
Maisa
Maisa builds Digital Workers: enterprise AI agents that run entire business processes end to end, with a code-level audit trail behind every decision. Aimed at regulated sectors such as banking, insurance, energy and manufacturing, and sold through demo requests only.
What is Maisa?
Maisa is an enterprise platform for building and running Digital Workers, software agents meant to take on a complete business process rather than a single task. The company draws the line explicitly: where a copilot drafts a document or answers a question, a Digital Worker is supposed to handle loan origination, invoice reconciliation, KYC verification or claims intake from start to finish.
Four building blocks are advertised: the Digital Workers themselves, Maisa Studio, the Knowledge Processing Unit or KPU, and custom AI models. Studio is the web platform where business teams describe a job in plain language, stating the objective, the rules and the acceptance criteria; the terms define it as a web-based, AI-powered studio for creating, configuring and deploying agents. The KPU is the proprietary engine, described as combining the intelligence of AI with the control of code.
The claim worth understanding is when the process comes into existence. Instead of drawing a workflow graph in advance, the KPU generates executable steps at runtime, runs them in a controlled environment, checks the results against rules and invariants, then decides the next step. Every action leaves a code trace, which Maisa calls the Chain-of-Work, recording which data was read, which rules were applied and why a decision was reached. Resistance to hallucinations is presented as a property of that design rather than a matter of prompt engineering: if the evidence is missing the system should not invent it, and if totals do not reconcile it should not approximate.
Maisa also insists on model independence, so customers choose and change language models, and the accumulated traces are meant to train a smaller model the customer owns. The product page advertises more than 300 integrations, while the funding announcement mentions over 450 third-party systems and connection to any documented API.
Sixteen use cases are published, weighted heavily towards banking, from trade finance and auto-loan processing to adverse media screening and power of attorney verification, alongside insurance claims intake, supply chain work and electricity network certification. Santander, Indigo and Elecnor are named as customers. Founded in 2024 with dual United States and European headquarters, the company reports being cited by Gartner across more than fifteen Hype Cycle reports.
What it does
- Run a complete business process end to end, from document intake to audit-ready output
- Describe the job in plain language, including its objective, rules and acceptance criteria
- Read and validate messy documents, including poor-quality scans and inconsistent formats
- Produce a code-level trace of every step for compliance and audit review
- Connect legacy and modern systems, and any documented API, into a single process
- Monitor cost, access and return on investment from one console
- Switch language models without rewriting the process
When to use Maisa / When not to
A quick filter to help you decide if Maisa is the right fit.
When to use Maisa
- Compliance, risk and KYC teams in banks that need every automated decision to survive an audit
- Insurance operations handling claims intake, policy administration and customer verification at volume
- Finance and accounting departments buried in invoice intake, reconciliations, expense approvals and month-end close
- Procurement, legal and contract teams processing high volumes of documents in inconsistent formats
- Operations leaders in energy, infrastructure and manufacturing who want to automate without waiting on an IT backlog
When not to use Maisa
- Individuals looking for a personal assistant to draft, summarise or brainstorm, which the site explicitly assigns to copilots rather than Digital Workers
- Small businesses and freelancers, since the contact form starts at eleven employees and no self-service signup exists
- Buyers who need to compare published prices before speaking to a salesperson
- Consumers, as the terms state the services are for businesses, professionals and developers, and anyone under eighteen is barred from the site
- Teams wanting a documented public API or a mobile app to embed the tool in their own product
How to use Maisa
A typical end-to-end flow, from setup to results.
- Submit the Request a Demo form, which asks for name, corporate email, phone, company size, reason for contact and how you heard about Maisa
- Go through the sales and scoping conversation, since no self-service signup exists
- Create an account on the platform, either by synchronising a Google or Microsoft account or by entering name, surname and email
- Invite colleagues from the Organisation tab and assign them a Member or Admin role
- Describe the work in plain language: the task, the data to use, the rules and the goal to reach
- Answer the Digital Worker's follow-up questions, since it asks for whatever information it still needs
- Connect the systems the process runs on, from legacy platforms to modern applications
- Share company policies, business logic and working practices as usable knowledge
- Take the worker live with monitoring, feedback loops and enterprise controls in place
- Track cost, access and return on investment from the console, and expand once the sixty-day pilot proves out
Pros & Cons
Pros
- Traceability at the level of evidence rather than logs, showing which data was read and why a decision was made
- A design that prefers failing openly to inventing an answer, which is unusual and checkable in the vendor's own wording
- Business teams build the automation in plain language, without depending on the IT backlog
- Model independence, so no lock-in to a single frontier lab
- Sixteen use cases published individually, with named customers such as Santander, Indigo and Elecnor
- Complete and readable legal set, including a Data Processing Agreement published openly as a PDF
- A contractual commitment not to train models on customer input without express permission
Cons
- No published pricing at all: no price page, no range, no entry tier
- No self-service trial; the only route in is a sales demo
- SOC 2 Type II and ISO 27001 are displayed prominently but carry an asterisk meaning the audits are still in progress
- Every performance figure is self-reported, with no published methodology behind the 10x, 90x and 150x claims
- No named list of sub-processors and no stated data hosting country
- Product documentation is gated behind authentication and no public API documentation exists
- Legal inconsistency: the legal notice points to Spanish law and Madrid courts while the terms point to Delaware law, and three slightly different company names appear across the documents
Pricing & Plans
There is no permanent free plan and no published price. Maisa operates a contact-sales model: the site carries no pricing page, and the terms refer only to the price stated on the platform once a customer is signed in, with the appropriate pricing tier selected during the commercial discussion. Invoices are payable within fifteen days and payments are non-refundable, subscriptions renew automatically for successive periods of equal length unless notice is given thirty days before expiry, and price changes take effect thirty days after notification. The terms also allow Maisa to make Studio available as a free beta version, but only on a temporary basis, never for production use and never for personal data, so it does not amount to a free tier. The homepage offers a sixty-day pilot without stating whether it is chargeable.
- No named pricing plans are published
- the terms refer only to a pricing tier selected by the customer during the sales process
- Free beta version of Maisa Studio
- temporary
- excluded from production use and from any processing of personal data
Data, GDPR & hosting
A consolidated view of how Maisa handles your data.
GDPR overview
GDPR implementation is concrete and documented. The privacy policy is written under Articles 12 and 13 of the GDPR and Article 11 of Spain's LOPDGDD, names Maisa AI Inc. as controller with its EIN and Dover offices, and routes access, rectification, erasure, objection, restriction and portability requests to privacy@maisa.ai, with the Spanish AEPD cited as supervisory authority. A Data Processing Agreement is published as an openly accessible PDF, with standard contractual clauses annexed, Maisa acting as processor, and deletion or return of all personal data at the end of the service. Transfers outside the EEA rely on those clauses. The footer claims GDPR and EU AI Act alignment. Two caveats: SOC 2 Type II and ISO 27001 are shown with an asterisk meaning the audits are still in progress, and no Article 27 representative or data protection officer is named.
Who owns the data?
The terms draw a clean line. The customer keeps all intellectual property rights in its Customer Data, its Input, meaning the text, instructions and prompts it supplies, and in any Customer Applications it builds. Maisa keeps the rights in the Services and in what it calls Maisa Technology, the tools, code, models and documentation it developed to deliver them. Input is contractually treated as confidential information, protected for the term of the agreement plus five years, and indefinitely for source code, security infrastructure and compliance documentation. Where a company subscribes on behalf of its staff, Maisa acts as a processor and that company's own privacy policy governs the data.
Reuse rights
Customers may use their own data and outputs freely, since they retain the rights to their Input, Customer Data and Customer Applications, subject only to the acceptable use policy and to a ban on reselling or sublicensing the Agents as a standalone product. In the other direction, Maisa commits to using Input solely to deliver the service, and states it will not use it to train machine learning models unless the customer expressly permits it. Customer Data is likewise limited to service delivery. On the website side, the privacy policy lists categories of processors, from hosting and CRM to AI providers, and names Google Analytics, PostHog, X and Stripe. Transfers outside the European Economic Area rely on the European Commission's standard contractual clauses. Maisa states it takes no action in response to browser Do Not Track signals, and the free beta version of Studio may not be used to process personal data at all.
Data retention & training
Hosting summary
Maisa names no hosting country and no hosting region. The only architectural statement published is a data sovereignty claim on the Digital Workers page, saying that processing occurs inside the customer's secure perimeter, which describes where the work runs rather than where the platform's own data sits. The privacy policy lists hosting service providers as one category of processor among others, without naming any. Transfers outside the European Economic Area are acknowledged and covered by the European Commission's standard contractual clauses, which implies data can leave the EEA without ever stating a destination. The controls that are described are organisational and technical rather than geographic: isolation, role-based access control, audit visibility and policy enforcement, plus the Data Processing Agreement's commitments to malware detection, prevention and recovery across network, hosting and application layers, restoration of availability after an incident, and regular testing of those measures. Anyone with a data residency requirement will need to raise it directly with the vendor.
Things to keep in mind
Risks and trade-offs to weigh before adopting Maisa.
- Every headline number is self-reported: the 10x, 90x and 150x cost claims, the 10x first-year ROI, the 93 and 98 percent accuracy figures and the 40,000 hours recovered all come from the vendor without published methodology
- SOC 2 Type II and ISO 27001 are displayed as achievements in the body copy while a discreet asterisk states the audits are still in progress
- Three company names and two Dover addresses circulate across the legal pages, and the legal notice applies Spanish law while the terms apply Delaware law
- The legal notice states that the Spanish original prevails over the English version in case of contradiction, so the text you read may not be the binding one
- No data hosting country is disclosed, and the data sovereignty claim describes processing inside the customer's perimeter without saying where the platform's own data sits
- Automation that produces its own audit trail can encourage teams to accept traced output without reviewing it, which shifts rather than removes the human control the vendor says is required
- Delegating an entire process rather than a task erodes the tacit know-how of the people who used to run it, and the traces become an operational dependency of their own
Setup & Integrations
Technical difficulty
Low in principle, moderate in practice. Maisa's core promise is that business teams build in natural language with no developer and no IT backlog, and the Digital Worker asks for whatever it still needs. The real effort sits elsewhere: connecting existing systems including legacy platforms, and transferring internal policies and business logic as usable knowledge. Deployment is guided by Maisa's own team under a method it calls 1-3-6, with pilot to production advertised at sixty days. One customer reports turning rough operational guidance into a working Digital Worker in weeks.
Deployment
Integrations
Behind Maisa
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Maisa.
Frequently asked questions
What exactly is a Digital Worker?
How is this different from an automation tool like n8n or from RPA?
How does Maisa claim to resist hallucinations?
Is my data used to train AI models?
How much does it cost?
Is there a free trial?
Is a Data Processing Agreement available?
Which security certifications does Maisa actually hold?
Do we need developers, and how long does deployment take?
Should you pick Maisa?
Maisa makes an unusually specific promise in a crowded agent market: not that the output will be good, but that it will be provable. The Chain-of-Work trace, the runtime formation of the process and the stated preference for failing rather than approximating are design commitments a compliance team can interrogate, which is more than most vendors offer. The evidence around it is respectable for a company founded in 2024, with sixteen documented use cases, named customers including Santander, Indigo and Elecnor, and a 25 million dollar seed round led by Creandum.
The reservations are about proof rather than intent. Every efficiency figure on the site is self-reported, including the 10x, 90x and 150x cost claims and the accuracy percentages attached to individual deployments; none carries a published methodology. The two security certifications displayed most prominently, SOC 2 Type II and ISO 27001, are still under audit, which the footnote says plainly but the page layout does not emphasise. No data hosting country is named, no sub-processor list is published, and the legal documents disagree with each other on governing law and on the exact company name.
The practical filter is simple. Maisa is aimed at large regulated organisations with an identified process, a compliance function in the loop and the patience for a sales cycle: there is no pricing page, no self-service trial and no mobile or public API route in. If that describes you, the depth of the legal documentation and the openly published Data Processing Agreement make due diligence unusually straightforward. If you want to evaluate a tool before talking to anyone, this is not that kind of product.
- Choosing a selection results in a full page refresh.
- Opens in a new window.