Vespia logo
Security Fraud · Gov Legal

Vespia

Vespia is an AI-powered AML compliance platform that combines business verification, identity checks, sanctions and PEP screening, risk scoring and continuous monitoring across more than 300 jurisdictions, delivered through a web dashboard and a GraphQL API.

Acquired GDPR compliant Free trial Subscription API available Verified by Guidaio
Overview

What is Vespia?

Vespia is an anti-money-laundering compliance platform built for organisations that have to verify other organisations. It brings KYB business verification, KYC identity verification, AML screening, customer onboarding, risk scoring, monitoring and reporting into a single workflow, so a compliance team does not have to stitch several vendors together to stay compliant.

The verification layer draws on commercial registers in more than 300 jurisdictions, backed by a claimed 5,000+ official sources and 1,500+ data points. A company lookup returns register information in under 30 seconds, along with original documents, corporate hierarchies and the identification of ultimate beneficial owners, shareholders and directors. Continuous UBO monitoring raises real-time alerts when an ownership structure changes.

Screening runs automatically on every entity attached to a company, checked against more than 4,000 PEP, sanctions and adverse-media lists, with smart filtering meant to cut false positives. On the individual side, KYC covers over 7,000 document types from more than 190 countries and territories, with liveness detection that asks the person to complete a task on camera.

Instead of long AML questionnaires, customers deploy Vespia's onboarding flow: ready KYB and KYC templates per jurisdiction, editable steps, logic and AML questions, and a white-label web SDK that embeds the flow into their own site. Risk scoring accepts the customer's own risk matrix and rules in a hybrid rule-based and AI approach, while Julia AI, presented as an AI AML compliance officer, offers guidance on smoothing the compliance process.

Monitoring works on three axes: KYB rechecks driven by the risk level set by the customer, daily PEP, sanctions and adverse-media screening, and alerts when an identity document expires. Results land in PDF and machine-readable reports with a full audit trail. Separate AI transaction monitoring detects suspicious activity.

Delivery is a web dashboard plus a GraphQL API with webhooks, so verification can be embedded in an existing system or CRM. The wider solution defined in the terms also covers Vespia Passport, a reusable business digital identity, and Compliance Officer as a Service, a network of certified compliance officers. Veriff has acquired Vespia and is folding its KYB technology into its own platform.

What it does

  • Pull commercial register information on a company from more than 300 jurisdictions in under 30 seconds
  • Map corporate hierarchies and identify ultimate beneficial owners, shareholders and directors
  • Screen every entity linked to a company against more than 4,000 PEP, sanctions and adverse-media lists
  • Verify the identity of founders and beneficial owners across 7,000+ document types with liveness detection
  • Score counterparty risk using your own risk matrix, with a hybrid of rules and AI
  • Monitor businesses, watchlists and document expiry continuously and raise alerts on changes
  • Produce PDF and machine-readable reports with a full audit trail for regulators
Audience

When to use Vespia / When not to

A quick filter to help you decide if Vespia is the right fit.

When to use Vespia

  • Compliance officers and AML analysts who onboard corporate customers across several jurisdictions
  • Banks, payment providers and crypto businesses that must screen companies and their stakeholders continuously
  • Accounting and audit firms running automated due diligence and AML checks on their clients
  • Developers integrating business and identity verification into an existing product or CRM through an API
  • Small and growing companies that need a ready-made AML programme rather than an in-house one

When not to use Vespia

  • Individuals and consumers: the platform is strictly business-to-business, with no personal plan
  • Teams needing a mobile app, since Vespia ships only a web dashboard and an API
  • Organisations requiring an interface or documentation in a language other than English
  • One-off users, because entry pricing starts at 99 EUR plus 35 EUR per KYB report
  • Buyers looking for a long-term standalone vendor, as Vespia has been acquired and folded into Veriff
Get started

How to use Vespia

A typical end-to-end flow, from setup to results.

  1. Create an account through the Vespia dashboard, or accept an invitation sent by Vespia
  2. Pick a solution package; a test account with limited features is available, for a period Vespia decides
  3. Load your own risk matrix and risk rules so that automated scoring reflects your policy
  4. Choose a ready KYB or KYC onboarding template for your jurisdiction
  5. Edit the steps, logic and AML questions, then brand the flow and embed it with the white-label web SDK
  6. Run a KYB check by submitting a company name, registration code and country code
  7. For API use, create a development account, obtain a token through the signIn mutation and send the required Origin header
  8. Refresh the access token every ten minutes, then switch to the production endpoints when you go live
  9. Subscribe to webhooks so verification updates reach your system in real time
  10. Review cases and alerts in the dashboard and export PDF or machine-readable reports with the audit trail
Quick read

Pros & Cons

Pros

  • Unusually broad coverage: 300+ jurisdictions, 5,000+ official sources and 7,000+ identity document types
  • The whole chain in one tool, from company lookup to screening, onboarding, scoring, monitoring and reporting
  • Public and detailed API documentation, with an Apollo playground, webhooks and a per-zone country coverage table
  • Rare legal transparency: a published DPA and a named list of eleven sub-processors
  • EU-based publisher, with AWS hosting and data stored in the EU by default
  • Entry price shown publicly, with a seven-day free trial and no seat limit on the starter package
  • Genuine customisation: your own risk matrix, editable onboarding templates and white-label branding

Cons

  • The tool has been acquired: Vespia OÜ was struck from the Estonian register in June 2026 and the site is now a shop window
  • Most pages, including contact, products, blog and careers, redirect to Veriff
  • Pricing is only partly public: one priced package, no billing period stated, nothing above it
  • The terms and conditions date from February 2023 and have not been revised since
  • No documented way to exclude customer data from model training
  • The terms allow aggregated and anonymised use of customer data for product development, and hand all feedback to the vendor
  • Support runs only 9am to 5pm Estonian time on weekdays, in English only, with no mobile app
Pricing

Pricing & Plans

There is no permanent free plan. The only publicly priced offer is the Starter Package at 99 EUR, to which KYB reports are added at 35 EUR per report depending on the region. No billing period is stated next to the amount. A seven-day free trial is offered, and the Pro Plan is quoted commercially rather than published. Prices are exclusive of tax, and any change requires three months' notice.

Plan 1
  • Starter Package — 99 EUR
  • described as AML support for startups and small businesses
  • with global KYB coverage
  • unlimited users
  • official business registry and database information
  • directors
  • shareholders and UBOs where available
  • company and stakeholder sanctions
Plan 3
  • Test Account — limited feature access
  • for a free period that Vespia sets at its discretion
Plan 4
  • Special Terms — a separate signed agreement for extra solutions
  • extra verification volume or extra support
  • with a possible setup fee for customisation and white labelling
Special offers — Discounts or other bonuses may be granted, for example in exchange for referring your own clients, with the detailed terms communicated by email
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Vespia handles your data.

GDPR overview

GDPR implementation is concrete and documented. The publisher is established in Estonia, so it falls directly under the regulation. The privacy policy is built around GDPR terms, names legitimate interest as the legal basis for processing client contacts, lists the rights of access, rectification, erasure, restriction and objection with a 30-day response window, and names the Estonian Data Protection Inspectorate as the supervisory authority. A Data Processing Agreement concluded under Article 28 is published as Appendix 1 to the terms, with a schedule of technical and organisational measures. Transfers outside the EU are limited to GDPR Chapter V conditions, and Standard Contractual Clauses are cited for the Australian screening provider. Sub-processor changes are notified by email with a seven-day objection window. No Article 27 representative is designated, and none is required.

Who owns the data?

Ownership is split. The customer keeps its Client Data and stays solely responsible for its lawfulness, quality and accuracy; under the Data Processing Agreement the customer is the controller and Vespia the processor acting on instruction. Vespia keeps exclusive intellectual property over the platform itself and grants only a limited, non-exclusive, non-transferable licence for the duration of the contract. Two clauses shift value the other way: any feedback a customer gives becomes Vespia's exclusive property with an irrevocable assignment of rights, and Vespia may use Client Data in aggregated or anonymised form for internal analysis, marketing and product development. Customers can export their data as PDF from the dashboard within one month of termination.

Reuse rights

Verification results are the customer's to use inside its own AML process: PDF reports, machine-readable reports and a full audit trail can be pulled from the dashboard, requested through the API, or asked for by email. No further permission from Vespia is needed for that operational reuse. The limits are legal rather than contractual: the customer must hold an appropriate legal basis for every search it runs, and Vespia disclaims responsibility for the accuracy or completeness of information coming from commercial registers, PEP and sanctions lists and adverse-media databases. The final decision on any verified company or person stays with the customer, and Vespia explicitly declines to advise whether the information obtained is sufficient. After termination, a history extract can be requested, and Vespia may charge for it. Accepting the terms also lets Vespia use the customer's name and logo in its own marketing materials.

Data retention & training

Retention summary
User account data is kept for as long as the account is active, plus up to one year of inactivity. Invoicing records and their supporting documents are kept for seven years to meet legal obligations, and information on legal transactions with a client is kept for the civil limitation period, three years, or ten years in case of intentional breach. Data may also be kept indefinitely in aggregated or anonymised form for analysis and statistics. Customer data uploaded through the service is retained for the period attached to the chosen package, and on termination it is made impersonal or obfuscated through one-way operations that prevent re-identification, unless law requires longer storage. Customers can export their data as PDF within one month of termination, and an unpaid invoice leads to account deletion after three months.
Trains on customer data
Unclear
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Hosting runs entirely on Amazon Web Services, described in the Data Processing Agreement as a single strategic infrastructure, storage and database partner, with the statement that data never leaves AWS servers and that customer data may not be stored outside that partner's infrastructure. By default data is stored in the EU unless otherwise agreed, and the privacy policy states that personal data is processed within the European Economic Area as a rule, with any transfer outside it following GDPR requirements. Transfers outside the EU are limited to Chapter V conditions, and Standard Contractual Clauses are cited for the Australian screening provider NameScan. The published technical measures include encryption in transit and at rest, role-based access control, access logging, logical separation of client data and separated test, development and production environments. One point of attribution matters: the ISO 27001, 27017 and 27018 certifications and the SOC and CSA STAR reports listed in the agreement belong to the hosting provider, not to the publisher, which claims no certification of its own.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Vespia.

  • The product has been acquired and the site is being dismantled: expect service discontinuity and a forced migration to Veriff
  • Results depend on third-party sources, and the vendor explicitly disclaims responsibility for the accuracy of registers, watchlists and adverse-media databases
  • Automated scores invite over-confidence: the risk matrix is supplied by the customer, so the output is only as good as the rules behind it, and the vendor will not say whether the information gathered is sufficient
  • Highly sensitive personal data flows through the platform, including identity documents, photos and videos of people, bank statements and PEP status, and the customer must hold a legal basis for every search
  • Aggregated and anonymised customer data may be used to develop the product, with no documented opt-out, and all customer feedback is irrevocably assigned to the vendor
  • Liability is capped at the fees paid over the previous three months, and an unpaid invoice leads to account suspension, deletion after three months and transfer of the debt to a collection agency
  • Accepting the terms grants the vendor the right to use your company name and logo in its marketing materials
Setup

Setup & Integrations

Technical difficulty

Two very different paths. Without code, the platform is usable straight from the dashboard, with ready onboarding templates per jurisdiction and no installation of any kind. With code, the effort is moderate and firmly developer territory: a GraphQL API with separate development and production endpoints, Bearer authentication on a ten-minute token that must be refreshed, a mandatory Origin header, webhook subscriptions to create, and a web SDK to embed for the white-label flow. Deeper customisation and white labelling may carry a setup fee.

Deployment

Web appAPI

Supported languages

English
Company

Behind Vespia

Company name
Vespia OÜ
Founded
28/07/2020
Country of origin
🇪🇪 Estonia
Headquarters
Avar tn 5-36, Maardu linn, Harju maakond, 74112, Estonia
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Fundraising

Seed round backed by Plug and Play, with Icebreaker VC among the backers; the amount was never publicly disclosed, and the Icebreaker logo appears in the partner strip on the Vespia homepage
Acquired by Veriff, announced on 5 February 2026 with financial terms undisclosed; the merger was recorded in the Estonian commercial register on 10 June 2026, with Veriff OÜ as legal successor

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Vespia.

O OnfidoJ Jumio
FAQ

Frequently asked questions

What does Vespia actually do?
It is an AML compliance platform that combines KYB business verification, KYC identity checks, screening against PEP, sanctions and adverse-media lists, customer onboarding, risk scoring, continuous monitoring and regulatory reporting in a single workflow.
How wide is the geographic coverage?
Vespia advertises more than 300 jurisdictions, 5,000+ official sources, 1,500+ data points, and identity verification on more than 7,000 document types from over 190 countries and territories. The API documentation groups jurisdictions into zones A to H, updated on 2 April 2026.
How much does it cost?
The Starter Package is listed at 99 EUR, with KYB reports charged separately from 35 EUR each depending on the region. No billing period is shown next to the amount, and the Pro Plan is quoted on request rather than published.
Is there a free plan or a free trial?
There is a seven-day free trial. No permanent free plan is advertised. The terms also mention a test account with limited features, for a free period that Vespia decides.
Is there an API?
Yes. Vespia publishes GraphQL API documentation with separate development and production endpoints, Bearer authentication with a ten-minute token and a refresh mutation, an Apollo playground, webhooks for real-time updates, and a web SDK for the onboarding flow.
Who is behind Vespia and where is the data hosted?
The publisher is Vespia OÜ, Avar tn 5-36, Maardu linn, Harju maakond 74112, Estonia, registry code 16017942, registered on 28 July 2020. Hosting runs on Amazon Web Services, with data stored in the EU by default unless otherwise agreed.
Is a DPA available and are sub-processors published?
Yes to both. A Data Processing Agreement under GDPR Article 28 is published as a PDF appendix to the terms, and it names eleven sub-processors: NameScan, Amazon Web Services, Hotjar, Intercom, Amplitude, Google Analytics, Mailchimp/Mandrill, HubSpot, Google Tag Manager, Google Search Console and Google Optimize.
Is customer data used to train AI models?
The documents do not say. Neither the terms nor the DPA mention model training, but both allow Vespia to use client data in aggregated or anonymised form to analyse and develop the solution, and no opt-out mechanism is documented.
Is Vespia still an independent product?
No. Veriff announced the acquisition on 5 February 2026 and is integrating the KYB technology into its own platform. Vespia OÜ was struck from the Estonian commercial register on 10 June 2026, with Veriff OÜ as legal successor, and most vespia.io pages now redirect to Veriff.
Conclusion

Should you pick Vespia?

Vespia built a genuinely complete answer to a narrow, painful problem: verifying companies rather than people, everywhere at once. The breadth is real, with registers in more than 300 jurisdictions, screening against over 4,000 watchlists, identity checks on 7,000+ document types, and a workflow that runs from first lookup to continuous monitoring and audit trail without leaving the platform. Its legal transparency is well above the market average: the terms and the Data Processing Agreement are published as PDFs, eleven sub-processors are named, technical and organisational measures are spelled out, and the publisher sits inside the EU with AWS hosting that keeps data in the EU by default.

Two caveats matter more than the rest. The first is factual and decisive: Vespia is no longer an independent product. Veriff announced its acquisition in February 2026, the Estonian company was struck from the register in June 2026, and the site is emptying page by page into Veriff's own domain. Anyone reading this today should expect to buy the capability through Veriff rather than through Vespia, and should treat the roadmap as Veriff's.

The second is contractual. The terms allow aggregated and anonymised use of customer data to develop the product, hand every piece of customer feedback to the vendor outright, and offer no documented way to keep data out of model training. For a tool that processes identity documents, bank statements and PEP status, that deserves a careful read before signing.

As a reference point, Vespia remains instructive: a compact, well-documented, API-first compliance stack with public entry pricing at 99 EUR and a seven-day trial. As a purchase, it is now a chapter of someone else's product.