercial terms. No price, no currency, no tier, no unit of billing, no contract length, and no statement of what the subscription is even measured against, whether that is screened names, alerts, seats or entities under monitoring.
For an enterprise platform sold into tier one banks a private rate card is the norm and not a fault in itself, but the absence here extends past the number to the shape, and a buyer cannot form a budget expectation or compare the commercial model against an incumbent without entering a sales process. The single entry route published is a demonstration or a 30 minute screening diagnostic call, offered without charge, which is a pre sales assessment rather than a trial of the product.
The one figure the company does publish on cost is other people's: an industry estimate of 30 to 70 dollars to review a single false positive alert, used to frame the value of removing them. This sits at the lower end of what this grade covers, and disclosing the billing unit alone would move it.
Depth at the top of the market, stated with unusual precision, and little published below it. The six of 29 global systemically important banks claim is the most specific institutional penetration statement located in this lane, and it is supported by tier one and tier two bank case studies, a named market data and risk customer, and stated coverage of global corporates, regulators and government agencies.
Regulatory literacy is segment specific rather than generic, with published material engaging the United Kingdom senior managers and certification regime and the Singapore individual accountability guidelines by name. Sanctions coverage spans the United States, European Union, United Kingdom and Australian regimes, so the geographic spread behind the customer claim is real. What is missing is the rest of the market.
Nothing published addresses credit unions, community and regional banks, payment firms, insurers or fintechs, and no entry configuration or lighter tier is described anywhere, so the smaller regulated buyer cannot tell whether the product is meant for them. The estate also reaches beyond financial services into security and intelligence work through the investigation product, which is coherent given the company's origins but dilutes the financial concentration.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No price, tier, unit of billing or contract length appears on any vendor surface
|
Not published. The vendor states nothing about how the product is priced or measured. Enterprise contract sold through a demonstration and a sales process, with partner led routes available through named channel and consultancy relationships. The only cost figure published anywhere in the vendor's material describes the buyer's existing burden rather than the vendor's price, citing an industry estimate of 30 to 70 dollars to review a single false positive alert and false positive rates of up to 95 percent, used to frame the value of removing them. | Not published at any tier. Data handling commitments are absent from the public surface beyond a privacy notice and a cookie policy. No data processing agreement, subprocessor list, retention schedule or model training commitment is obtainable without contacting the vendor. The architecture reduces the vendor's data footprint at the margin, since the customer supplies its own sanctions, politically exposed person and adverse media feeds and its own internal datasets, but the resolved entity profiles and the retained decision history sit with the vendor under terms that are not public. | No implementation, onboarding, configuration or migration fee is published, and no statement describes whether deployment is a professional services engagement or included in the subscription. For an enterprise screening platform replacing an incumbent system at a tier one institution, migration of historic alert decisions and tuning against the buyer's own alert volume are substantial pieces of work, and the vendor's entity model makes prior decision history explicitly valuable to carry forward, so the question of who performs and pays for that migration is material and unanswered. What the vendor does publish is free of charge and pre sales: a product demonstration and a 30 minute screening diagnostic in which a specialist reviews the buyer's current capability, identifies gaps and benchmarks against practice. That is an assessment rather than a trial, and no free tier, sandbox, proof of concept term or trial period is published. Partner led delivery exists through a global consultancy on the share register and named regional partners, which implies a services layer priced by those partners rather than by the vendor. | Vendor Published |
Two passes across the vendor's own site, its product and use case pages, its published questions and the software aggregator listings produced no commercial disclosure of any kind. Unlike most contact sales postures, which at least name the billing unit or the tier structure, this one publishes neither, so a buyer cannot tell whether the subscription is measured on screened names, alert volume, entities under continuous monitoring, seats or platform modules.
Aggregator listings carry empty price fields and one notes the company has not claimed its profile. The grade sits at the lower boundary of what it covers, held there rather than lower because the vendor is transparent about the entry route and charges nothing for the pre sales assessment. Publishing the billing unit alone, without any figure, would move this. Separately, buyers should note that four products sit on the platform and nothing published indicates whether they are licensed together or separately.