Resistant AI logo
Security Fraud · Content Authenticity Detection

Resistant AI

Resistant AI checks any PDF or image for forgery, reuse and AI generation in under twenty seconds, and layers more than 80 fraud and money-laundering models over an existing transaction monitoring system. Built for banks, lenders, insurers and marketplaces.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Resistant AI?

Resistant AI is a financial-crime detection layer aimed at the teams who decide whether to approve a customer, a loan, a claim or a payment. It is sold as three products.

Resistant Documents inspects any PDF or image entering a workflow, runs more than 500 fraud and authenticity checks on it, and returns a verdict in under twenty seconds. It is deliberately document- and language-agnostic: the models examine how a file was built rather than reading what it says. The vendor presents this as both a coverage argument, since a document from any country can be checked, and a privacy argument, since the customer's text is never the subject of the analysis. Three fraud families are called out by name: ordinary tampering left behind by online editors, documents that have been reused or purchased as ready-made templates, and files produced by generative image models. The vendor says its models were trained on more than 200 million documents and claims three times more fraud detected, over 90% fewer manual reviews and 99.2% decision accuracy.

Resistant Transactions is an overlay rather than a replacement. More than 80 off-the-shelf models, built by AI scientists and financial-crime specialists, sit on top of an existing rules-based monitoring system, respond in under 100 milliseconds and target AML, authorised push payment fraud and buy-now-pay-later risk. Defence in Depth joins the two together and adds behavioural signals and device fingerprints, which the vendor credits with 60% more detections than its own products used separately, and 20% fewer false positives.

The four-stage pipeline explains the speed claims: a readability check in under three seconds, a document classification in under four, a trust verdict in under twenty, then a decision step that applies the customer's own risk policy. What comes back is a plain verdict with indicator-level evidence and a downloadable PDF report rather than an opaque percentage, and Adaptive Decision lets a team tune those verdicts to its appetite.

Two delivery routes exist: a drag-and-drop web interface that needs no development work, and a REST API with OAuth2 authentication, presigned uploads and results by polling, Amazon SQS or webhook. There is no self-service signup and no published price.

What it does

  • Check any PDF or image for forgery and authenticity and return a Trusted, Warning or High Risk verdict
  • Surface tampering left by online editors that is invisible to the naked eye, including attempts to hide the edits
  • Detect reused documents and ready-made fraud templates by cross-referencing every file against all the others
  • Flag AI-generated documents by reading textures and structural patterns left by image models
  • Classify the document and verify its metadata as part of the same pass
  • Overlay an existing transaction monitoring system with more than 80 AML and fraud models
  • Correlate documents, transactions, behaviours and device fingerprints into a single risk picture
Audience

When to use Resistant AI / When not to

A quick filter to help you decide if Resistant AI is the right fit.

When to use Resistant AI

  • Fraud and financial-crime teams at banks, neobanks and payment providers handling merchant or customer onboarding at volume
  • Credit and mortgage underwriters who approve loans on the strength of bank statements, payslips and income documents
  • Insurance claims handlers and loss adjusters trying to keep fabricated or duplicated claims out of the payout queue
  • AML and compliance analysts who want more risk coverage without ripping out the rules-based monitoring system they already run
  • Marketplace, property and tenant-screening operators verifying seller or applicant paperwork before granting access

When not to use Resistant AI

  • Individuals or small teams wanting to check a document occasionally: there is no self-service signup, no free plan and no published price
  • Buyers who need to compare costs before talking to anyone, since every route ends at a demo request or a private AWS Marketplace offer
  • Anyone needing scanned formats beyond images and born-digital PDFs, or a mobile app or browser extension, none of which exist
  • Teams expecting the tool to read and understand a document's contents: it analyses how the file was built, not what it says
  • Organisations whose procurement requires published terms of service, a legal notice or a public subprocessor list before evaluation
Get started

How to use Resistant AI

A typical end-to-end flow, from setup to results.

  1. Make contact through the Book a demo form, or request a private offer through AWS Marketplace: there is no self-service signup
  2. Have the vendor provision a tenant, which gives you a tenant subdomain and one or more regional cells
  3. If your network filters outbound traffic, allowlist the domains for your cell: the API, the Okta token host, the S3 endpoints and the web interface
  4. Start immediately without writing code by dragging documents into the web interface
  5. For automation, obtain an OAuth2 access token from the European Okta host and reuse it rather than requesting one per call
  6. Create a submission with POST /v2/submission, then upload the file to the presigned S3 URL you get back
  7. Collect results by polling with exponential backoff, by consuming an Amazon SQS queue, or by receiving a webhook
  8. Review the detail in the web interface or the offline iFrame viewer, and download the PDF report where evidence has to be filed
  9. Configure Adaptive Decision so verdicts match your own approval, rejection and escalation policy
  10. Delete a submission ahead of its retention deadline with DELETE /v2/submission/{submission_id} when you need earlier removal
Quick read

Pros & Cons

Pros

  • Public, genuinely complete API documentation covering authentication, quotas, formats, regions and webhooks, which is rare for a B2B financial-crime vendor
  • Five hosting cells named individually, so data residency can be discussed with facts rather than assurances
  • A stated default retention period of 90 days and a customer-side deletion endpoint, both published rather than promised
  • Explainability is the design choice, not a feature: a readable verdict with evidence instead of a risk percentage
  • Adds to the existing stack rather than replacing it, which is the repeated argument on the transactions side
  • Purchasable through AWS Marketplace and billed to the AWS account, which shortens legal review
  • Named, checkable customer references and published case studies, behind a European vendor with more than 100 staff and identified investors

Cons

  • No public pricing of any kind: no pricing page, no figure, no tier, and the only routes in are a demo request or a private offer
  • No terms and conditions and no legal notice anywhere on the site; the company's legal identity is only findable inside the privacy policy
  • The privacy policy covers the marketing website alone, not the customer data the product processes, and carries no effective date
  • No subprocessor list is published, and the trust centre is a JavaScript application whose contents cannot be read without access
  • A SOC 2 badge sits in the footer of every page with no certification page a visitor can actually open
  • Nothing is published about whether customer documents are used to train the models, and no opt-out mechanism is documented
  • The Meet the Resistants section of the About page was still showing template placeholder content at the time of review
  • Input formats are limited to images and born-digital PDFs, and there is no mobile app or browser extension
Pricing

Pricing & Plans

No price is published. The site carries no pricing page, no rate card and no figure of any kind, and neither a permanent free plan nor a free trial is announced. Pricing is obtained by requesting a demo or, on AWS Marketplace, by asking for a private offer, in which case Amazon Web Services handles billing and the charges appear on the buyer's AWS bill. The technical documentation confirms that commercial terms are individually negotiated, noting that certain limits vary by contract, tenant configuration and deployment cell.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Resistant AI handles your data.

GDPR overview

The vendor is established in the EU, in Prague, so no Article 27 representative applies or is named. Its privacy policy is written directly against the GDPR across nine sections, stating that the company proceeds in accordance with Regulation (EU) 2016/679. It sets out lawful bases, data minimisation and the full set of data-subject rights: access, rectification, erasure, restriction, portability, objection and freedom from automated decisions, with a one-month response deadline. The Czech supervisory authority is named explicitly. Transfers outside the EU and EEA to relay server and IT operators are acknowledged, with "adequate measures" claimed but not detailed. Two gaps matter: the policy carries no effective or last-updated date, and it covers only the marketing website, not the customer data processed by the product.

Who owns the data?

The site does not publish any terms and conditions, so the contractual question of who owns submitted documents is simply not answered in public. The only legal text available is a privacy policy, and it is narrow: it governs personal data collected through the resistant.ai website itself, naming Resistant AI s.r.o. as controller for that data. It says nothing about the documents and transaction records customers push through the product. What is documented sits in the API reference instead: the customer can delete a submission at any point with a DELETE call, which implies practical control but is not an ownership clause. Buyers purchasing through AWS Marketplace are told the vendor aligns with AWS Marketplace terms. Ownership therefore has to be settled contractually, before signature.

Reuse rights

Because no terms and conditions are published, there is no public rule stating what a customer may or may not do with what the tool returns. In practice the product is built to hand results back for reuse: each submission yields a verdict, indicator-level explanations, metadata checks, a document classification and a downloadable PDF report, and these can be pulled by polling, pushed to an Amazon SQS queue or delivered by webhook, then displayed in the web interface or in an offline iFrame viewer. Customers can also delete a submission before its retention period expires. On the website side, the privacy policy grants the standard GDPR rights, including portability in a structured, machine-readable format. The absence of published terms remains the main limitation here: reuse is technically supported but contractually undocumented.

Data retention & training

Retention summary
For the product, retention depends on the contract, with a documented default of 90 days. Customers who need a document removed sooner can call DELETE /v2/submission/{submission_id} themselves rather than raising a request. For the marketing website, the privacy policy says personal data is kept only as long as the purpose requires or the law prescribes, and is erased when consent is withdrawn. Server log files are deleted as soon as their purpose ends, except where they are needed as evidence until a case closes. Visitors' IP addresses are deleted or anonymised after the visit unless a legal obligation or a claim requires otherwise. Session cookies disappear when the browser closes; persistent cookies last according to the browser's own settings.
GDPR contact

Hosting summary

The product runs on AWS in regional cells that the integration documentation lists explicitly: eu-1 in Dublin on eu-west-1, us-1 in West Virginia on us-east-1, ca-1 in Montreal on ca-central-1, ap-2 in Mumbai on ap-south-1 and ap-3 in Sydney on ap-southeast-2. A tenant may be provisioned in only a subset of these, and the testing environment exists in eu-west-1 only. Files are uploaded and downloaded through presigned S3 URLs in the cell's own region, with a custom-domains add-on available to avoid allowlisting S3 directly. One element stays European regardless of cell: OAuth2 authentication goes through an Okta host in the EU. The marketing website is separate, sitting behind an anycast CDN, and its privacy policy acknowledges that personal data may be transferred to relay server and IT operators outside the EU and EEA under measures it calls adequate but does not describe. The vendor itself is established in the Czech Republic.

Hosting countries
🇮🇪 Ireland🇺🇸 United States🇨🇦 Canada🇮🇳 India🇦🇺 Australia
Hosting regions
EUNorth AmericaAPAC
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Resistant AI.

  • This is a tool that makes decisions about people: a High Risk verdict can mean a refused loan, a blocked account or a rejected insurance claim
  • The vendor claims 99.2% accuracy and explicitly refuses to promise 100%, which is honest but means false positives land on legitimate customers
  • Cutting manual reviews by over 90% is the selling point and the risk: far fewer human eyes remain to catch the machine's mistakes
  • Because the analysis is structural, a genuine document that was re-scanned, re-encoded or compressed may look suspicious; the documentation itself warns to preserve original file bytes
  • Nothing is published about whether submitted documents train the models, while the vendor advertises training on more than 200 million documents without saying where they came from
  • Submitted files are exactly the sensitive material fraudsters want: bank statements, payslips and identity documents, held by a third party with transfers outside the EU acknowledged
  • With no public terms, liability for a missed forgery cannot be assessed before entering a commercial conversation
Setup

Setup & Integrations

Technical difficulty

Two very different levels. Using the drag-and-drop web interface requires no development work at all. A full API integration is a normal engineering task: OAuth2 tokens through Okta, POST to create a submission, presigned S3 upload, then results by polling, Amazon SQS or webhook, with mandatory handling of HTTP 429 using exponential backoff and jitter. Default quotas are four submission requests per second. Networks that filter outbound traffic need allowlisting first. Neither route is self-service: the vendor provisions the tenant. On the transactions side, deployment is advertised as taking days rather than months, one risk typology at a time.

Deployment

Web appAPI

Integrations

Experian ABBYY Vantage Tungsten Automation ComplyAdvantage Lucinity AWS Marketplace Amazon SQS Amazon S3 Okta Svix
Company

Behind Resistant AI

Company name
Resistant AI s.r.o.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇨🇿 Czechia
Headquarters
Lazarská 8, 120 00 Nové Město, Czech Republic
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

Seed round of USD 2.75 million led by Index Ventures and Credo Ventures, described as the company's first tranche of external funding after the founders bootstrapped it
Series A of USD 16.6 million
Series A extended to USD 27.6 million, announced on 27 June 2023, with an additional USD 11 million from Notion Capital alongside existing investors GV, Index Ventures, Credo Ventures and Seedcamp
Series B of USD 25 million announced on 13 October 2025, led by DTCP Growth with Experian, GV and Notion Capital participating; the company said it had reached breakeven in September
Experian holds a strategic investment in the company, made alongside a commercial partnership

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly does Resistant AI check?
Any PDF or image submitted into a workflow. Each document goes through more than 500 fraud and authenticity checks and comes back with a verdict in under twenty seconds, together with the evidence behind it.
Do I have to replace my existing transaction monitoring system?
No. Resistant Transactions is designed as an overlay: more than 80 off-the-shelf models sit on top of the rules-based system you already run, responding in under 100 milliseconds, so no rip-and-replace project is required.
Can it detect documents generated by AI?
Yes. Generative AI fraud is one of the three fraud families the vendor names, alongside ordinary tampering and reused or template-farmed documents. Detection works from visual textures and structural patterns rather than from the text.
Does the tool read the contents of my documents?
No, and the vendor makes a point of it. The models analyse how a document was built rather than what it says, which is presented as both a coverage argument and a privacy argument for the end customer.
Which file formats are supported?
Images in JPG, JPEG, PNG, TIF, TIFF, BMP, GIF, JFIF, AVIF, HEIC, HEIF and ICO, plus born-digital PDFs. Anything outside that list is not covered by the published format documentation.
How long are submitted documents kept?
Retention depends on the contract, with 90 days as the documented default. A customer can remove a document earlier by calling DELETE /v2/submission/{submission_id} on the API.
Where is the data hosted?
Across five AWS cells that the integration documentation names individually: Dublin for the EU, West Virginia for the US, Montreal for Canada, Mumbai and Sydney for Asia-Pacific. A tenant may be provisioned in only some of them, and the testing environment is EU-only.
Is there an API?
Yes, with public documentation. Authentication uses OAuth2 through an Okta host, submissions are uploaded to presigned S3 URLs, and results arrive by polling, Amazon SQS or Svix webhooks. Default quotas are four submission requests per second.
How much does it cost?
No amount is published anywhere on the site. You either book a demo or request a private offer through AWS Marketplace, and no free plan or free trial is advertised.
How do I reach support?
General product, API and integration questions go to support@resistant.ai, security incidents to security@resistant.ai, and urgent production issues can be raised by phone on +1-332-334-7066.
Conclusion

Should you pick Resistant AI?

Resistant AI is a serious, well-engineered product with an unusually candid technical face and an unusually closed commercial one. The engineering side earns trust: the API documentation is public and complete, the five AWS hosting cells are named individually, the default retention period is stated as 90 days rather than described vaguely, and customers get a deletion endpoint. The core design decision is also the most defensible one. By analysing how a document was assembled instead of reading it, the tool sidesteps language and format coverage problems and keeps the customer's text out of the analysis, and it returns a readable verdict with evidence rather than a percentage nobody can act on.

The reservations are about what is not published. There are no terms and conditions and no legal notice; the company's own legal identity has to be dug out of a privacy policy that covers only the marketing website and carries no effective date. A SOC 2 badge sits in the footer with no page behind it, the trust centre will not open without access, and no subprocessor list exists in public. Most pointedly for a vendor whose models were trained on more than 200 million documents, nothing at all is said about whether customer documents feed that training, and no opt-out is documented. Pricing is equally opaque.

None of this is disqualifying for the buyer it is aimed at, since a bank or insurer will negotiate a contract anyway and can ask all of these questions directly. It does mean the public site cannot answer them. Anyone evaluating Resistant AI should treat the demo as the point where data ownership, model training, subprocessors and the SOC 2 report get settled in writing. The detection capability looks strong; the paperwork has to be requested.