SpeciCRED Co-pilot Suite
A suite of seven agentic AI co-pilots for credit risk in private banking, built by the SpeciTec AI Lab in Geneva. It runs inside the bank's own environment, feeds on SpeciCRED data and keeps a human in the loop.
What is SpeciCRED Co-pilot Suite?
The SpeciCRED Co-pilot Suite is a set of seven production AI agents built by the SpeciTec AI Lab for credit work inside private banks. It is agentic rather than conversational: SpeciTec describes co-pilots that take action under supervision instead of yet another chatbot, and the agents draw on the data already held in the SpeciCRED Lombard credit platform. Each agent carries a published success rate and average latency, both of them the vendor's own figures rather than audited results.
The Credit File Analyst runs a health check on a credit file, covering required documents, portfolio composition, client history, risk scoring and context analysis, and returns an indicative approval trend for the credit committee; SpeciTec reports 96.4% success at an average of 38 seconds. The Breach Analyst takes each breach through a liquidity analysis and recommends a margin call, a capital injection, a portfolio reallocation, acceptance of the risk or legal escalation, with the supporting documentation, always human-in-the-loop; the vendor reports 94.2% at 28 seconds. The Market Risk Analyst structures stress-test scenarios from each client's real data, ready to activate in SpeciCRED (97.1%, 90 seconds). The Termsheets Analyst reads a termsheet against credit policy, the observation period and the existing book, then issues a reasoned lend or decline suggestion with an amount (95.8%, 22 seconds). The Credit Ops Co-pilot handles simple, non-strategic files in bulk, meaning facilities under CHF 2M, Pool 4 clients and retail-like profiles, writing commentary and pre-filling documents (92.3%, 6 seconds). The Reports & Dashboard Generator produces SSRS reports and dashboards on demand (99.4%, 18 seconds), and the Derivatives Strategist analyses both legs of Accu/Deco, TARF and Strangle structures to suggest increasing or reducing exposure (93.5%, 14 seconds). Across the suite SpeciTec claims a 95.7% follow-through rate, a 65% cut in credit committee preparation time and full audit trail coverage, figures the site itself labels indicative.
All seven are configured, monitored and audited from a single AI Agents Control Center, with live updates, an exportable audit log, granular role-based access control and a pending-review queue. Integration to core systems runs through Model Context Protocol servers, and deployment can be public cloud, private cloud, on-premise or fully air-gapped. What it is not: it is neither the underlying SpeciCRED credit platform nor the sister SpeciVIM Co-pilot Suite of eight KYC and AML compliance agents.
What it does
- Run a health check on a credit file and return an indicative approval trend for the credit committee
- Analyse a breach, work it through a liquidity review and recommend the action: margin call, capital injection, portfolio reallocation, risk acceptance or legal escalation
- Read a termsheet against credit policy, the observation period and the existing book, then suggest whether to lend and how much
- Structure stress-test scenarios from each client's real data, ready to activate in SpeciCRED
- Process simple, non-strategic credit files at volume, write the commentary and pre-fill the supporting documents
- Generate SSRS reports and dashboards on demand from existing data
- Analyse both legs of Accu/Deco, TARF and Strangle option structures and suggest increasing or reducing exposure
When to use SpeciCRED Co-pilot Suite / When not to
A quick filter to help you decide if SpeciCRED Co-pilot Suite is the right fit.
When to use SpeciCRED Co-pilot Suite
- Private banks and wealth managers, from tier-1 institutions down to boutique houses
- Institutions already running the SpeciCRED platform, where the agents plug into the existing data model with no migration phase
- Banks under strong sovereignty constraints, such as FINMA in Switzerland, MAS in Singapore, MFSA in Malta, BaFin in Germany or the FCA in the United Kingdom
- Organisations that require an on-premise or air-gapped deployment, with no data leaving their own perimeter
- Credit teams that want to industrialise credit committee preparation and the handling of breaches
When not to use SpeciCRED Co-pilot Suite
- Anyone outside private banking and wealth management: the AI Lab declares an exclusive focus on that sector
- Buyers who want a published price or a self-service purchase, since every engagement is quoted privately after a workshop
- Small organisations, because the entry tier is a contracted 90-day pilot with an embedded consultant
- Teams whose need is KYC, AML or sanctions compliance, which is covered by the sister SpeciVIM Co-pilot Suite rather than this one
- Individuals: nothing in the offer is aimed at a single private user
How to use SpeciCRED Co-pilot Suite
A typical end-to-end flow, from setup to results.
- Start with the online scoping calculator: pick the agents, the assets under management band, the number of front-office users, the deployment posture, the applicable regulators, whether SpeciCRED is already in production and your target go-live date; it returns a recommended tier, not a price
- Request a discovery workshop through the contact form, selecting the SpeciCRED suite as the subject
- Discovery: a Talent consultant runs a scoping workshop with your business owners to choose the co-pilot, the data to connect and the success metrics
- Pilot: the co-pilot is deployed on-premise inside your own environment and connected to your systems through Model Context Protocol servers
- Expect a working co-pilot within six to ten weeks, running under human-in-the-loop validation
- Operate the agents from the AI Agents Control Center: configure them, monitor them and clear the pending-review queue
- Read the confidence score and the source reasoning attached to every suggestion before approving it, since nothing is passed to downstream systems without an explicit human validation
- Scale: extend the suite to other departments, add co-pilots and hand the runtime over to your own IT team under long-term governance
- Run: quarterly model and prompt reviews, regulatory watch and an ongoing FINMA evidence pack, with an embedded Talent engagement manager
- Export the immutable audit log to your SIEM whenever internal audit or a regulator asks for evidence
Pros & Cons
Pros
- A native on-premise and air-gapped posture: SpeciTec states that customer banking data never transits its own infrastructure
- An audit trail on every prompt, retrieval and action, built for FINMA scrutiny and internal audit
- ISO/IEC 27001:2022 certified by SGS under reference CH24/00000088 and valid until 07/10/2027, a claim that can actually be checked
- Each of the seven agents is documented individually, with its triggers, its actions and the metrics the vendor publishes for it
- BYOLLM and customer-held encryption keys, so both the model and key custody stay with the bank
- A declared focus on private banking and wealth management rather than a generalist AI consultancy
- Attaches to an existing SpeciCRED data model with no migration phase
Cons
- No public pricing whatsoever: all three tiers read "On request" and a quotation only follows a private discovery workshop
- No terms and conditions are published anywhere on the site, so the contractual framework cannot be read before negotiation
- No public API documentation, even though the architecture is presented as API-first
- No customer is named: the three case studies are anonymised and named references are reserved for parties under NDA
- The agent performance figures are vendor claims that the site itself labels indicative, and none of them can be checked from outside
- Strong dependence on the SpeciTec ecosystem, since the full value assumes SpeciCRED is already in production
- No free plan and no free trial: the entry point is a contracted 90-day pilot
Pricing & Plans
There is no free plan and no free trial, and no price is published. The three tiers, Pilot, Scale and Enterprise, are all shown as "On request". SpeciTec states that pricing is structured around scope, deployment posture and SLA, and is quoted privately by its Talent team after a discovery workshop; the tiers are denominated in Swiss francs or euros and include the relevant FINMA evidence pack. The billing shape differs by tier: a one-off plus a success fee for the 90-day Pilot, an annual contract for Scale, and a multi-year subscription under a master agreement for Enterprise. A comparative return on investment model is shared under NDA after a discovery call. The online scoping calculator returns a recommended tier only, never a figure. Prospective buyers should therefore plan on the basis of a private quotation rather than a list price.
- a 90-day pilot agreement
- priced on request
- billed as a one-off plus a success fee. It covers one co-pilot on one workflow and up to 25 active users
- a connection to SpeciCRED
- SpeciVIM or Mobile Banking
- a hosted LLM with on-premise inference
- an embedded Talent consultant for the duration of the pilot and best-effort support in business hours. Core banking connectors are not included at this tier.
- an annual contract
- priced on request and billed annually. It covers up to three active co-pilots and up to 250 active users
- custom core banking integrations
- optional BYOLLM and up to two internal systems
- a dedicated AI Lab squad with a Talent engagement manager
- a 99.9% SLA in business hours with on-call cover
- quarterly model and prompt reviews
- an annual penetration test
- a multi-year master agreement
- priced on request and billed as a multi-year subscription. It covers unlimited co-pilots
- users and internal systems
- a fully on-premise air-gapped deployment
- BYOLLM with customer-hosted models
- a co-pilot factory letting the bank build its own agents under SpeciTec governance
- a dedicated AI Lab squad with a named Talent Partner
- a 99.95% SLA around the clock with a dedicated technical account manager
Data, GDPR & hosting
A consolidated view of how SpeciCRED Co-pilot Suite handles your data.
GDPR overview
GDPR is addressed explicitly. The privacy policy, last updated on 25 March 2025, is written against both the Swiss FADP and the European GDPR, and lists rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. A single address, dpo@specitec.com, handles those requests. International transfers are said to rest on standard contractual clauses where required. The Trust Center answers its own question, "Are you GDPR / nFADP compliant?", with a yes, and an Article 28 data processing agreement is available on request. Two gaps are worth noting: no Article 27 EU representative is designated anywhere on the site, and the legal notice carries neither a company identification number nor a named officer. SpeciTec also argues that in most deployments it is not a processor of your banking data, because it does not host it.
Who owns the data?
SpeciTec states that it does not host customer banking data: the platform is deployed in the bank's own tenant, on-premise or in the cloud the bank operates, and the vendor publishes the claim that customer banking data never transits its infrastructure. It says it runs no region, no managed cloud tenant and no shared database, and that it holds no path to the encryption keys, which stay in the customer's custody through CMK or BYOK. The audit trail the agents produce belongs to the bank, and when a contract ends the customer's team keeps control of the runtime. One caveat: the published privacy policy governs the website, not the deployed product, whose terms sit in the Article 28 DPA supplied on request.
Reuse rights
No terms and conditions are published, so no reuse licence can be quoted, and what the site documents splits in two. On the website, SpeciTec collects an email address, first and last name, telephone number, postal address and usage data such as IP address, browser, pages visited, timestamps and device identifiers. It states it uses them to provide and maintain the service, manage accounts, perform contracts, contact you by email, telephone or SMS, send similar offers unless you object, handle your requests, support a business transfer and run analytics to improve the service; cookies are limited to essential session, notice-acceptance and functionality categories. On the product side the picture is different: the data stays inside your tenant, every prompt, retrieval and action is written to an audit trail you own and can export to your SIEM, and the vendor says it has no standing access to production data, with any support intervention opt-in, time-boxed, logged on your own identity provider and framed by a written DPA. SpeciTec adds that in most deployments it is not a processor of your banking data, because it does not host it.
Data retention & training
Hosting summary
SpeciTec operates no hosting region of its own: the suite runs inside the customer's environment. Five topologies are supported, namely on-premise in the bank's own datacentre, hardware and network; a customer-managed Azure tenant in the region of its choice; a customer-managed AWS tenant on the same basis; a fully air-gapped network with no internet egress; and hybrid combinations. On-premise is presented as the default for tier-1 banks under FINMA, MAS or DFSA sovereignty constraints, Azure as the most common pattern in Switzerland, Luxembourg and the EU, and AWS as the frequent choice across APAC and the Americas. Data residency is therefore a customer decision, with deployments in Switzerland, the EU or the jurisdiction the bank chooses. One caveat on attribution: the supplier table published in the Trust Center, listing Microsoft 365, a self-hosted Azure DevOps Server, Atlassian, OpenAI ChatGPT Enterprise, Anthropic Claude Enterprise, Vercel Enterprise and VTX Telecom, covers SpeciTec's own internal operations, not the runtime that processes your banking data. The public website itself resolves to a Swiss address on AS12350, VTX Services SA in Fribourg.
Things to keep in mind
Risks and trade-offs to weigh before adopting SpeciCRED Co-pilot Suite.
- Every agent performance figure is a vendor claim: the site presents them as indicative results observed across SpeciTec's own pilot programmes, and none has been independently audited
- Delegating credit file triage and breach recommendations to an agent can quietly erode the judgement of junior analysts, who may stop rebuilding the reasoning themselves; the confidence score shown on each suggestion is a comfort signal, not a proof
- ISO/IEC 42001:2023 and SOC 2 Type II are announced as in progress rather than obtained, and FINMA 2018/3, CSSF 22/806, MAS TRMG and PCI DSS are declared alignments, not certifications; reading them as certifications would misstate the vendor's actual posture
- The published privacy policy governs the website, not the product deployed inside the bank, so any GDPR analysis of the product itself runs through the Article 28 DPA, which is only available on request
- The vendor's showcase numbers and its client evidence cannot be corroborated: no customer is named, the case studies are anonymised, named references are reserved for parties under NDA, and no contractual terms are published for review before negotiation
- The site contradicts itself on the publisher's own history, showing two different seniority claims on the same page alongside two different founding years across its markup and its prose, so the corporate track record should be treated as unconfirmed
- Two due-diligence loose ends: the vendor's supplier table credits Vercel Enterprise with delivering its website while the domain resolves to a Swiss VTX address behind Microsoft IIS, and the demo subdomain is behind an authentication wall, so nothing can be tried without going through sales
Setup & Integrations
Technical difficulty
Moderate, and vendor-led rather than self-service. There is no sign-up: a scoping workshop precedes deployment, and SpeciTec announces a working co-pilot within six to ten weeks for a pilot. Reference Kubernetes manifests and Terraform modules ship with hardened defaults, alongside hardening guides for Azure, AWS and on-premise, plus SSO federation through SAML 2.0, OIDC or SCIM 2.0. You need an operations team, because the bank owns the runtime, log retention and incident response. Where SpeciCRED is already live, the agents attach to the existing data model with no migration phase.
Deployment
Integrations
Supported languages
Behind SpeciCRED Co-pilot Suite
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What exactly is the SpeciCRED Co-pilot Suite?
What does agentic AI mean in a banking context?
Can the agents run on-premise?
How do the agents connect to our existing systems?
Where is our data stored, and can SpeciTec see it?
How are AI governance and compliance handled?
Which certifications does SpeciTec actually hold?
Is there a published price, a free plan or a trial?
How is success measured once the agents are live?
What happens when the contract ends?
Should you pick SpeciCRED Co-pilot Suite?
The SpeciCRED Co-pilot Suite is a narrow, vertical product, and that is precisely its argument. Seven credit agents covering file analysis, breach handling, stress-test scenarios, termsheets, bulk credit operations, reporting and derivatives strategy are aimed squarely at private banks and wealth managers, not at anyone shopping for a general-purpose assistant. Its structural strength is architectural: the platform runs inside the bank's own tenant, on-premise or air-gapped where needed, with customer-held keys, an audit trail on every prompt and action, and an ISO/IEC 27001:2022 certificate from SGS that a buyer can actually verify. That is the only certification SpeciTec holds today: ISO/IEC 42001:2023 and SOC 2 Type II are still in progress, and the FINMA, CSSF, MAS and PCI DSS references are declared alignments rather than certifications. Its structural weakness is commercial opacity, and it is complete: no published price, no terms and conditions, no named customer, and no public API documentation despite an API-first pitch. Every performance figure, from the 95.7% follow-through rate to the per-agent success rates and latencies, is the vendor's own and is presented by the site itself as indicative. The suite makes most sense for an institution already running SpeciCRED, where the agents attach to an existing data model with no migration phase; for everyone else this is a heavy contractual engagement that begins with a discovery workshop and a paid 90-day pilot rather than a sign-up form. Maturity looks credible, with agents described as in production and a long-established Geneva publisher that is visibly active. Treat the metrics as claims to be tested during the pilot, and the evidence pack as the thing worth negotiating for.
- Choosing a selection results in a full page refresh.
- Opens in a new window.