SpeciCRED Co-pilot Suite logo
Agents Orchestration Frameworks · Financial Analysis

SpeciCRED Co-pilot Suite

A suite of seven agentic AI co-pilots for credit risk in private banking, built by the SpeciTec AI Lab in Geneva. It runs inside the bank's own environment, feeds on SpeciCRED data and keeps a human in the loop.

Active GDPR compliant Contact Sales No public API 13+ Verified by Guidaio
Overview

What is SpeciCRED Co-pilot Suite?

The SpeciCRED Co-pilot Suite is a set of seven production AI agents built by the SpeciTec AI Lab for credit work inside private banks. It is agentic rather than conversational: SpeciTec describes co-pilots that take action under supervision instead of yet another chatbot, and the agents draw on the data already held in the SpeciCRED Lombard credit platform. Each agent carries a published success rate and average latency, both of them the vendor's own figures rather than audited results.

The Credit File Analyst runs a health check on a credit file, covering required documents, portfolio composition, client history, risk scoring and context analysis, and returns an indicative approval trend for the credit committee; SpeciTec reports 96.4% success at an average of 38 seconds. The Breach Analyst takes each breach through a liquidity analysis and recommends a margin call, a capital injection, a portfolio reallocation, acceptance of the risk or legal escalation, with the supporting documentation, always human-in-the-loop; the vendor reports 94.2% at 28 seconds. The Market Risk Analyst structures stress-test scenarios from each client's real data, ready to activate in SpeciCRED (97.1%, 90 seconds). The Termsheets Analyst reads a termsheet against credit policy, the observation period and the existing book, then issues a reasoned lend or decline suggestion with an amount (95.8%, 22 seconds). The Credit Ops Co-pilot handles simple, non-strategic files in bulk, meaning facilities under CHF 2M, Pool 4 clients and retail-like profiles, writing commentary and pre-filling documents (92.3%, 6 seconds). The Reports & Dashboard Generator produces SSRS reports and dashboards on demand (99.4%, 18 seconds), and the Derivatives Strategist analyses both legs of Accu/Deco, TARF and Strangle structures to suggest increasing or reducing exposure (93.5%, 14 seconds). Across the suite SpeciTec claims a 95.7% follow-through rate, a 65% cut in credit committee preparation time and full audit trail coverage, figures the site itself labels indicative.

All seven are configured, monitored and audited from a single AI Agents Control Center, with live updates, an exportable audit log, granular role-based access control and a pending-review queue. Integration to core systems runs through Model Context Protocol servers, and deployment can be public cloud, private cloud, on-premise or fully air-gapped. What it is not: it is neither the underlying SpeciCRED credit platform nor the sister SpeciVIM Co-pilot Suite of eight KYC and AML compliance agents.

What it does

  • Run a health check on a credit file and return an indicative approval trend for the credit committee
  • Analyse a breach, work it through a liquidity review and recommend the action: margin call, capital injection, portfolio reallocation, risk acceptance or legal escalation
  • Read a termsheet against credit policy, the observation period and the existing book, then suggest whether to lend and how much
  • Structure stress-test scenarios from each client's real data, ready to activate in SpeciCRED
  • Process simple, non-strategic credit files at volume, write the commentary and pre-fill the supporting documents
  • Generate SSRS reports and dashboards on demand from existing data
  • Analyse both legs of Accu/Deco, TARF and Strangle option structures and suggest increasing or reducing exposure
Audience

When to use SpeciCRED Co-pilot Suite / When not to

A quick filter to help you decide if SpeciCRED Co-pilot Suite is the right fit.

When to use SpeciCRED Co-pilot Suite

  • Private banks and wealth managers, from tier-1 institutions down to boutique houses
  • Institutions already running the SpeciCRED platform, where the agents plug into the existing data model with no migration phase
  • Banks under strong sovereignty constraints, such as FINMA in Switzerland, MAS in Singapore, MFSA in Malta, BaFin in Germany or the FCA in the United Kingdom
  • Organisations that require an on-premise or air-gapped deployment, with no data leaving their own perimeter
  • Credit teams that want to industrialise credit committee preparation and the handling of breaches

When not to use SpeciCRED Co-pilot Suite

  • Anyone outside private banking and wealth management: the AI Lab declares an exclusive focus on that sector
  • Buyers who want a published price or a self-service purchase, since every engagement is quoted privately after a workshop
  • Small organisations, because the entry tier is a contracted 90-day pilot with an embedded consultant
  • Teams whose need is KYC, AML or sanctions compliance, which is covered by the sister SpeciVIM Co-pilot Suite rather than this one
  • Individuals: nothing in the offer is aimed at a single private user
Get started

How to use SpeciCRED Co-pilot Suite

A typical end-to-end flow, from setup to results.

  1. Start with the online scoping calculator: pick the agents, the assets under management band, the number of front-office users, the deployment posture, the applicable regulators, whether SpeciCRED is already in production and your target go-live date; it returns a recommended tier, not a price
  2. Request a discovery workshop through the contact form, selecting the SpeciCRED suite as the subject
  3. Discovery: a Talent consultant runs a scoping workshop with your business owners to choose the co-pilot, the data to connect and the success metrics
  4. Pilot: the co-pilot is deployed on-premise inside your own environment and connected to your systems through Model Context Protocol servers
  5. Expect a working co-pilot within six to ten weeks, running under human-in-the-loop validation
  6. Operate the agents from the AI Agents Control Center: configure them, monitor them and clear the pending-review queue
  7. Read the confidence score and the source reasoning attached to every suggestion before approving it, since nothing is passed to downstream systems without an explicit human validation
  8. Scale: extend the suite to other departments, add co-pilots and hand the runtime over to your own IT team under long-term governance
  9. Run: quarterly model and prompt reviews, regulatory watch and an ongoing FINMA evidence pack, with an embedded Talent engagement manager
  10. Export the immutable audit log to your SIEM whenever internal audit or a regulator asks for evidence
Quick read

Pros & Cons

Pros

  • A native on-premise and air-gapped posture: SpeciTec states that customer banking data never transits its own infrastructure
  • An audit trail on every prompt, retrieval and action, built for FINMA scrutiny and internal audit
  • ISO/IEC 27001:2022 certified by SGS under reference CH24/00000088 and valid until 07/10/2027, a claim that can actually be checked
  • Each of the seven agents is documented individually, with its triggers, its actions and the metrics the vendor publishes for it
  • BYOLLM and customer-held encryption keys, so both the model and key custody stay with the bank
  • A declared focus on private banking and wealth management rather than a generalist AI consultancy
  • Attaches to an existing SpeciCRED data model with no migration phase

Cons

  • No public pricing whatsoever: all three tiers read "On request" and a quotation only follows a private discovery workshop
  • No terms and conditions are published anywhere on the site, so the contractual framework cannot be read before negotiation
  • No public API documentation, even though the architecture is presented as API-first
  • No customer is named: the three case studies are anonymised and named references are reserved for parties under NDA
  • The agent performance figures are vendor claims that the site itself labels indicative, and none of them can be checked from outside
  • Strong dependence on the SpeciTec ecosystem, since the full value assumes SpeciCRED is already in production
  • No free plan and no free trial: the entry point is a contracted 90-day pilot
Pricing

Pricing & Plans

There is no free plan and no free trial, and no price is published. The three tiers, Pilot, Scale and Enterprise, are all shown as "On request". SpeciTec states that pricing is structured around scope, deployment posture and SLA, and is quoted privately by its Talent team after a discovery workshop; the tiers are denominated in Swiss francs or euros and include the relevant FINMA evidence pack. The billing shape differs by tier: a one-off plus a success fee for the 90-day Pilot, an annual contract for Scale, and a multi-year subscription under a master agreement for Enterprise. A comparative return on investment model is shared under NDA after a discovery call. The online scoping calculator returns a recommended tier only, never a figure. Prospective buyers should therefore plan on the basis of a private quotation rather than a list price.

Pilot, positioned as "Validate value in one workflow"
  • a 90-day pilot agreement
  • priced on request
  • billed as a one-off plus a success fee. It covers one co-pilot on one workflow and up to 25 active users
  • a connection to SpeciCRED
  • SpeciVIM or Mobile Banking
  • a hosted LLM with on-premise inference
  • an embedded Talent consultant for the duration of the pilot and best-effort support in business hours. Core banking connectors are not included at this tier.
Enterprise, positioned as "A bank-wide co-pilot platform"
  • a multi-year master agreement
  • priced on request and billed as a multi-year subscription. It covers unlimited co-pilots
  • users and internal systems
  • a fully on-premise air-gapped deployment
  • BYOLLM with customer-hosted models
  • a co-pilot factory letting the bank build its own agents under SpeciTec governance
  • a dedicated AI Lab squad with a named Talent Partner
  • a 99.95% SLA around the clock with a dedicated technical account manager
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how SpeciCRED Co-pilot Suite handles your data.

GDPR overview

GDPR is addressed explicitly. The privacy policy, last updated on 25 March 2025, is written against both the Swiss FADP and the European GDPR, and lists rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. A single address, dpo@specitec.com, handles those requests. International transfers are said to rest on standard contractual clauses where required. The Trust Center answers its own question, "Are you GDPR / nFADP compliant?", with a yes, and an Article 28 data processing agreement is available on request. Two gaps are worth noting: no Article 27 EU representative is designated anywhere on the site, and the legal notice carries neither a company identification number nor a named officer. SpeciTec also argues that in most deployments it is not a processor of your banking data, because it does not host it.

Who owns the data?

SpeciTec states that it does not host customer banking data: the platform is deployed in the bank's own tenant, on-premise or in the cloud the bank operates, and the vendor publishes the claim that customer banking data never transits its infrastructure. It says it runs no region, no managed cloud tenant and no shared database, and that it holds no path to the encryption keys, which stay in the customer's custody through CMK or BYOK. The audit trail the agents produce belongs to the bank, and when a contract ends the customer's team keeps control of the runtime. One caveat: the published privacy policy governs the website, not the deployed product, whose terms sit in the Article 28 DPA supplied on request.

Reuse rights

No terms and conditions are published, so no reuse licence can be quoted, and what the site documents splits in two. On the website, SpeciTec collects an email address, first and last name, telephone number, postal address and usage data such as IP address, browser, pages visited, timestamps and device identifiers. It states it uses them to provide and maintain the service, manage accounts, perform contracts, contact you by email, telephone or SMS, send similar offers unless you object, handle your requests, support a business transfer and run analytics to improve the service; cookies are limited to essential session, notice-acceptance and functionality categories. On the product side the picture is different: the data stays inside your tenant, every prompt, retrieval and action is written to an audit trail you own and can export to your SIEM, and the vendor says it has no standing access to production data, with any support intervention opt-in, time-boxed, logged on your own identity provider and framed by a written DPA. SpeciTec adds that in most deployments it is not a processor of your banking data, because it does not host it.

Data retention & training

Retention summary
Two regimes apply and the site only documents one of them. For the website, the privacy policy states that, absent a legal obligation, your data will be deleted after a period of one year, and that usage data is kept for shorter periods for internal analysis except where it serves security or service improvement. For the product, no retention period is published at all, which is consistent with the architecture: the audit trail is produced by the platform but stored, rotated and deleted by the bank on its own infrastructure, so retention is a customer policy rather than a vendor one. Anything firmer, including deletion commitments written into the Article 28 DPA, has to be requested directly.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

SpeciTec operates no hosting region of its own: the suite runs inside the customer's environment. Five topologies are supported, namely on-premise in the bank's own datacentre, hardware and network; a customer-managed Azure tenant in the region of its choice; a customer-managed AWS tenant on the same basis; a fully air-gapped network with no internet egress; and hybrid combinations. On-premise is presented as the default for tier-1 banks under FINMA, MAS or DFSA sovereignty constraints, Azure as the most common pattern in Switzerland, Luxembourg and the EU, and AWS as the frequent choice across APAC and the Americas. Data residency is therefore a customer decision, with deployments in Switzerland, the EU or the jurisdiction the bank chooses. One caveat on attribution: the supplier table published in the Trust Center, listing Microsoft 365, a self-hosted Azure DevOps Server, Atlassian, OpenAI ChatGPT Enterprise, Anthropic Claude Enterprise, Vercel Enterprise and VTX Telecom, covers SpeciTec's own internal operations, not the runtime that processes your banking data. The public website itself resolves to a Swiss address on AS12350, VTX Services SA in Fribourg.

Hosting countries
🇨🇭 Switzerland
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting SpeciCRED Co-pilot Suite.

  • Every agent performance figure is a vendor claim: the site presents them as indicative results observed across SpeciTec's own pilot programmes, and none has been independently audited
  • Delegating credit file triage and breach recommendations to an agent can quietly erode the judgement of junior analysts, who may stop rebuilding the reasoning themselves; the confidence score shown on each suggestion is a comfort signal, not a proof
  • ISO/IEC 42001:2023 and SOC 2 Type II are announced as in progress rather than obtained, and FINMA 2018/3, CSSF 22/806, MAS TRMG and PCI DSS are declared alignments, not certifications; reading them as certifications would misstate the vendor's actual posture
  • The published privacy policy governs the website, not the product deployed inside the bank, so any GDPR analysis of the product itself runs through the Article 28 DPA, which is only available on request
  • The vendor's showcase numbers and its client evidence cannot be corroborated: no customer is named, the case studies are anonymised, named references are reserved for parties under NDA, and no contractual terms are published for review before negotiation
  • The site contradicts itself on the publisher's own history, showing two different seniority claims on the same page alongside two different founding years across its markup and its prose, so the corporate track record should be treated as unconfirmed
  • Two due-diligence loose ends: the vendor's supplier table credits Vercel Enterprise with delivering its website while the domain resolves to a Swiss VTX address behind Microsoft IIS, and the demo subdomain is behind an authentication wall, so nothing can be tried without going through sales
Setup

Setup & Integrations

Technical difficulty

Moderate, and vendor-led rather than self-service. There is no sign-up: a scoping workshop precedes deployment, and SpeciTec announces a working co-pilot within six to ten weeks for a pilot. Reference Kubernetes manifests and Terraform modules ship with hardened defaults, alongside hardening guides for Azure, AWS and on-premise, plus SSO federation through SAML 2.0, OIDC or SCIM 2.0. You need an operations team, because the bank owns the runtime, log retention and incident response. Where SpeciCRED is already live, the agents attach to the existing data model with no migration phase.

Deployment

Web appAPI

Integrations

Avaloq OLYMPIC Temenos FNZ Finnova Azure OpenAI AWS Bedrock AWS KMS Azure Key Vault

Supported languages

EnglishFrenchGermanItalianChinese (Simplified)Chinese (Traditional)
Company

Behind SpeciCRED Co-pilot Suite

Company name
SpeciTec SA
Founded
INFORMATION_NOT_FOUND
Country of origin
🇨🇭 Switzerland
Headquarters
Place de Pont-Rouge 1, 1212 Grand-Lancy, Geneva, Switzerland
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇫🇷 France
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly is the SpeciCRED Co-pilot Suite?
It is a set of seven production agents built by the SpeciTec AI Lab for credit work in private banking: a Credit File Analyst, a Breach Analyst, a Market Risk Analyst, a Termsheets Analyst, a Credit Ops Co-pilot, a Reports & Dashboard Generator and a Derivatives Strategist. They are agentic rather than conversational, they act under supervision, and they are configured, monitored and audited from a single AI Agents Control Center.
What does agentic AI mean in a banking context?
SpeciTec defines it as goal-driven autonomous systems that plan, reason and execute multi-step workflows with minimal human intervention. Inside a bank that means co-pilots automating compliance reviews, credit analysis, onboarding and operational tasks alongside the experts who validate the output, rather than a chatbot answering questions.
Can the agents run on-premise?
Yes. The reference architecture supports full on-premise, private cloud and air-gapped deployments. Inference runs inside your own environment and SpeciTec states that no customer data leaves your perimeter. You can also bring your own large language model, hosted on Azure OpenAI, AWS Bedrock or self-hosted open weights.
How do the agents connect to our existing systems?
Through Model Context Protocol servers, an open standard. The same protocol is used for SpeciCRED, SpeciVIM and the Avaloq, OLYMPIC, Temenos, FNZ and Finnova cores. Role-based access control is applied so that a co-pilot only sees what the requesting user is entitled to see.
Where is our data stored, and can SpeciTec see it?
On infrastructure your institution operates. SpeciTec says it does not host customer banking data and that the platform is deployed in your tenant. It reports no standing access to production data: any support intervention is opt-in, time-boxed, logged on your own identity provider and governed by a written data processing agreement.
How are AI governance and compliance handled?
A model risk management pack covers validation, drift monitoring, rollback procedures and human-in-the-loop policies, and every prompt, retrieval and action is logged with a full audit trail. SpeciTec says the framework is designed to align with FINMA, EBA, MAS and local frameworks, and that it is reviewed by the second line of defence.
Which certifications does SpeciTec actually hold?
One: ISO/IEC 27001:2022, certified by SGS under reference CH24/00000088 and valid until 07/10/2027. ISO/IEC 42001:2023 and SOC 2 Type II are listed as in progress rather than obtained. FINMA 2018/3, CSSF 22/806, MAS TRMG and PCI DSS are described as alignments the vendor claims, not as certifications it holds.
Is there a published price, a free plan or a trial?
None of the three. The Pilot, Scale and Enterprise tiers are all shown as "On request", and SpeciTec quotes privately after a discovery workshop. There is no free plan and no free trial; the way in is a contracted 90-day pilot.
How is success measured once the agents are live?
Each agent is instrumented from day one with business KPIs such as cycle time, reviews per relationship manager and false positive rate, plus quality KPIs such as groundedness and escalation rate. SpeciTec says these are reviewed quarterly.
What happens when the contract ends?
Your data has stayed inside your own environment throughout, so at termination your team keeps control of the runtime. SpeciTec says it provides migration tooling, documentation and handover support. Before signing, it also offers an audit under NDA covering its ISO 27001 certificate and statement of applicability, penetration test summaries, secure deployment guides, continuity plans and architecture diagrams, with written audits and on-site visits accepted on reasonable notice.
Conclusion

Should you pick SpeciCRED Co-pilot Suite?

The SpeciCRED Co-pilot Suite is a narrow, vertical product, and that is precisely its argument. Seven credit agents covering file analysis, breach handling, stress-test scenarios, termsheets, bulk credit operations, reporting and derivatives strategy are aimed squarely at private banks and wealth managers, not at anyone shopping for a general-purpose assistant. Its structural strength is architectural: the platform runs inside the bank's own tenant, on-premise or air-gapped where needed, with customer-held keys, an audit trail on every prompt and action, and an ISO/IEC 27001:2022 certificate from SGS that a buyer can actually verify. That is the only certification SpeciTec holds today: ISO/IEC 42001:2023 and SOC 2 Type II are still in progress, and the FINMA, CSSF, MAS and PCI DSS references are declared alignments rather than certifications. Its structural weakness is commercial opacity, and it is complete: no published price, no terms and conditions, no named customer, and no public API documentation despite an API-first pitch. Every performance figure, from the 95.7% follow-through rate to the per-agent success rates and latencies, is the vendor's own and is presented by the site itself as indicative. The suite makes most sense for an institution already running SpeciCRED, where the agents attach to an existing data model with no migration phase; for everyone else this is a heavy contractual engagement that begins with a discovery workshop and a paid 90-day pilot rather than a sign-up form. Maturity looks credible, with agents described as in production and a long-established Geneva publisher that is visibly active. Treat the metrics as claims to be tested during the pilot, and the evidence pack as the thing worth negotiating for.