Trapets logo
Security Fraud · Gov Legal

Trapets

Case management is the investigation module of Trapets' Instantwatch platform. It gathers transaction monitoring, screening, KYC and trade surveillance alerts into one case queue, then uses explainable AI to rank them for compliance teams in regulated financial institutions.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Trapets?

Case management is the investigation layer of Instantwatch, the modular financial crime platform built by the Swedish vendor Trapets AB. Instantwatch also carries transaction monitoring, customer and company screening, KYC and due diligence, and market and trade surveillance; case management is what ties them together. Whether a compliance officer is looking at a payment, a sanctions hit, an onboarding file or a suspicious trade, every alert lands in the same interface and is automatically classified into a case structure, so that prioritisation and hand-offs happen in one place instead of four.

The ranking is done by AI. Trapets says its models learn from past case outcomes and risk patterns to surface the alerts most likely to matter, and it insists the AI is fully explainable, audit-ready and aligned with regulatory expectations for responsible use in financial services. That framing matters in this market: a bank has to justify to a supervisor why an alert was closed, so a black-box score would be unusable. Configurable rules sit alongside the models, and every recommendation stays reviewable.

The investigation tools are what an analyst actually works in. Customer profiles consolidate real-time risk scores, historical alert and KYC data, and connected identifiers such as accounts, aliases and jurisdictions. Network mapping draws the links between customers, transactions and trades across counterparties, timelines and geographies. For high-volume environments there are full audit trails and case logs, shared analysis and escalation workflows, and filtering and sorting for bulk alert review. Alerts arrive either in real time or in T+1 batch mode. Role-specific dashboards give each team member their own widgets, KPIs and queues, and the module exposes ready-to-integrate APIs for external systems.

Behind it sits an established vendor: founded in Sweden in 2000, around 80 staff in Stockholm and Hanoi, more than 500 customers, ISO 27001 certified since 2018, and customer data held in Swedish data centres.

What it does

  • Centralise alerts from transaction monitoring, screening, KYC and trade surveillance in one case queue
  • Rank alerts automatically with explainable AI trained on past case outcomes
  • Investigate a customer from a consolidated profile carrying real-time risk scores and full alert history
  • Map the network of links between customers, transactions and trades by counterparty, timeline and geography
  • Handle alerts in real time or in T+1 batch mode, depending on the regulatory requirement
  • Evidence every step with complete audit logs, case notes and escalation workflows
  • Feed dashboards and external systems through ready-to-integrate APIs
Audience

When to use Trapets / When not to

A quick filter to help you decide if Trapets is the right fit.

When to use Trapets

  • Compliance and AML officers at banks, credit institutions and payment service providers who must investigate alerts across several risk areas at once
  • Financial crime investigators drowning in alert volume who need automatic case triage and network mapping to find the files that matter
  • Market abuse and trade surveillance teams at investment firms and trading venues that have to evidence every review to a regulator
  • KYC and onboarding teams running continuous customer due diligence who want screening results, risk scores and case history on a single customer profile
  • Nordic and EU institutions preparing for AMLR, MAR and DORA that need Swedish data residency and an auditable trail behind every AI recommendation

When not to use Trapets

  • Small firms that need a published price before they will talk to a vendor: nothing is priced anywhere on the site
  • Anyone hoping to sign up and start today: there is no self-service account, no free plan and no free trial, only a sales conversation
  • Buyers who want to read the contract first: Trapets publishes no terms of service, no EULA and no standalone DPA
  • Developers who want to evaluate the API before committing: the developer portal is password protected and the password comes from support
  • Teams looking for a mobile or desktop client: the product is delivered as a web platform and an API, nothing else
  • Organisations outside the regulated financial sector looking for a general-purpose case tracker rather than an AML and market abuse tool
Get started

How to use Trapets

A typical end-to-end flow, from setup to results.

  1. Start from the product page and request a demonstration or a consultation through the form; there is no self-service sign-up
  2. Discuss scope with the sales team, since case management is not sold on its own but as part of the Instantwatch platform
  3. Agree the commercial terms and the data processing agreement, which Trapets supplies in its own template unless another form is negotiated
  4. Work through the implementation and onboarding process that Trapets documents as a dedicated stage
  5. Connect your source systems, either through the web platform or directly via the API
  6. Configure detection rules, case structures and deletion routines to match your own risk model and retention policy
  7. Set up role-specific dashboards, widgets and KPIs for each member of the compliance team
  8. Choose real-time or T+1 batch alert delivery according to your regulatory obligations
  9. Request a developer portal password from support if your team needs the data input specifications and API documentation
  10. Use the Zendesk support portal for day-to-day tickets, and the support phone line to escalate an existing ticket during business hours
Quick read

Pros & Cons

Pros

  • One case file across four risk areas, where many compliance teams still juggle a separate tool per area
  • AI positioned for regulatory scrutiny rather than raw accuracy: explainable, audit-ready and paired with configurable rules
  • Customer data held in Swedish data centres, with processing contractually limited to the EU and EEA unless otherwise agreed in writing
  • ISO 27001 certified since 2018, recertified in 2024 and valid to 2027, with documented annual audits, penetration tests and disaster recovery tests
  • Unusually open trust centre: an annual 22-page vendor audit report, the full data protection policy and a DORA note, all downloadable
  • Established vendor with a long track record, more than 500 customers and named references including DNB Carnegie, Norsk Tipping, Kraft Bank and Safello
  • Choice of real-time or T+1 alert handling, plus managed services for teams that would rather not run surveillance themselves

Cons

  • No public pricing at all: no pricing page, no plans and not a single amount anywhere on the site or in its documents
  • No published terms of service, general conditions or EULA, so the contractual detail only appears during negotiation
  • No free plan and no free trial, and no way to sign up without going through sales
  • Developer documentation sits behind a password, so the API cannot be evaluated before becoming a customer
  • No subprocessor list is published; the vendor audit report defers additional subcontractor information to a request
  • No opt-out from model training is documented, even though the product page says the AI models learn from past case outcomes
  • No interface languages are declared, and there is no mobile or desktop client
Pricing

Pricing & Plans

Trapets does not publish any pricing for case management or for the Instantwatch platform. There is no pricing page, and none exists in the site's three sitemaps; around twenty likely pricing paths were tested and all returned a clean 404; and no monetary amount in any currency appears on the site's pages or in the trust centre documents. No free plan and no free trial are advertised. The stated route to a figure is the contact form: the site invites visitors interested in solutions, features and pricing to fill it in so that the team can reach out. Pricing should therefore be treated as quotation-based, and any figure will come from a sales conversation rather than from a published rate card.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Trapets handles your data.

GDPR overview

GDPR alignment is claimed explicitly and repeatedly: Trapets says it operates in line with EU frameworks including GDPR, DORA, EBA and ESMA. A Data Protection Officer is named and reachable at dpo@trapets.com, and a published data protection policy, approved in version 1.2 on 19 December 2025, describes the processor safeguards. Trapets is established in Sweden, so no Article 27 representative is required and none is designated. The named supervisory authority is the Swedish IMY, and the policy points readers to their own national authority as an alternative. Rectification, erasure, access, restriction and objection rights are all documented. A data processing agreement is part of the customer contract, in Trapets' own template unless otherwise agreed. Trapets itself has been ISO 27001 certified since 2018.

Who owns the data?

For everything processed inside the platform, Trapets acts as a processor and each customer remains the controller under the GDPR. Trapets states plainly that as a processor it does not determine the scope or the purposes of that processing, which is instead governed by the customer contract, the data processing agreement and the controller's own instructions. Trapets does own the software: it says it developed and owns all rights to the Instantwatch platform, which is a claim over the product and not over customer records. Trapets becomes a controller only for its own peripheral processing, namely website business contacts, the Zendesk support portal, e-learning and recruitment, and to a limited extent for screening data.

Reuse rights

Customer data is used only to deliver the service and meet contractual obligations, following the controller's instructions under the data processing agreement. Customers therefore do not need Trapets' permission to use their own records; conversely, Trapets does not grant itself a general right to reuse them. Screening data is a separate case: it is supplied for the customer's AML and counter-terrorist financing obligations and is delivered as is, so verifying its quality falls on the customer. One point is left open. The product page says the AI models learn from past case outcomes and risk patterns, but no page states whether that learning stays inside a single customer's tenant or is pooled, and no opt-out from model training is documented anywhere.

Data retention & training

Retention summary
Trapets keeps personal data no longer than its purpose or legal requirements demand, and no fixed number of days or months is published. Inside the products, the retention period is effectively set by the customer: depending on the product, Trapets offers a standard configuration and lets each controller define customised deletion routines or request ad hoc deletion in line with its own retention policy. When a contract ends, customer data is deleted or anonymised so that it cannot be recovered or linked back to a person or entity. Business contact data is held for the duration of the customer relationship and a reasonable period after it, and for prospects for as long as it is considered relevant. Screening data is continuously updated and not kept beyond its purpose. Data no longer needed is securely destroyed.
Trains on customer data
Unclear
DPA available
Yes
GDPR contact

Hosting summary

Trapets states that all customer data is stored in Swedish data centres meeting European standards. Hosting runs through a named partner, Iver Sverige AB, which also supplies a security operations centre as a service. The data centres are geographically separated and subject to recurring audits carried out by Trapets together with that partner. The vendor audit report adds that all data centres sit within the EU and are ISO 27001 certified and SOC II compliant, though those two certifications belong to the hosting partner rather than to Trapets. The data protection policy is firmer still: unless otherwise agreed in writing, personal data processed by Trapets as a processor is stored and processed only within the EU and EEA area, and any transfer to a third country must use a valid GDPR mechanism. Support portal data held in Zendesk is also stated to be stored within the EU. Trapets has an office in Hanoi, but says service delivery is performed from Sweden only. One distinction is worth keeping: the public website itself resolves to a server in Frankfurt, Germany, which says nothing about where customer data lives.

Hosting countries
🇸🇪 Sweden
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Trapets.

  • Nothing about the commercial terms is public: no price, no plans and no terms of service, so cost and contract only become visible inside a negotiation
  • Screening data is supplied as is, and the data protection policy places the duty to check its quality on the customer, not on Trapets
  • The AI models are said to learn from past case outcomes, but the site never says whether learning is isolated per customer, and no training opt-out is documented
  • No subprocessor list is published; additional subcontractor information is only made available on request
  • Attribution deserves care: the ISO 27001 certification is genuinely Trapets', but the SOC II compliance and ISO 27001 status quoted for the data centres belong to the hosting partner Iver Sverige AB
  • AMLR, MAR, DORA, 6AMLD, MiCA and the EBA and ESMA guidelines are the rules the software helps customers meet and the obligations of the client institutions; they are not authorisations held by Trapets
  • Automated ranking can quietly become the decision: an explainable score is still a score, and a team that stops reading deprioritised alerts has moved its risk rather than reduced it
Setup

Setup & Integrations

Technical difficulty

Moderate to high, and driven by integration rather than by the software itself. The product is delivered as SaaS with nothing to install, reached through a web platform or an API, but it has to be wired into core banking, payment or trading systems and fed data that matches published input specifications. Trapets documents a dedicated implementation and onboarding stage, and expects real configuration work: detection rules, role-specific dashboards and customised deletion routines are all set by the customer, with what the vendor calls full configuration freedom and in-house specialists in support. Managed services are available for teams that would rather not operate it themselves.

Deployment

Web appAPI

Integrations

Dow Jones Acuris Risk Intelligence ThreatFabric
Company

Behind Trapets

Company name
Trapets AB
Founded
INFORMATION_NOT_FOUND
Country of origin
🇸🇪 Sweden
Headquarters
Kungsgatan 56, 111 22 Stockholm, Sweden
UBO
Monterro
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
INFORMATION_NOT_FOUND

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What is Trapets Case management?
It is the investigation and case management module of Instantwatch, the financial crime platform built by Trapets AB. It centralises alerts from transaction monitoring, screening, KYC and trade surveillance into a single case structure so compliance teams can prioritise and investigate in one place.
Which risk areas does it cover?
Four: transaction monitoring, customer and company screening against sanctions, PEP, RCA and UBO data, KYC and due diligence workflows, and market abuse and trade surveillance.
How does the AI prioritise alerts, and is it auditable?
The models learn from past case outcomes and risk patterns to surface the alerts most likely to be relevant. Trapets states the AI is fully explainable, audit-ready and aligned with regulatory expectations, and it sits alongside configurable rules with clear audit trails.
Is there an API?
Yes. The product page advertises ready-to-integrate APIs and the screening pages invite customers to connect directly via API. Trapets runs a developer portal at devportal.instantwatch.net, which its data protection policy calls the Trapets documentation site. The portal is password protected and the support team issues the password on request.
How much does it cost?
No price is published anywhere. There is no pricing page, no plans and no amount on the site or in its trust centre documents. Pricing is obtained by contacting the sales team through the demo form.
Is there a free trial or a free plan?
Neither is advertised. Nothing on the site mentions a free trial, a free tier or a trial period, and there is no self-service sign-up.
Where is customer data hosted?
In Swedish data centres, through the hosting partner Iver Sverige AB. The data protection policy adds that, unless otherwise agreed in writing, personal data processed by Trapets as a processor is stored and processed only within the EU and EEA.
Is Trapets certified?
Trapets has been ISO 27001 certified since 2018, was recertified in 2024, and its certification runs to 2027 with annual surveillance audits. Note that the SOC II compliance and ISO 27001 status mentioned for the data centres belong to the hosting partner, not to Trapets.
What is Trapets' role under the GDPR?
Processor. Each customer remains the controller and defines the scope and purposes of processing, which is governed by a data processing agreement included in the customer contract. Trapets names a Data Protection Officer, reachable at dpo@trapets.com.
Who is behind the product?
Trapets AB, registered in Sweden under company number 556586-4773 at Kungsgatan 56, 111 22 Stockholm, founded in Sweden in 2000, with around 80 employees across Stockholm and Hanoi. The company states it is majority owned by Monterro, a Nordic private equity firm, with minority ownership held by founders and employees.
Conclusion

Should you pick Trapets?

Trapets Case management is a serious, narrowly aimed product from a vendor that has been in financial crime prevention since 2000. Its central idea is sound and increasingly rare: one case file for four risk areas, so a compliance team stops re-investigating the same customer in four different tools. The supporting features are the ones investigators actually ask for, namely consolidated customer profiles, network mapping, real-time or T+1 delivery, and audit trails on everything.

The AI is presented the way this market requires. Trapets does not claim the highest detection rate; it claims explainability, audit-readiness and regulatory defensibility, with configurable rules alongside the models. For a bank that has to justify a closed alert to a supervisor, that emphasis is the right one.

The security posture is genuinely transparent. Swedish data centres, EU and EEA processing written into the data protection policy, ISO 27001 since 2018, and an annual vendor audit report published in full are more than most vendors in this space offer without an NDA.

The commercial posture is the opposite. There is no price, no plan, no free trial, no published terms of service, and the API documentation is behind a password. A buyer cannot evaluate cost, contract or integration effort without entering a sales cycle, and that is a real filter: this product is bought by institutions with a procurement process, not by teams comparing tools on a Friday afternoon.

One question is left open. The product page says the AI models learn from past case outcomes, but nothing states whether that learning is kept per customer, and no training opt-out is documented. For regulated buyers, that is worth putting on the due diligence list.