
Nyx
Nyx is an autonomous fraud operations system for banks, built by Cleafy. Specialist AI agents investigate every fraud event end to end, link isolated cases into coordinated campaigns and deliver a full forensic report in under five minutes.
What is Nyx?
Nyx is a fraud operations system for banks, built by the Italian security vendor Cleafy. Its premise is that detection is no longer the bottleneck in financial crime: the constraint is the operating model itself, because every alert still needs an analyst to open it, work it and close it. Nyx removes that ceiling by running the whole fraud lifecycle — detection, investigation, decisioning and response — continuously and at machine scale, leaving people to govern outcomes rather than process volume.
Before any reasoning begins, every actor, channel and interaction across the institution's digital environment is classified, enriched and correlated into structured, auditable evidence. Four specialist agents then work on that material in parallel: an Investigation Analyst that reconstructs the full attack chain, a Campaign Hunter that links isolated cases into coordinated campaigns, an Intelligence Writer that turns analysis into decision-ready output, and a Security Posture Agent that watches and tunes the active detection rules.
What reaches the analyst is not a risk score but a complete assessment: a causal chain running from the first event to the recommended action, a prioritised recommendation carrying a confidence level and an impact analysis, and a forensic report written in the analyst's working language, with Italian, English and Spanish shown on the page. Recommendations arrive tagged as technical, human or escalation, and a person approves or rejects them. Cleafy states the cycle takes under five minutes, averaging two and a half to three, against an industry baseline of four to five hours per case, and that it applies to every event rather than a sample.
The system is presented as attack-agnostic, covering account takeover, scams, fraudulent device enrolment, malware- and remote-access-driven fraud and multi-stage campaigns, with campaign detection claimed up to fifteen days before the first fraudulent transaction. Deployment is single-tenant and, according to Cleafy, customer data never touches a shared graph: instead of a generic industry-trained model, Nyx builds knowledge of each institution's own threat landscape. It has run in regulated European banking environments since December 2025.
What it does
- Investigate every fraud event end to end, with no sampling and no human triage
- Reconstruct the full causal chain from the first signal to the recommended action
- Correlate isolated cases into coordinated campaigns across accounts, devices, channels and time
- Produce a decision-ready forensic report in the analyst's own working language
- Rank recommendations by confidence and impact, tagged technical, human or escalation
- Monitor risk drift and tune active detection rules without manual intervention
- Approve or reject each recommendation before any action is taken
When to use Nyx / When not to
A quick filter to help you decide if Nyx is the right fit.
When to use Nyx
- Fraud operations teams at banks and payment providers whose case backlog is limited by analyst headcount
- Heads of fraud and VPs of fraud who need every event assessed rather than a sampled subset
- Chief risk officers and compliance leads who must produce explainable, auditable evidence for regulators
- SOC and threat intelligence analysts hunting coordinated campaigns across accounts, devices and channels
- Large regulated institutions that require single-tenant isolation of their customer data
When not to use Nyx
- Individuals and small businesses: Nyx is sold institution to institution, with no self-service sign-up
- Buyers who need a published price before engaging, since no rate, plan or trial is disclosed anywhere
- Teams outside banking and payments: the whole product is scoped to digital banking fraud
- Developers looking for an API or technical documentation, as neither is published
- Organisations wanting immediate access, since Cleafy states it is onboarding selected institutions only
How to use Nyx
A typical end-to-end flow, from setup to results.
- Open the Nyx page and read the pipeline section, which walks through a worked fraud case
- Fill in the contact form, selecting your role from risk, executive, technology, AI, fraud or security
- Accept the privacy notice and, optionally, the Article 13 GDPR marketing consent
- Wait for Cleafy to reply, which the page says happens within 48 hours
- Agree a single-tenant deployment and connect the event feed from Cleafy's Fraud xDR platform
- Let events flow in: each one is classified, enriched and correlated before any reasoning starts
- Watch the four specialist agents run the lifecycle in parallel, with no prior training required
- Review each case when it reaches the ready-for-review stage, with its evidence and forensic report
- Approve or reject the prioritised recommendations, tagged technical, human or escalation
- Let the system fold each closed case and identified campaign back into your institutional memory
Pros & Cons
Pros
- A case is assessed in under five minutes, against a stated industry baseline of four to five hours
- Every event is investigated rather than a sample, so backlogs do not accumulate
- Output is built for regulatory review: explainable, auditable and replayable
- Correlation works at campaign level, not only case by case
- Reports are delivered in the analyst's working language, with three languages shown
- Single-tenant deployment keeps customer data out of any shared graph
- The vendor is an established one, active since 2014, with a 10 million euro round raised in 2023
Cons
- No price, plan, free tier or trial is published, so the cost cannot be compared or budgeted
- Access is restricted: Cleafy states it is onboarding selected institutions only
- The site is a single page, with no product documentation, no API and no technical reference
- No legal document is specific to Nyx: both the privacy policy and the terms of use cover cleafy.com
- No data processing agreement, subprocessor list, hosting location or certification is published for Nyx
- Every performance figure is vendor-stated, with no independent source or audit cited
- Customer references and testimonials are anonymised, so they cannot be checked
Pricing & Plans
Nyx has no published pricing. Cleafy states neither a permanent free plan nor a free trial, and no amount, currency or billing unit appears anywhere on the site; the structured data on the page carries an offer with an availability status but no price, and the pricing path returns a genuine 404. Commercial terms are arranged through the sales contact form alone, so no entry price can be stated.
Data, GDPR & hosting
A consolidated view of how Nyx handles your data.
GDPR overview
The GDPR is applied explicitly, though the published material covers the corporate website rather than the Nyx service. The controller, Cleafy Spa, is established in Milan, so no Article 27 representative is named or needed, and no data protection officer is designated. The privacy policy carries a dedicated section on user rights under the GDPR: withdrawal of consent, objection, access, verification and rectification, restriction, erasure, portability and complaint to a supervisory authority. The Nyx contact form collects marketing consent under Article 13 GDPR, and the website terms of use place the relationship under Italian law with the Court of Milan holding exclusive jurisdiction. No data processing agreement, subprocessor list or security certification is published for Nyx itself.
Who owns the data?
No product-level clause on data ownership is published. The only privacy document Cleafy links from the Nyx page is its iubenda policy, which is titled the privacy policy of www.cleafy.com and governs website visitors rather than the Nyx service. It names Cleafy Spa, Via Meravigli 16, 20123 Milan, as owner and data controller, reachable at privacy@cleafy.com, and was last updated on 9 April 2026. On the product side the single statement is architectural: Nyx runs single-tenant and, in Cleafy's words, customer data never touches a shared graph. Cleafy's SaaS terms of service exist but sit inside a trust centre that cannot be opened publicly, so the contractual position on ownership remains undisclosed.
Reuse rights
Nothing in the published documents grants or restricts an end user's right to reuse the output. On the product side, Cleafy states that Nyx builds knowledge of each institution's own threat landscape, that it does not rely on a generic model trained on industry data, and that it sharpens with every case closed and campaign identified, all within a single-tenant deployment. Whether customer data ever feeds the vendor's own models is never addressed. The website privacy policy covers a different perimeter altogether, listing purposes such as analytics, contact management, remarketing, advertising, tag management and session recording for visitors to the corporate site; marketing consent on the Nyx form is collected under Article 13 GDPR and can be withdrawn by writing to privacy@cleafy.com.
Data retention & training
Hosting summary
Cleafy publishes no hosting location for Nyx. Neither a country nor a region is named, and no cloud provider is identified for the service. The only architectural statement is that deployment is single-tenant and that customer data never touches a shared graph; the structured data on the page describes the operating system simply as cloud. The marketing site itself resolves to a Google anycast address, which says nothing about where customer data lives. The processing locations that do appear in Cleafy's privacy policy — the United States, Ireland and Malta — belong to third-party trackers on the corporate website, not to the Nyx platform, and should not be read as hosting jurisdictions for banking data. Since the controller is established in Milan and the terms of use place the relationship under Italian law with the Court of Milan competent, the governing jurisdiction is Italian even though the physical hosting is undisclosed.
Things to keep in mind
Risks and trade-offs to weigh before adopting Nyx.
- Automation bias: when a system hands over a finished assessment and an approve or reject button, reviewers tend to confirm rather than examine, and a wrong recommendation can be waved through
- Skill erosion: if analysts stop reconstructing attack chains themselves, the institution slowly loses the expertise it needs on the day the system is wrong or unavailable
- Unverified claims: every performance figure comes from the vendor, with no independent audit and with customer references anonymised, so the business case rests on trust
- Undocumented data terms: no data processing agreement, subprocessor list or hosting jurisdiction is published for Nyx, and the legal documents that do exist govern the corporate website instead
- Unclear training boundary: the system is said to learn from your own environment inside a single tenant, but nothing states whether customer data ever informs the vendor's own models
- Vendor lock-in: Nyx is shown consuming events from Cleafy's Fraud xDR platform, so adopting it is a commitment to a single supplier's stack
- Opaque decisions on real people: recommendations freeze accounts and contact customers, so an incorrect correlation has an immediate effect on someone's access to their money
Setup & Integrations
Technical difficulty
There is no self-service path: setup begins with a sales conversation, and Cleafy says it replies within 48 hours. Deployment is single-tenant at the institution, and the event feed comes from Cleafy's own Fraud xDR platform, so the practical prerequisite is that platform rather than a generic integration. Cleafy states the agents need no prior training and start producing complete assessments immediately. Beyond that, nothing is documented: no integration guide, no API and no technical reference is published, so the real effort cannot be judged from outside.
Deployment
Supported languages
Behind Nyx
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What are Autonomous Fraud Operations?
How is Nyx different from fraud automation or an analyst co-pilot?
How long does a full fraud assessment take?
Can Nyx detect coordinated fraud campaigns?
What kinds of fraud does it cover?
How much does Nyx cost?
Is my data mixed with other customers' data?
In which languages are the reports produced?
Is there a public API or a mobile app?
Should you pick Nyx?
Nyx is a narrow, serious product rather than a general-purpose assistant. It addresses a real and well-described problem — fraud teams whose throughput is capped by analyst hours — and its answer is coherent: structure the evidence first, let four specialist agents run the lifecycle in parallel, and hand the analyst a complete assessment instead of another alert to open. The emphasis on explainable, auditable and replayable output is the right instinct for a regulated buyer, and the single-tenant stance will matter to any bank that has read a shared-model clause carefully.
The reservations are about evidence rather than design. Every headline figure — under five minutes, seventy-seven times faster, two million protected users, fifteen days of campaign lead time — comes from Cleafy alone, with no independent source, no audit and anonymised customer references. The product is also very young in public terms: production is dated December 2025 and the site itself first appeared online in April 2026.
The bigger gap is documentary. Nyx has no legal documents of its own: the privacy policy and the terms of use both state that they cover cleafy.com, and the SaaS terms sit behind a trust centre that will not open to the public. No data processing agreement, no subprocessor list, no hosting jurisdiction and no security certification is published for Nyx, and no price of any kind is disclosed. For the institutions being targeted, none of that is fatal — these things are normally settled in procurement — but it does mean nothing material can be assessed before talking to the vendor. Behind the product stands a credible company: Cleafy has operated since 2014 from Milan, raised 10 million euros in 2023 and sells a second product to the same market.
- Choosing a selection results in a full page refresh.
- Opens in a new window.