Platform
Solutions
Resources
Company
Resources
Sanctions screening · AML · Fraud monitoring

Agentic AI powered AML & Risk Intelligence Platform

Reclaim up to 80% of the time your compliance processes take today. TruvaLI automates the operational load of AML, sanctions screening, identity verification, transaction monitoring, anomaly detection and risk scoring on a single platform.

Sanctions screening480+ sources · 257 countries

Live monitoring
0 less time on compliance operations
< 200 ms Risk score per event

Transaction monitoringEvery event scored in real time

Identity verificationRemote ID check in a single session

AMLKYCFraud Risk scoringAnomaly detectionScreening

Agentic AI assistantPrompt to rule · prompt to scheduled report

Trust

Security at global standard. Proven, certified, zero tolerance.

TruvaLI meets the highest international standards for information security, outsourced service provision and enterprise quality. Every certificate below covers a live management system you can hand to an auditor, not a one-off assessment.

ISO/IEC 27001

Information security: protects information assets end to end.

Certified management system

SOC 2 Type II

Security, availability and confidentiality, evidenced over an audit period: the control report global banks and financial institutions ask for.

Independent attestation

Six more management systems

Each one a live, audited certificate you can hand to a supervisor, not a one-off assessment.

  • ISO 22301Business continuity: keeps the service resilient through disruption.
  • ISO/IEC 20000-1IT service management: structured enterprise IT service processes.
  • ISO 9001Quality management: continuous, measured quality improvement.
  • ISO 37001Anti-bribery: ethical governance across the supply chain.
  • ISO 10002Customer satisfaction: structured complaint handling and resolution.
  • ISO 45001Occupational health & safety: a safe working environment for the team.
Compliance & Regulation

Built for the regulators you answer to.

Local and EU obligations, met from one platform.

MASAK

TruvaLI helps financial institutions detect transaction and customer risk earlier in their MASAK AML/CFT processes, manage investigation workflows and keep every decision on record.

KVKK

TruvaLI helps manage access, retention and security controls for the sensitive data used in financial-crime and risk analysis, in line with institutional policy.

GDPR

TruvaLI supports the technical security controls GDPR requires by offering access control, data security, an audit trail and on-premise deployment options across the risk-management processes that handle personal and financial data.

AMLA

TruvaLI helps institutions manage customer risk assessment, Transaction Monitoring, Sanctions & PEP Screening, Ongoing Monitoring and Case Management from a single platform.

Your data centre Private cloud

On-Premise Deployment

TruvaLI runs inside your own environment. Data, keys and the audit trail stay under your control, in your building.

Deployment details
[ On-premise architecture ]

Everything you need to know about running TruvaLI on your own infrastructure.

What does on-premise mean at TruvaLI?

It is installed on infrastructure your own team operates. Customer records, transaction data and case files never leave your network; retention, backup and access follow your policies rather than ours. Releases arrive as versioned packages that your team schedules, so nothing changes in production without your say-so.

Built for institutions that answer to a regulator

Banks, payment and e-money institutions, insurers and crypto-asset service providers all face the same outsourcing question from their supervisor: where does the data go, and who can reach it?

TruvaLI runs on-premise inside your own information systems; customer records stay under your control and under your own retention rules.

That answers the outsourcing question the same way in every market we operate in: EU outsourcing guidelines for financial institutions, the Turkish communiqué on information systems of payment and e-money institutions, and the data-residency rules that come with each.

Audit cooperation, data return and destruction, continuity, subcontractors and breach remediation are contractual, not a statement of intent.

The same installation is your team's development environment

Every capability in TruvaLI (screening, scoring, case management, reporting) is exposed through a documented API, so your own teams can build on top of it: connect it to the core banking system, the CRM or the data warehouse, and automate the hand-offs that still run on e-mail. Integrations no longer wait on a vendor roadmap.

And because TruvaLI watches events and fires on rules, what you automate does not have to be a compliance workflow at all. A retail team can write the rule "text the new campaign to customers who spent well last month but have not visited this month" themselves. Segregation of duties keeps the teams apart: no department sees another department's rules.

An MCP server for your AI agents

TruvaLI's MCP (Model Context Protocol) server lets the AI assistants and agents your teams already use connect to the platform directly, querying cases, running screenings and drafting reports through the same governed API, without leaving your perimeter. It is the shortest route from an idea in your innovation team to an automation running in production.

Developers
[ Screening ]

Sanctions, PEP, adverse media, official sources and sector lists. One screening.

TruvaLI screens people, companies and vessels against 480+ sources across 257 countries and territories, then adds the lists we prepare for your sector and the lists you build yourself. AI reads the news about them and confirms the match with a photograph. One search answers every list at once.

  1. Sanctions lists

    UN, EU, OFAC, UK HMT and the national programmes that matter in your markets, consolidated into one index and matched on aliases, transliterations and dates of birth rather than spelling alone.

    480+ sources · 257 countries · 15-min refresh
  2. PEP lists

    Politically exposed persons with their relatives and close associates: heads of state, parliaments, senior officials, state-owned enterprise boards and regional office holders, each with the role and the date it was recorded.

  3. Official sources

    Gazettes, court records, regulator notices and enforcement actions, read by TruvaLI and turned into structured list entries automatically, so a new circular becomes a screenable list the same day.

  4. Sector lists

    Lists built for your customer's sector that you will not find ready anywhere else: national athletes, referees and club presidents for sports betting; well-known musicians and influencers for payment and e-money institutions. They ship with the platform, so nobody on your team has to compile them.

Schedule a demo

Your own lists, built with AI

Describe who you want to watch, or hand over a website address: the AI crawls the site end to end, pulls the names out of it and builds a deduplicated list, ready to screen against, in minutes. From a debtor list to an internal blacklist.

  • Deduplicated
  • Ready to screen
  • In minutes

Adverse media, read in any language

AI reads the news, classifies it by risk (fraud, corruption, terrorism financing, organised crime) and links it to the right person, not a namesake.

Photo confirmation

When a name matches a sanctions list or an adverse media story, TruvaLI finds the person's photograph in the source, or failing that on priority addresses such as Wikipedia, and shows it with a confidence score. You see whether the person in front of you is the person in the news.

Lists from official documents

Upload a gazette, a court order or a regulator circular. Names, aliases and identifiers are extracted and become a sanctions list or a blacklist automatically, with no re-typing.

Every compliance and risk need, on one platform

One contract. One integration.
Lower cost, higher throughput.

TruvaLI is an orchestration product: AML and sanctions screening, identity checks, fraud monitoring, real-time scoring, anomaly detection and case management do not stand apart as separate products; they work together end to end on one view of the customer.

AML & sanctions screening

Real-time screening against global sanctions regimes, PEP records, adverse media and watchlists, plus any internal list you maintain yourself.

Remote identity verification

Remote identity checks at onboarding and at the moment of a transaction: document capture, OCR, NFC chip read on ICAO 9303 ID cards and passports, passive liveness and video verification, all in a single session.

Real-time transaction monitoring

Watch every transaction and account event as it happens, and catch suspicious behaviour before it turns into a loss.

Anomaly detection

It weighs financial and non-financial behaviour together and surfaces the movements that fall outside the usual pattern, without you writing a rule for them.

Real-time risk scoring

A dynamic score for every customer, transaction and counterparty, recomputed in under 200 ms as behaviour changes.

Case management & reporting

AI-assisted investigation, regulatory reports drafted automatically in your own format, and a complete audit trail behind every decision.

Agentic AI

Your AI-powered compliance team.

Agentic AI does not wait to be asked. It reads the cases, drafts the rules and the filings, and puts each one in front of your analyst for a decision, so the team spends its day judging risk rather than assembling it.

See the copilot at work
01

Writing a rule needs neither code nor menus

  • In other systems a rule is built in SQL, or through long chains of drop-down menus. In TruvaLI you describe it in a sentence: write “flag transfers over €10,000 from accounts opened today” and the AI drafts the rule and waits for your approval.
  • A report you have already built can be turned into a rule in one step; you do not start again to get from analysis to enforcement.
02

Your rule set keeps itself current

  • The AI reviews the cases as they happen and weighs them against the policies, regulations, official gazette changes and news events you have loaded into the system. What comes out is either a new rule or an improvement to one you already run.
  • So you are not left with fixed thresholds written years ago. What you save into your knowledge base can become a rule set, and the proposals run through simulation and check themselves; approving them is still yours.
03

Network and relationship analysis

  • People at the same address, people sharing a surname, transfers into the same IBAN, connections from the same IP or the same device ID, e-mail addresses that fuzzy-match one another, phone numbers registered in sequence on the same day.
  • TruvaLI weighs these traces together rather than one by one. Details that mean nothing on their own bring mule networks and organised fraud structures into view on a graph.
04

Closing the case comes down to one approval

  • Compliance officers have to write rules they know will raise false positives, because the regulation asks for every case to be reviewed and closed, and the day goes on that work.
  • Say a customer's surname changed on marriage and her identity details no longer match the record. TruvaLI has already asked her to verify and already suspended the account. The AI reviews the case in advance and writes down what happened and what was done; all that is left for the officer is to approve it.
05

Reporting needs no code either

  • A report builder where you set the conditions the way you write a rule, down to the columns you want. Or you describe it to the AI in a sentence and have the report built for you.
  • Pick the days of the week and the hours and the report is produced on its own. Behind it the system writes the SQL, the aggregations and the derived fields; there is no template for you to upload.
06

The final decision is always a person's

  • The AI has no place in the maker and checker chain and cannot have one: the regulator wants a real person carrying the responsibility, and an AI cannot be held to account.
  • TruvaLI prepares the work, gives its reasons and puts it in front of you; the signature, the filing and the accountability stay with your team.
100% the share of final decisions taken by a person

People direct. AI assists. The final decision is always human.

Beside the compliance officer

You describe it. TruvaLI writes the rule, and the report.

Your team already reviews stacks of transactions. TruvaLI is not one more system to feed: it drafts the rule, assembles the report, and hands over a judgement that is ready to approve.

Writing a rule
You type

Flag the cases where three different customer accounts were signed into from the same device id.

TruvaLI returns
  • A drafted rule with the parameters filled in
  • Opened in simulation, or replayed against a date you name so you see the result on that day's traffic
  • Held for your approval: nothing goes live on its own
Writing a report
You type

Summarise last month's flagged gaming customers for the MASAK filing.

TruvaLI returns
  • The report drafted in your own reporting format
  • Every figure traceable to the case it came from
  • Yours to review, edit and sign

Write it in whichever language you use

Write to the copilot in Turkish, in English, in whichever language your team works in; a language-detection layer reads your sentence. The rule record it produces carries the whole detail, down to why each condition is there, so what you put in front of an auditor is a decision with its reasoning attached rather than a black box.

Not a separate product, it lives in the screen you work in

The copilot sits inside the rule and report screens. While you are writing a rule you say “ask the AI” and carry on from the same place; your team learns no new interface and changes no habit. Whether to ask for help at all is your call at every step.

People who have sat in your seat

There are not only engineers on our team: the practitioners on the compliance and fraud side carry ten to fifteen years and more of it inside banks. When a supervisor asks a question you have not met before, there is someone to call who has answered it from their own desk.

One platform · one contract
80%

less time lost to compliance operations. Screening, identity checks, monitoring and reporting run on one platform, so your team finishes the work without changing screens.

Risk management doesn't have to be complex or expensive.

Scale is a matter of resources, not limits

In load testing it ran clean on a data set of two million users. A small payment institution and a bank with hundreds of branches use the same platform; only the resources behind it differ.

Your own policies live inside the system

You load your compliance policies and your sector knowledge into TruvaLI, and the rules and the AI work with those in front of them.

You pay for what you use

The size of your team does not change the bill; what you pay follows the volume of transactions and customer onboardings, and only the ones that succeed are billed. The unit price falls as the volume grows.

Changing a rule does not wait for a release

Low-code configuration: a new rule or a new report does not have to join the development queue.

Built for heavily regulated sectors

What these sectors have in common is not only that they are supervised: in all of them customers are taken on remotely, transaction volume is far past what a human eye can follow, and the cost of a compliance failure does not stop at a fine. TruvaLI was built for the places where all three hold at once.

  • Banking and financial services
  • Fintechs and payment institutions
  • Insurance companies
  • Gaming and betting
  • Crypto and digital assets
  • E-commerce and marketplaces
  • Lending and other financial services

Start in shadow mode

  • Beside the system you run today, on the same data TruvaLI takes your production data in parallel with the system you use today and reaches its own decisions. On the same day, over the same transactions, you see side by side what each of them produced; which alert was noise and which risk went unseen becomes a measurement rather than a guess.
  • Rules run in simulation A rule in simulation raises its alert without opening a case, and prepares its callback without firing it. Your compliance team's workload is untouched by the trial, and not a single call reaches downstream systems such as core banking or messaging. You calibrate the thresholds against your own live traffic and settle the rule set before anything goes live.
  • You set the switchover date The go-live is planned once the simulation output has been reviewed and the rule set signed off. The decision follows what you have seen the platform do with your own data rather than a vendor's calendar, and shadow mode lasts as long as you need it to.

Going live, step by step

  1. Setting up the data feeds The points that will flow from your own platforms into TruvaLI are identified and the feeds are brought up. Which event arrives from which system, how often and with which fields is settled at this stage.
  2. Completeness and rate of growth Incoming data is put through integrity tests: missing fields, broken relations and lagging feeds surface here. The rate of growth is measured at the same time, so capacity planning rests on measurement rather than estimate.
  3. Writing events and rules Event definitions and rules are written against the data now flowing. They do not go straight into production; they run in simulation and the alerts they raise are judged against your real traffic.
  4. Loading policy and sector knowledge Your institution's compliance policies and the knowledge records for your sector are defined in the system. From then on the rules and the AI work with your policy in front of them rather than a generic template.
  5. Training, then the planned switch The teams are trained on the system, the simulation output is reviewed together and the rule set is signed off. The go-live schedule follows.
How long it takes depends on the size of the institution and the team it puts on the work. It starts at four weeks.
Pricing

Straight answers first. The number comes after.

Every installation differs in volume, in the steps you switch on and in where the software runs. What should not be a secret is how the offer is put together, and that is exactly what follows.

What moves your quote

  • Monthly volume of monitored events
  • Which steps and modules you switch on
  • Number of legal entities and jurisdictions you operate in
  • Cloud, private cloud or on-premise
  • Support tier and response time
  • Historical data and rule migration

Included at every tier

  • No-code rule engine, and a rule library drawn from the regulators' own guidance
  • Alerts, case management and investigation surface
  • Immutable audit trail and decision logging
  • Unlimited users, no per-seat charge
  • Platform updates and regulatory changes
  • Sanctions and watchlist data refresh
  • The lists and the know-how we prepare for your sector
01

What are we actually billed for?

A monthly platform fee, and beyond that what you use. In onboarding you pay only for the steps you switch on; in monitoring you pay per transaction, and only the ones that succeed are billed, so a failed attempt costs you nothing. The number of users is not a criterion: add every analyst, auditor and engineer you need.

02

How is implementation priced?

Implementation is a one-off line, set by its scope: a clean API connection is light, carrying years of history, rules and open cases is not. You see what it comes to before you sign, as a single line in the offer, and nothing about it surprises you on an invoice. The POC and the shadow-mode period sit inside that line.

03

Do we pay maintenance on top?

There is no separate maintenance invoice. Platform updates, new detection typologies, additions to the rule library and the changes we make to keep up with regulation are part of the subscription.

04

Does on-premise cost extra?

There is no penalty for keeping data in your own estate: the licence model changes, not the price philosophy. You supply the infrastructure and we licence the platform to run inside it. At high volume, on-premise usually works out cheaper, not dearer.

05

If our volume grows, does the unit price grow too?

The other way round. In transaction monitoring the unit price is banded, and it comes down markedly as the volume grows. Growing does not cost you extra.

06

What happens if we go past our limit?

Usage is quoted by the month, and because the agreement runs for a year at least, what you hold is twelve times that monthly figure. Go past it and nothing stops: the platform does not halt and no limit is enforced. The next agreement is renewed against what you actually used.

A quote takes one call, not a procurement cycle

Tell us your monthly volumes and where the software has to run. You get a written proposal with the subscription, the one-off implementation figure and the assumptions behind both, so your finance team can check the arithmetic rather than trust it.

Get a quote
Newsroom

Let's explore risk, compliance and technology together.


We share product updates, regulatory insight and industry analysis on our blog. Follow it all from our site or our LinkedIn page.

Follow on LinkedIn