Spektr
Spektr, legally spektr ApS, is a Copenhagen compliance infrastructure company founded in 2022 by Mikkel Skarnager as chief executive with Ciprian Florescu as chief technology officer, Jan-Erik Wagner as chief revenue officer and Jeremy Joly as chief product officer, a founding team with a prior exit in identity verification. Its argument is that a decade of compliance technology addressed workflow and data collection while leaving the analytical work itself to human analysts, so it sells agents that do that work: researching a company, interpreting what is found, verifying that a business genuinely operates, mapping ownership, and writing a structured risk rationale.
Nine named agents cover business verification, industry classification, network discovery, address checking, licence checking, document review, source of funds, false positive reduction and website checking, and an agent builder lets a customer define new ones, specifying how they gather data, apply logic and produce outputs. Around the agents sit configurable processes for business and individual onboarding, monitoring, risk scoring, remediation, enrichment, questionnaires, credit and customer scoring and event orchestration, with a public API. Agents can be shipped across jurisdictions, watched in production and rolled back immediately.
Named customers include Santander Leasing, Nexi, Pleo, Mercuryo, Monta, Kompasbank, Athlos and Fyorin. It raised a 20 million dollar Series A led by New Enterprise Associates in April 2026 with Northzone, Seedcamp and PSV Tech, taking total funding to roughly 26 million dollars, and opened offices in London and New York. Its disclosure is unusually complete: it holds ISO/IEC 27001:2022, ISO/IEC 27701:2019 and ISO/IEC 42001:2023 certifications and a SOC 2 Type II attestation, publishes the certificate numbers and names both the certification body and the attesting firm, and states that all data sits within the European Union and is handled only by people based there.
Capability Axes
Capability grades
15 of 15 axes rated · 9 graded A or B
The company's founding argument is a centrality argument. Its stated view is that compliance technology has spent a decade on workflow and data collection while the actual bottleneck, analysts researching companies and documenting decisions, was left untouched, and the product is built to take that work rather than to route it.
Nine named agents each perform an analytical task, and an agent builder lets customers define more by specifying how they gather data, apply logic and produce outputs. Strip the models and what remains is the configurable process layer, which is precisely what the company describes as the insufficient state of the rest of the market. This is the CleverChain side of the orchestration line rather than the Ondorse side: the agents reason and conclude, and the workflow engine exists to carry their conclusions somewhere.
The first A on this axis in the business verification pocket, and it rests on a control almost nobody in this index publishes: agents can be shipped into production, watched in real time, and rolled back immediately. Described precisely, that is deployment level withdrawal of a misbehaving agent rather than a per decision kill switch, but it is a real and stated mechanism for retracting autonomous behaviour from live compliance work, and no competitor in this pocket describes anything equivalent.
Around it sit three further elements: agents return structured outputs for a human team to act on rather than deciding alone, the monitoring layer commits to showing how a decision was reached with visibility at every step rather than only the final answer, and the whole arrangement sits inside an independently certified AI management system. Traceability at step level plus a stated withdrawal mechanism plus a human acting on the output is the enforcement mechanism named and positioned in the execution path.
A monitoring layer that tracks how agents perform and an optimisation loop that refines their logic over time are described as product capabilities, and feedback loops exist as a named process, so measurement is clearly happening. None of it is published. No accuracy figure, no false positive or false negative rate, no benchmark, no evaluation methodology, no model documentation and no validation pack for a customer's own model risk function.
Graded C deliberately rather than crediting the ISO 42001 certification a second time here: that certification is an audited management system and it earns its grade on the governance axis where it belongs, and counting one credential twice is the double crediting this index refuses elsewhere. A vendor that has clearly built the measurement apparatus and publishes no result from it is a C on evidence, not a B on inference.
Eight named customers carrying individual case studies, and a named executive on the record: the head of compliance at Fyorin, quoted by name and title. That is squarely the B bar. It stops short of an A because no quantified outcome is attached to any named customer in the vendor's own material.
The published quote is qualitative, describing a fast move from concept to production, and the figures that appear in trade coverage of the funding round are generic claims about hours becoming minutes rather than a result measured at a named institution. The ingredients for an A are close: the customers are named and the case studies exist, so a single published number against one of them would move this grade.
The pooled corpus question is unanswered and this vendor is better placed than most to answer it. Customers are told they have full control over data, access and how AI operates on their platform, and all data stays inside the European Union, but nothing states whether customer documents, corporate records, analyst corrections or agent outputs are used to train or improve models served to other customers.
The question is live here because the product ships a shared library of agents that improve over time and an optimisation loop that refines agent logic, so a customer would reasonably ask whether their material is what the refinement learns from. Three vendors in other pockets have now answered this plainly, and a vendor holding a certified AI management system publishing no answer is a choice rather than an oversight.
Materially above the policy and badge floor that this pocket usually sits on, on the strength of a certification almost nothing in this index holds: ISO/IEC 27701:2019, an independently audited privacy information management system rather than a self declaration of GDPR compliance. Alongside it is a residency and access statement that is specific in a way most are not, committing that all data is located within the European Union and is handled by people based in the European Union.
The second half of that closes the support access gap that most vendors leave open, where data resident in one jurisdiction is routinely accessed by staff in another. Held below an A because no subprocessor list, retention schedule or data processing agreement terms were located in the vendor's own top level material.
The strongest credential disclosure in this pocket and among the best in the index, because it survives every part of the credential test with room to spare. ISO/IEC 27001:2022 is named with the correct current edition and with its certificate number published. The certification body is identified by name, Mastermind Assurance LLC, which lets a buyer check the certificate against the registry rather than trust a badge image. The SOC 2 Type II attestation names the attesting firm, A-LIGN.
A trust page carries the detail. Publishing certificate numbers and the accreditation chain is the standard set by idenfy, previously the high water mark in this index, and this vendor meets it while also holding two further certifications. Nothing here is a supervisory body dressed as a certification, and nothing is an unenumerated claim.
A software supplier outside the regulatory perimeter. No licence, no registration, no supervised sandbox participation and no enrolment in a regulator run scheme was located. Its customers hold the anti money laundering obligations and answer to supervisors; the vendor holds neither.
The certifications it does hold are voluntary international standards audited by private bodies, which is a different thing from regulatory standing, and this index has consistently declined to read conformity assessments across as supervision.
This vendor holds ISO/IEC 42001:2023 with its certificate number published and its certification body named, which puts it among a small number of holders located anywhere in this index and makes it the only one in this pocket, where every peer is silent. That is a genuine independently audited AI management system covering data governance, model transparency, bias controls and human oversight.
Held at B rather than A on the standing rule earned from hyperexponential: a management system certification attests to the process around the models and is not evidence about the models themselves. No fairness testing, no error breakdown and no evaluation across jurisdictions, name types or business structures is published.
The specific unexamined exposure is that agents which classify industries, verify that a business is real and judge source of funds will read some business types, sectors and countries less reliably than others, and a business wrongly judged is refused an account.
The party carrying the consequence of an error is a business that is not the customer. A company wrongly classified, wrongly judged to be inactive, or wrongly assessed on source of funds may be declined or offboarded by its bank without learning that an agent produced the finding, and it has no relationship with the vendor, no notice and no route to challenge.
Nothing published states who bears the cost of a wrong agent decision, how a disputed output is corrected, or whether corrections reach institutions that already acted on it. The rollback capability is an operational control for the vendor's customer, not a remedy for the business on the other side of the decision. The regulated institution absorbs the supervisory consequence for reasoning it did not produce.
No model provider, family or version is named in the vendor's own top level material, and no third party provider case study naming this vendor was located either, so the supplier discloses the vendor check returned nothing. For a platform whose entire product is agents built on language models, and which certifies its AI management system to ISO 42001, the absence is notable rather than ordinary: the certification implies a documented supply chain internally, and none of it is published.
Nothing states where inference runs, which providers receive customer documents and corporate records, or what those providers may retain, although the stated commitment that all data stays within the European Union constrains the answer more than most vendors do.
A published API with its own developer documentation, a dedicated integrations page, a coverage map, release notes, and an event orchestration process that lets outcomes in one system trigger checks and downstream actions in another. Public API documentation is more than most of this pocket offers and it means a buyer can assess the integration surface before contracting.
Held below an A because no specific system of record is named in the vendor's own top level material: a buyer learns that the platform connects and orchestrates, not which core banking, case management or customer system it plugs into, nor which data providers sit behind the agents.
An explicit and unusually specific residency statement on an axis where most of this index says nothing at all: all data is located within the European Union and is handled by individuals based in the European Union. The personnel clause is the part worth noting, because it addresses who can reach the data rather than only where it rests, and a buyer running a transfer impact assessment needs both.
Agents can also be scaled across jurisdictions without rebuilding, which implies jurisdictional configuration in the product. Held below an A because no cloud provider, region or availability zone is named, no single tenant or private deployment option is described, and no customer managed key or bring your own storage arrangement appears.
No pricing published at any level: no list price, no tier structure, no per check or per seat basis, and no indication of how cost scales with volume or with the number of agents deployed. The route in is a demo booking or a self guided product tour, which is marginally more open than a demo gate alone because a buyer can see the product before speaking to sales, but it produces no cost information. For a platform sold on replacing analyst headcount, no figure exists against which a buyer could test that trade.
Named customers across five buyer types for a company only four years old: a global bank's leasing arm in Santander Leasing, major European payments infrastructure in Nexi, a Danish challenger bank for small businesses in Kompasbank, spend management in Pleo, crypto payments and wallets in Mercuryo and a wallet serving over twenty million users, plus Athlos and Fyorin. Held at B rather than A on two counts.
The disclosed customer count is modest and no figure is published for institutions served in total, and the base is concentrated in Europe with the London and New York offices only just opening. One named customer, an electric vehicle charging platform, is a non financial corporate buying onboarding compliance, which is worth recording as a widening of the buyer set rather than as a problem, since the majority of named customers are regulated financial institutions.
What Changed
Material product, regulatory, evidence and commercial changes at Spektr, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Spektr released version 3.0, adding real time transaction monitoring, a Policy Engine that translates written compliance policies into executable rules, and Case AI, which uses agents to gather evidence and recommend investigation outcomes with citations and confidence levels, on top of its existing KYC and KYB system.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Spektr
The closest documented capability profiles to Spektr in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Operational and Outcome Evidence and Institution and Segment Coverage
A lighter documented profile than Spektr
A lighter documented profile than Spektr
A lighter documented profile than Spektr
Documents Regulatory Status and Licensure and AI Liability and Recourse where Spektr does not
Documents Regulatory Status and Licensure and Model Risk Management and Transparency where Spektr does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.