Trapets
Case management is the investigation module of Trapets' Instantwatch platform. It gathers transaction monitoring, screening, KYC and trade surveillance alerts into one case queue, then uses explainable AI to rank them for compliance teams in regulated financial institutions.
What is Trapets?
Case management is the investigation layer of Instantwatch, the modular financial crime platform built by the Swedish vendor Trapets AB. Instantwatch also carries transaction monitoring, customer and company screening, KYC and due diligence, and market and trade surveillance; case management is what ties them together. Whether a compliance officer is looking at a payment, a sanctions hit, an onboarding file or a suspicious trade, every alert lands in the same interface and is automatically classified into a case structure, so that prioritisation and hand-offs happen in one place instead of four.
The ranking is done by AI. Trapets says its models learn from past case outcomes and risk patterns to surface the alerts most likely to matter, and it insists the AI is fully explainable, audit-ready and aligned with regulatory expectations for responsible use in financial services. That framing matters in this market: a bank has to justify to a supervisor why an alert was closed, so a black-box score would be unusable. Configurable rules sit alongside the models, and every recommendation stays reviewable.
The investigation tools are what an analyst actually works in. Customer profiles consolidate real-time risk scores, historical alert and KYC data, and connected identifiers such as accounts, aliases and jurisdictions. Network mapping draws the links between customers, transactions and trades across counterparties, timelines and geographies. For high-volume environments there are full audit trails and case logs, shared analysis and escalation workflows, and filtering and sorting for bulk alert review. Alerts arrive either in real time or in T+1 batch mode. Role-specific dashboards give each team member their own widgets, KPIs and queues, and the module exposes ready-to-integrate APIs for external systems.
Behind it sits an established vendor: founded in Sweden in 2000, around 80 staff in Stockholm and Hanoi, more than 500 customers, ISO 27001 certified since 2018, and customer data held in Swedish data centres.
What it does
- Centralise alerts from transaction monitoring, screening, KYC and trade surveillance in one case queue
- Rank alerts automatically with explainable AI trained on past case outcomes
- Investigate a customer from a consolidated profile carrying real-time risk scores and full alert history
- Map the network of links between customers, transactions and trades by counterparty, timeline and geography
- Handle alerts in real time or in T+1 batch mode, depending on the regulatory requirement
- Evidence every step with complete audit logs, case notes and escalation workflows
- Feed dashboards and external systems through ready-to-integrate APIs
When to use Trapets / When not to
A quick filter to help you decide if Trapets is the right fit.
When to use Trapets
- Compliance and AML officers at banks, credit institutions and payment service providers who must investigate alerts across several risk areas at once
- Financial crime investigators drowning in alert volume who need automatic case triage and network mapping to find the files that matter
- Market abuse and trade surveillance teams at investment firms and trading venues that have to evidence every review to a regulator
- KYC and onboarding teams running continuous customer due diligence who want screening results, risk scores and case history on a single customer profile
- Nordic and EU institutions preparing for AMLR, MAR and DORA that need Swedish data residency and an auditable trail behind every AI recommendation
When not to use Trapets
- Small firms that need a published price before they will talk to a vendor: nothing is priced anywhere on the site
- Anyone hoping to sign up and start today: there is no self-service account, no free plan and no free trial, only a sales conversation
- Buyers who want to read the contract first: Trapets publishes no terms of service, no EULA and no standalone DPA
- Developers who want to evaluate the API before committing: the developer portal is password protected and the password comes from support
- Teams looking for a mobile or desktop client: the product is delivered as a web platform and an API, nothing else
- Organisations outside the regulated financial sector looking for a general-purpose case tracker rather than an AML and market abuse tool
How to use Trapets
A typical end-to-end flow, from setup to results.
- Start from the product page and request a demonstration or a consultation through the form; there is no self-service sign-up
- Discuss scope with the sales team, since case management is not sold on its own but as part of the Instantwatch platform
- Agree the commercial terms and the data processing agreement, which Trapets supplies in its own template unless another form is negotiated
- Work through the implementation and onboarding process that Trapets documents as a dedicated stage
- Connect your source systems, either through the web platform or directly via the API
- Configure detection rules, case structures and deletion routines to match your own risk model and retention policy
- Set up role-specific dashboards, widgets and KPIs for each member of the compliance team
- Choose real-time or T+1 batch alert delivery according to your regulatory obligations
- Request a developer portal password from support if your team needs the data input specifications and API documentation
- Use the Zendesk support portal for day-to-day tickets, and the support phone line to escalate an existing ticket during business hours
Pros & Cons
Pros
- One case file across four risk areas, where many compliance teams still juggle a separate tool per area
- AI positioned for regulatory scrutiny rather than raw accuracy: explainable, audit-ready and paired with configurable rules
- Customer data held in Swedish data centres, with processing contractually limited to the EU and EEA unless otherwise agreed in writing
- ISO 27001 certified since 2018, recertified in 2024 and valid to 2027, with documented annual audits, penetration tests and disaster recovery tests
- Unusually open trust centre: an annual 22-page vendor audit report, the full data protection policy and a DORA note, all downloadable
- Established vendor with a long track record, more than 500 customers and named references including DNB Carnegie, Norsk Tipping, Kraft Bank and Safello
- Choice of real-time or T+1 alert handling, plus managed services for teams that would rather not run surveillance themselves
Cons
- No public pricing at all: no pricing page, no plans and not a single amount anywhere on the site or in its documents
- No published terms of service, general conditions or EULA, so the contractual detail only appears during negotiation
- No free plan and no free trial, and no way to sign up without going through sales
- Developer documentation sits behind a password, so the API cannot be evaluated before becoming a customer
- No subprocessor list is published; the vendor audit report defers additional subcontractor information to a request
- No opt-out from model training is documented, even though the product page says the AI models learn from past case outcomes
- No interface languages are declared, and there is no mobile or desktop client
Pricing & Plans
Trapets does not publish any pricing for case management or for the Instantwatch platform. There is no pricing page, and none exists in the site's three sitemaps; around twenty likely pricing paths were tested and all returned a clean 404; and no monetary amount in any currency appears on the site's pages or in the trust centre documents. No free plan and no free trial are advertised. The stated route to a figure is the contact form: the site invites visitors interested in solutions, features and pricing to fill it in so that the team can reach out. Pricing should therefore be treated as quotation-based, and any figure will come from a sales conversation rather than from a published rate card.
Data, GDPR & hosting
A consolidated view of how Trapets handles your data.
GDPR overview
GDPR alignment is claimed explicitly and repeatedly: Trapets says it operates in line with EU frameworks including GDPR, DORA, EBA and ESMA. A Data Protection Officer is named and reachable at dpo@trapets.com, and a published data protection policy, approved in version 1.2 on 19 December 2025, describes the processor safeguards. Trapets is established in Sweden, so no Article 27 representative is required and none is designated. The named supervisory authority is the Swedish IMY, and the policy points readers to their own national authority as an alternative. Rectification, erasure, access, restriction and objection rights are all documented. A data processing agreement is part of the customer contract, in Trapets' own template unless otherwise agreed. Trapets itself has been ISO 27001 certified since 2018.
Who owns the data?
For everything processed inside the platform, Trapets acts as a processor and each customer remains the controller under the GDPR. Trapets states plainly that as a processor it does not determine the scope or the purposes of that processing, which is instead governed by the customer contract, the data processing agreement and the controller's own instructions. Trapets does own the software: it says it developed and owns all rights to the Instantwatch platform, which is a claim over the product and not over customer records. Trapets becomes a controller only for its own peripheral processing, namely website business contacts, the Zendesk support portal, e-learning and recruitment, and to a limited extent for screening data.
Reuse rights
Customer data is used only to deliver the service and meet contractual obligations, following the controller's instructions under the data processing agreement. Customers therefore do not need Trapets' permission to use their own records; conversely, Trapets does not grant itself a general right to reuse them. Screening data is a separate case: it is supplied for the customer's AML and counter-terrorist financing obligations and is delivered as is, so verifying its quality falls on the customer. One point is left open. The product page says the AI models learn from past case outcomes and risk patterns, but no page states whether that learning stays inside a single customer's tenant or is pooled, and no opt-out from model training is documented anywhere.
Data retention & training
Hosting summary
Trapets states that all customer data is stored in Swedish data centres meeting European standards. Hosting runs through a named partner, Iver Sverige AB, which also supplies a security operations centre as a service. The data centres are geographically separated and subject to recurring audits carried out by Trapets together with that partner. The vendor audit report adds that all data centres sit within the EU and are ISO 27001 certified and SOC II compliant, though those two certifications belong to the hosting partner rather than to Trapets. The data protection policy is firmer still: unless otherwise agreed in writing, personal data processed by Trapets as a processor is stored and processed only within the EU and EEA area, and any transfer to a third country must use a valid GDPR mechanism. Support portal data held in Zendesk is also stated to be stored within the EU. Trapets has an office in Hanoi, but says service delivery is performed from Sweden only. One distinction is worth keeping: the public website itself resolves to a server in Frankfurt, Germany, which says nothing about where customer data lives.
Things to keep in mind
Risks and trade-offs to weigh before adopting Trapets.
- Nothing about the commercial terms is public: no price, no plans and no terms of service, so cost and contract only become visible inside a negotiation
- Screening data is supplied as is, and the data protection policy places the duty to check its quality on the customer, not on Trapets
- The AI models are said to learn from past case outcomes, but the site never says whether learning is isolated per customer, and no training opt-out is documented
- No subprocessor list is published; additional subcontractor information is only made available on request
- Attribution deserves care: the ISO 27001 certification is genuinely Trapets', but the SOC II compliance and ISO 27001 status quoted for the data centres belong to the hosting partner Iver Sverige AB
- AMLR, MAR, DORA, 6AMLD, MiCA and the EBA and ESMA guidelines are the rules the software helps customers meet and the obligations of the client institutions; they are not authorisations held by Trapets
- Automated ranking can quietly become the decision: an explainable score is still a score, and a team that stops reading deprioritised alerts has moved its risk rather than reduced it
Setup & Integrations
Technical difficulty
Moderate to high, and driven by integration rather than by the software itself. The product is delivered as SaaS with nothing to install, reached through a web platform or an API, but it has to be wired into core banking, payment or trading systems and fed data that matches published input specifications. Trapets documents a dedicated implementation and onboarding stage, and expects real configuration work: detection rules, role-specific dashboards and customised deletion routines are all set by the customer, with what the vendor calls full configuration freedom and in-house specialists in support. Managed services are available for teams that would rather not operate it themselves.
Deployment
Integrations
Behind Trapets
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What is Trapets Case management?
Which risk areas does it cover?
How does the AI prioritise alerts, and is it auditable?
Is there an API?
How much does it cost?
Is there a free trial or a free plan?
Where is customer data hosted?
Is Trapets certified?
What is Trapets' role under the GDPR?
Who is behind the product?
Should you pick Trapets?
Trapets Case management is a serious, narrowly aimed product from a vendor that has been in financial crime prevention since 2000. Its central idea is sound and increasingly rare: one case file for four risk areas, so a compliance team stops re-investigating the same customer in four different tools. The supporting features are the ones investigators actually ask for, namely consolidated customer profiles, network mapping, real-time or T+1 delivery, and audit trails on everything.
The AI is presented the way this market requires. Trapets does not claim the highest detection rate; it claims explainability, audit-readiness and regulatory defensibility, with configurable rules alongside the models. For a bank that has to justify a closed alert to a supervisor, that emphasis is the right one.
The security posture is genuinely transparent. Swedish data centres, EU and EEA processing written into the data protection policy, ISO 27001 since 2018, and an annual vendor audit report published in full are more than most vendors in this space offer without an NDA.
The commercial posture is the opposite. There is no price, no plan, no free trial, no published terms of service, and the API documentation is behind a password. A buyer cannot evaluate cost, contract or integration effort without entering a sales cycle, and that is a real filter: this product is bought by institutions with a procurement process, not by teams comparing tools on a Friday afternoon.
One question is left open. The product page says the AI models learn from past case outcomes, but nothing states whether that learning is kept per customer, and no training opt-out is documented. For regulated buyers, that is worth putting on the due diligence list.
- Choosing a selection results in a full page refresh.
- Opens in a new window.