
Wecan
Wecan is a Swiss KYC/AML compliance platform for banks, external asset managers and fintechs. It automates onboarding, perpetual KYC and periodic reviews, with data hosted in Switzerland, Luxembourg or on your own servers, under ISO 27001 certification.
What is Wecan?
Wecan is a KYC/AML compliance platform published by WeCanGroup SA, a Geneva company that became a subsidiary of the Nasdaq-listed SealSQ Corp in June 2026. It addresses one job: the client due diligence work that regulated financial institutions must perform and then be able to defend under audit.
The publisher calls it The AI Compliance Copilot, and the word copilot is deliberate. Wecan describes a division of labour in which the AI extracts, drafts and flags while the human team reviews and approves; nothing is approved automatically. The product is organised around three moments of the client relationship: onboarding, lifecycle monitoring of changes in circumstances, and periodic reviews.
Twelve cross-cutting capabilities carry that promise: KYC forms per client profile, OCR and AI document extraction, a screening marketplace, AML risk scoring, internal rules written in natural language, a workflow engine, a conversational copilot, smart folders, a MiFID suitability questionnaire, an open API with native integrations, onboarding pack generation, and an append-only audit trail. A second building block, Wecan Comply, has been in production since 2021: a shared KYC/KYB network where an entity maintains its file once and shares it, with consent, across all its banking counterparties. The audit trail is anchored on a blockchain, and the terms still describe a Wecan Chain with anchoring fees billed in WECAN tokens.
Coverage extends to individuals, legal entities, trusts, foundations and asset managers, in four interface languages. The publisher claims more than 100 financial institutions in production across over five countries, and names Pictet, Lombard Odier, Edmond de Rothschild, Syz, Barclays Private Bank, UBP, Gonet, Arab Bank Switzerland, Banque Delubac & Cie and Banque Cramer among its clients. It also claims onboarding compressed from thirty days to a few hours, cost per file down by 81%, periodic reviews handled in ten minutes and manual review time cut by 80%. Those are the publisher's own figures, not independently measured ones. Research continues through the Compliance Copilot 2026-2028 programme, run with FHGR and professor Joerg Osterrieder and funded with more than CHF 600,000 by Innosuisse.
What it does
- Capture KYC material in any form - documents, scanned photos, forwarded emails, voice notes - and extract it field by field, in any language, with a confidence score
- Score AML risk from 0 to 100 and screen for sanctions, PEP and adverse media through the screening provider of your choice
- Apply internal rules written in plain language, then run regulatory checks and consistency checks in parallel
- Route files through configurable workflows with four-eyes approval, routing to the right team and deadlines
- Generate onboarding packs, contracts and an audit-ready file, then push them to the CRM and the core banking system
- Share a KYC or KYB file with counterparties on the trust network, under explicit and revocable consent
- Monitor the whole portfolio around the clock for trigger events and pre-fill periodic reviews on a risk-banded calendar
When to use Wecan / When not to
A quick filter to help you decide if Wecan is the right fit.
When to use Wecan
- Private and universal banks that need to industrialise client onboarding and periodic KYC reviews
- External asset managers looking for a front-friendly compliance workflow they can run without a large back office
- Fintechs that want an API-first compliance layer, with a go-live announced at four to six weeks
- Compliance and AML officers at institutions subject to FINMA and AMLA in Switzerland, or to EU AML 5/6, CSSF in Luxembourg and BaFin in Germany
- Insurers, family offices and trustees dealing with trusts, foundations and layered ownership chains where beneficial owners must be resolved
When not to use Wecan
- Private individuals and consumers: the platform is sold to regulated institutions, never to end customers
- Anyone who wants to sign up and test alone, since there is no online registration and every entry point leads to a booked demonstration
- Buyers who need published prices to build a shortlist, as not a single figure appears anywhere on the site
- Teams running high-volume retail identity checks, a segment the publisher's own comparison page attributes to Ondato rather than to itself
- Very large multi-jurisdictional global banks, which that same page positions as Fenergo territory
How to use Wecan
A typical end-to-end flow, from setup to results.
- Watch the 9-minute product video, which is available without filling in any form
- Book a demo from the contact page: 30 minutes, no slides, run on real KYC scenarios, with a reply announced within 24 working hours
- Use the same form to raise a pricing or RFP request, a partnership or a press enquiry, since there is no self-service sign-up
- Choose where the data will live: Switzerland, Luxembourg or your own infrastructure
- Plan four to six weeks to go live, API integration with the CRM and the core banking system included
- Connect identity: Keycloak as identity provider, SAML, OpenID Connect and MFA, with Microsoft, Google or WISeID accounts
- Configure the platform without code from the admin UI: KYC forms, document packs, scoring models, workflows and internal rules written in plain language
- Work day to day in a chat-style workspace: drop a file, a photo or an email, or dictate a voice note, and get structured KYC data back
- Train the teams with the included knowledge base and tutorials; additional training is quoted separately under clause 3.1 of the terms
- Escalate to the helpdesk, open Monday to Friday from 9am to 5pm CET and reserved for the named users your organisation has trained
Pros & Cons
Pros
- Data sovereignty is a real option rather than a slogan: Switzerland, Luxembourg or on-premise, chosen by the customer, with Swiss regulation (FINMA, AMLA) treated as a speciality instead of generic global coverage
- ISO 27001 is held by the publisher itself, since 2022, certified by SQS with an annual audit - and it is the only certification Wecan claims for itself
- Explainability is designed in: the risk score shows the rules that fired and their weight, and the audit trail records provenance field by field, which is what an auditor actually asks for
- The human keeps the decision: no automatic approval, four-eyes review and L1/L2 validation
- The Wecan Comply network adds something rivals do not offer, according to the publisher's own comparison: a shared KYC/KYB file maintained once and reused across counterparties
- Configurable by the customer without development work - forms, workflows, scoring models and internal rules - and neutral on suppliers, with the screening provider and the AI engine both left to the customer's choice
- Institutional backing that can be checked: named private banking references, an announced 99.5% SLA with RTO under 48 hours and RPO under 24 hours, and a listed parent (SealSQ, Nasdaq: LAES) committing CHF 5 million in June 2026
Cons
- No price is published anywhere: there is no pricing page (the /pricing path simply returns the home page), no pricing entry in the sitemap, and the terms only refer to a quotation
- No self-service at all - no online trial, no sign-up - so every path runs through a salesperson
- The 14-day free trial appears in a single comparison article on the site and nowhere in the actual journey, and that same article claims pricing transparency while no figure is published anywhere
- No public API documentation, although the API is presented as central to the deployment
- The subprocessor list is not published and is only sent by email on request, and the site never says whether customer data is used to train AI models, neither to confirm it nor to rule it out
- Clause 7.3 of the terms disclaims all liability in the event of a security breach or data leak, a broad exclusion for a platform handling KYC data, and no Article 27 EU representative is appointed even though the product explicitly targets the European Union
- Support is limited to Swiss office hours (9am to 5pm CET, Monday to Friday) and to named, trained users, a single generic address covers legal, GDPR, support and sales alike, there is no mobile app or browser extension, and the terms (version 25.12.11) still describe a blockchain anchoring platform billed in WECAN tokens
Pricing & Plans
No price is published. Wecan operates a contact-sales model: there is no pricing page - the /pricing path returns the home page itself and the sitemap holds no pricing entry - and no amount appears anywhere on the website. Clause 4.1 of the terms provides that licence fees apply according to the required level of use and that Wecan informs the customer of them, which describes a quotation rather than a rate card; clause 4.2 adds anchoring fees for blockchain transactions, billed in WECAN tokens. Payment falls due within 30 days, access may be suspended for late payment, reminder fees apply, and prices may be increased with 30 days' notice (clauses 4.3 and 4.4). Additional training is quoted separately. The contact form offers a dedicated Pricing & RFP option, which confirms a tender-based approach. The only figures the publisher puts forward are cost-per-file estimates, around CHF 1,850 brought down to roughly CHF 350 for a mid-sized bank handling some 650 onboardings a year - an internal benchmark, not a tariff. A comparison article published on the site describes Wecan's own model as a transparent subscription with no hidden fees and a 14-day free trial; no other page confirms this, and it should be verified with the publisher before being relied upon. No permanent free plan is mentioned.
- the website names no tier
- no grid and no package
- a demonstration followed by a quotation
- the contact form offering a dedicated Pricing & RFP option
- The terms refer to licence fees set according to the needed level of use
- without ever listing or pricing those levels
Data, GDPR & hosting
A consolidated view of how Wecan handles your data.
GDPR overview
Wecan states compliance with both the revised Swiss FADP and the European GDPR, and repeats a GDPR aligned badge on the home page and the security page. The privacy policy, version 23/08/25, says data is processed and stored on servers located in Switzerland, and that disclosure abroad happens only where the Federal Council has recognised adequate protection, where express consent is given, or where the transfer is directly linked to the conclusion or performance of a contract. Section 9 grants access in a common electronic format, rectification and erasure, and requires express consent for sensitive data. The publisher holds ISO/IEC 27001:2013 and supplies a data processing addendum on request. Two gaps: no Article 27 EU representative is designated anywhere, and no data protection officer is named. Every request goes to one generic address, contact@wecangroup.ch.
Who owns the data?
The terms draw a clear line. WeCanGroup SA acts as processor, not owner: the customer institution stays responsible for the client data it uploads and warrants, under clause 6.3, that it obtained the data owner's consent before moving that data to a cloud service, as Swiss FADP and GDPR require. Clause 6.1 reserves every intellectual property right in the platform itself to Wecan. On the shared KYC network the publisher states You own your data: each entity controls exactly what it shares and with whom, consent being explicit, revocable and logged. Clause 10.2 is the sting: when the contract ends, access to the data ends with it, so anything the customer must keep has to be exported first.
Reuse rights
The privacy policy says Wecan processes the user's first name, surname, email address and telephone number, plus whatever else its contractual and legal obligations require. The stated purposes are identifying and contacting users, delivering the services, monitoring and improving their use, handling requests, managing the business relationship and invoicing, sending newsletters, performing the contract, meeting its own legal duties (KYC, AML, tax, corporate) and asserting or defending its rights. Because the platforms are exchange platforms, section 5.2 puts the customer in charge of distribution: it is the user who chooses who receives their data. Clause 6.2 goes further and lets the user share data obtained or uploaded through the platforms with the entities of its own group, without asking Wecan for permission. Processors authorised by the user (IT, infrastructure, server location, maintenance) may access the data, and the exhaustive list is only sent on request to contact@wecangroup.ch. Data may also pass to a third party in a merger, sale, liquidation or asset transfer, and the website itself relies on cookies, Google Analytics (Google Inc., United States) and social plugins. One silence deserves attention: nowhere does the site say whether customer data is used to train AI models, neither to confirm it nor to rule it out.
Data retention & training
Hosting summary
The customer chooses the perimeter: Switzerland, Luxembourg or its own infrastructure - your data never leaves the perimeter you choose. The privacy policy states that data is processed and stored on servers located in Switzerland, and that transfer abroad is possible only under Swiss data protection conditions: recognised adequacy, express consent, or a direct link to a contract. Database and document storage are isolated per tenant, backups are encrypted and isolated, and encryption applies at rest and in transit. Identity runs through Keycloak as provider, with SAML, OpenID Connect, MFA and Microsoft, Google or WISeID accounts. The architecture is audited and penetration-tested every year, and the publisher has held ISO 27001 since 2022, certified by SQS. Continuity targets are announced at RTO of 48 hours or less, RPO of 24 hours or less and a 99.5% SLA, with post-quantum expertise inherited from the SealSQ group. One gap remains: subprocessors are acknowledged (IT, infrastructure, server location, maintenance) but the list is not published and is sent only on request. Note that the marketing website itself resolves to a Microsoft Azure address in Amsterdam, which concerns the site, not customer data.
Things to keep in mind
Risks and trade-offs to weigh before adopting Wecan.
- Identity has to be pieced together: there is no legal notice or Impressum page (/legal and /impressum both return 404), so the company name comes from the terms and the addresses from the contact page. The commercial register records the Geneva address as c/o ExpertFid & Audit SA, a domiciliation at an accounting firm, while the site presents the same address as its Geneva HQ
- Certifications need care: only ISO 27001, awarded by SQS since 2022, is claimed by the publisher for itself. FINMA, AMLA, CSSF, BaFin, PSD2 and MiCA are frameworks the tool helps customers comply with, never approvals or licences held by Wecan
- The comparison article claiming a 14-day free trial and full pricing transparency is contradicted by the total absence of published prices everywhere else on the site. Verify both claims with the publisher before relying on either
- The documentation lags behind the product: the terms (version 25.12.11) describe a blockchain anchoring platform billed in WECAN tokens and never mention AI or a copilot, the llms.txt file attributes the Compliance Copilot role to the Comply page when the site's own navigation gives it elsewhere, the privacy policy names the products Wecan and Wecan Connect, a naming found nowhere else, and the contact page announces 15 minutes for the demo in its meta description against 30 minutes in its title and body
- Clause 7.3 of the terms disclaims liability very broadly in the event of a security breach or data leak - a clause worth negotiating before signing, for a platform that processes KYC data
- The product screenshots are a demonstration dataset: the client names, file numbers, amounts and email addresses shown are fictional and nothing should be inferred from them. The home page counters are JavaScript animations whose final values do not appear in the page source either; only the 81% cost reduction per file is readable in static HTML
- The founded in 2015 by Dr Vincent Pignon line needs nuance: at incorporation on 12 October 2015 the board was Julia Jaussaud as chair, Jean-Claude Respen, Alexandre Coquet and Thomas Giacomo, and Vincent Pignon appears in the register only in February 2017. The same legal entity, CHE-414.469.523, traded as WeCan.Fund SA, a crowdfunding platform based in Carouge, until its name and corporate purpose changed in February 2019
Setup & Integrations
Technical difficulty
Moderate, and organisational more than technical. Go-live is announced at four to six weeks, API integration with the CRM (Wize, Salesforce, custom), core banking and PMS included, with UiPath RPA for legacy systems. The customer's own teams configure KYC forms, document packs, scoring models, workflows and plain-language rules from the admin UI without code, the publisher promising no training week and changes in hours rather than months. SSO and MFA must be wired through Keycloak, SAML or OIDC, and an on-premise deployment implies customer-side infrastructure. The real constraint: no public API documentation, so integration work runs through the publisher.
Deployment
Integrations
Supported languages
Behind Wecan
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Wecan.
Frequently asked questions
Who is Wecan built for?
What does the platform cover across the client lifecycle?
Where is the data hosted?
Which certifications does Wecan actually hold?
How much does it cost?
Is there a free trial?
Is there an API?
Which integrations are available?
Is customer data used to train AI models?
How long does it take to get started, and what support is included?
Should you pick Wecan?
Wecan is an unashamedly narrow tool, and that is its strength. It does one thing - client due diligence for regulated financial institutions - with a Swiss anchoring it makes no attempt to hide. The operational credibility is there: named private banking references, ISO 27001 held by the publisher since 2022, and a shared KYC network in production since 2021.
The architecture suits the actual job. Because the AI extracts, drafts and flags while a human reviews and approves, a file can be defended in front of an auditor rather than merely produced quickly. The explainable 0-100 risk score, the field-level audit trail and the four-eyes workflow all point the same way, and the choice of hosting - Switzerland, Luxembourg or your own servers - makes data sovereignty a decision instead of a claim.
The weak point is not the product but commercial transparency. No price is published, no trial is reachable, no API documentation is public, and the subprocessor list arrives only by email. The 14-day free trial mentioned in a single comparison article sits awkwardly against the complete absence of pricing everywhere else, and should be verified before anyone relies on it. The contractual documents lag behind as well: the terms, version 25.12.11, still describe a blockchain anchoring platform billed in WECAN tokens and never mention AI, while clause 7.3 disclaims liability for security breaches in remarkably broad terms.
One last thing to watch: SEALSQ became the majority shareholder in June 2026 with CHF 5 million committed, and the roadmap will be shaped by that. Recommended for compliance teams at regulated institutions willing to go through a sales process, and unsuitable for anyone who needs to compare prices before speaking to a vendor.
- Choosing a selection results in a full page refresh.
- Opens in a new window.