Vespia
Vespia is an AI-powered AML compliance platform that combines business verification, identity checks, sanctions and PEP screening, risk scoring and continuous monitoring across more than 300 jurisdictions, delivered through a web dashboard and a GraphQL API.
What is Vespia?
Vespia is an anti-money-laundering compliance platform built for organisations that have to verify other organisations. It brings KYB business verification, KYC identity verification, AML screening, customer onboarding, risk scoring, monitoring and reporting into a single workflow, so a compliance team does not have to stitch several vendors together to stay compliant.
The verification layer draws on commercial registers in more than 300 jurisdictions, backed by a claimed 5,000+ official sources and 1,500+ data points. A company lookup returns register information in under 30 seconds, along with original documents, corporate hierarchies and the identification of ultimate beneficial owners, shareholders and directors. Continuous UBO monitoring raises real-time alerts when an ownership structure changes.
Screening runs automatically on every entity attached to a company, checked against more than 4,000 PEP, sanctions and adverse-media lists, with smart filtering meant to cut false positives. On the individual side, KYC covers over 7,000 document types from more than 190 countries and territories, with liveness detection that asks the person to complete a task on camera.
Instead of long AML questionnaires, customers deploy Vespia's onboarding flow: ready KYB and KYC templates per jurisdiction, editable steps, logic and AML questions, and a white-label web SDK that embeds the flow into their own site. Risk scoring accepts the customer's own risk matrix and rules in a hybrid rule-based and AI approach, while Julia AI, presented as an AI AML compliance officer, offers guidance on smoothing the compliance process.
Monitoring works on three axes: KYB rechecks driven by the risk level set by the customer, daily PEP, sanctions and adverse-media screening, and alerts when an identity document expires. Results land in PDF and machine-readable reports with a full audit trail. Separate AI transaction monitoring detects suspicious activity.
Delivery is a web dashboard plus a GraphQL API with webhooks, so verification can be embedded in an existing system or CRM. The wider solution defined in the terms also covers Vespia Passport, a reusable business digital identity, and Compliance Officer as a Service, a network of certified compliance officers. Veriff has acquired Vespia and is folding its KYB technology into its own platform.
What it does
- Pull commercial register information on a company from more than 300 jurisdictions in under 30 seconds
- Map corporate hierarchies and identify ultimate beneficial owners, shareholders and directors
- Screen every entity linked to a company against more than 4,000 PEP, sanctions and adverse-media lists
- Verify the identity of founders and beneficial owners across 7,000+ document types with liveness detection
- Score counterparty risk using your own risk matrix, with a hybrid of rules and AI
- Monitor businesses, watchlists and document expiry continuously and raise alerts on changes
- Produce PDF and machine-readable reports with a full audit trail for regulators
When to use Vespia / When not to
A quick filter to help you decide if Vespia is the right fit.
When to use Vespia
- Compliance officers and AML analysts who onboard corporate customers across several jurisdictions
- Banks, payment providers and crypto businesses that must screen companies and their stakeholders continuously
- Accounting and audit firms running automated due diligence and AML checks on their clients
- Developers integrating business and identity verification into an existing product or CRM through an API
- Small and growing companies that need a ready-made AML programme rather than an in-house one
When not to use Vespia
- Individuals and consumers: the platform is strictly business-to-business, with no personal plan
- Teams needing a mobile app, since Vespia ships only a web dashboard and an API
- Organisations requiring an interface or documentation in a language other than English
- One-off users, because entry pricing starts at 99 EUR plus 35 EUR per KYB report
- Buyers looking for a long-term standalone vendor, as Vespia has been acquired and folded into Veriff
How to use Vespia
A typical end-to-end flow, from setup to results.
- Create an account through the Vespia dashboard, or accept an invitation sent by Vespia
- Pick a solution package; a test account with limited features is available, for a period Vespia decides
- Load your own risk matrix and risk rules so that automated scoring reflects your policy
- Choose a ready KYB or KYC onboarding template for your jurisdiction
- Edit the steps, logic and AML questions, then brand the flow and embed it with the white-label web SDK
- Run a KYB check by submitting a company name, registration code and country code
- For API use, create a development account, obtain a token through the signIn mutation and send the required Origin header
- Refresh the access token every ten minutes, then switch to the production endpoints when you go live
- Subscribe to webhooks so verification updates reach your system in real time
- Review cases and alerts in the dashboard and export PDF or machine-readable reports with the audit trail
Pros & Cons
Pros
- Unusually broad coverage: 300+ jurisdictions, 5,000+ official sources and 7,000+ identity document types
- The whole chain in one tool, from company lookup to screening, onboarding, scoring, monitoring and reporting
- Public and detailed API documentation, with an Apollo playground, webhooks and a per-zone country coverage table
- Rare legal transparency: a published DPA and a named list of eleven sub-processors
- EU-based publisher, with AWS hosting and data stored in the EU by default
- Entry price shown publicly, with a seven-day free trial and no seat limit on the starter package
- Genuine customisation: your own risk matrix, editable onboarding templates and white-label branding
Cons
- The tool has been acquired: Vespia OÜ was struck from the Estonian register in June 2026 and the site is now a shop window
- Most pages, including contact, products, blog and careers, redirect to Veriff
- Pricing is only partly public: one priced package, no billing period stated, nothing above it
- The terms and conditions date from February 2023 and have not been revised since
- No documented way to exclude customer data from model training
- The terms allow aggregated and anonymised use of customer data for product development, and hand all feedback to the vendor
- Support runs only 9am to 5pm Estonian time on weekdays, in English only, with no mobile app
Pricing & Plans
There is no permanent free plan. The only publicly priced offer is the Starter Package at 99 EUR, to which KYB reports are added at 35 EUR per report depending on the region. No billing period is stated next to the amount. A seven-day free trial is offered, and the Pro Plan is quoted commercially rather than published. Prices are exclusive of tax, and any change requires three months' notice.
- Starter Package — 99 EUR
- described as AML support for startups and small businesses
- with global KYB coverage
- unlimited users
- official business registry and database information
- directors
- shareholders and UBOs where available
- company and stakeholder sanctions
- Pro Plan — subscription package covering the chosen volume of verifications and monitoring
- price and contents are given in a commercial proposal
- not published on the site
- Test Account — limited feature access
- for a free period that Vespia sets at its discretion
- Special Terms — a separate signed agreement for extra solutions
- extra verification volume or extra support
- with a possible setup fee for customisation and white labelling
Data, GDPR & hosting
A consolidated view of how Vespia handles your data.
GDPR overview
GDPR implementation is concrete and documented. The publisher is established in Estonia, so it falls directly under the regulation. The privacy policy is built around GDPR terms, names legitimate interest as the legal basis for processing client contacts, lists the rights of access, rectification, erasure, restriction and objection with a 30-day response window, and names the Estonian Data Protection Inspectorate as the supervisory authority. A Data Processing Agreement concluded under Article 28 is published as Appendix 1 to the terms, with a schedule of technical and organisational measures. Transfers outside the EU are limited to GDPR Chapter V conditions, and Standard Contractual Clauses are cited for the Australian screening provider. Sub-processor changes are notified by email with a seven-day objection window. No Article 27 representative is designated, and none is required.
Who owns the data?
Ownership is split. The customer keeps its Client Data and stays solely responsible for its lawfulness, quality and accuracy; under the Data Processing Agreement the customer is the controller and Vespia the processor acting on instruction. Vespia keeps exclusive intellectual property over the platform itself and grants only a limited, non-exclusive, non-transferable licence for the duration of the contract. Two clauses shift value the other way: any feedback a customer gives becomes Vespia's exclusive property with an irrevocable assignment of rights, and Vespia may use Client Data in aggregated or anonymised form for internal analysis, marketing and product development. Customers can export their data as PDF from the dashboard within one month of termination.
Reuse rights
Verification results are the customer's to use inside its own AML process: PDF reports, machine-readable reports and a full audit trail can be pulled from the dashboard, requested through the API, or asked for by email. No further permission from Vespia is needed for that operational reuse. The limits are legal rather than contractual: the customer must hold an appropriate legal basis for every search it runs, and Vespia disclaims responsibility for the accuracy or completeness of information coming from commercial registers, PEP and sanctions lists and adverse-media databases. The final decision on any verified company or person stays with the customer, and Vespia explicitly declines to advise whether the information obtained is sufficient. After termination, a history extract can be requested, and Vespia may charge for it. Accepting the terms also lets Vespia use the customer's name and logo in its own marketing materials.
Data retention & training
Hosting summary
Hosting runs entirely on Amazon Web Services, described in the Data Processing Agreement as a single strategic infrastructure, storage and database partner, with the statement that data never leaves AWS servers and that customer data may not be stored outside that partner's infrastructure. By default data is stored in the EU unless otherwise agreed, and the privacy policy states that personal data is processed within the European Economic Area as a rule, with any transfer outside it following GDPR requirements. Transfers outside the EU are limited to Chapter V conditions, and Standard Contractual Clauses are cited for the Australian screening provider NameScan. The published technical measures include encryption in transit and at rest, role-based access control, access logging, logical separation of client data and separated test, development and production environments. One point of attribution matters: the ISO 27001, 27017 and 27018 certifications and the SOC and CSA STAR reports listed in the agreement belong to the hosting provider, not to the publisher, which claims no certification of its own.
Things to keep in mind
Risks and trade-offs to weigh before adopting Vespia.
- The product has been acquired and the site is being dismantled: expect service discontinuity and a forced migration to Veriff
- Results depend on third-party sources, and the vendor explicitly disclaims responsibility for the accuracy of registers, watchlists and adverse-media databases
- Automated scores invite over-confidence: the risk matrix is supplied by the customer, so the output is only as good as the rules behind it, and the vendor will not say whether the information gathered is sufficient
- Highly sensitive personal data flows through the platform, including identity documents, photos and videos of people, bank statements and PEP status, and the customer must hold a legal basis for every search
- Aggregated and anonymised customer data may be used to develop the product, with no documented opt-out, and all customer feedback is irrevocably assigned to the vendor
- Liability is capped at the fees paid over the previous three months, and an unpaid invoice leads to account suspension, deletion after three months and transfer of the debt to a collection agency
- Accepting the terms grants the vendor the right to use your company name and logo in its marketing materials
Setup & Integrations
Technical difficulty
Two very different paths. Without code, the platform is usable straight from the dashboard, with ready onboarding templates per jurisdiction and no installation of any kind. With code, the effort is moderate and firmly developer territory: a GraphQL API with separate development and production endpoints, Bearer authentication on a ten-minute token that must be refreshed, a mandatory Origin header, webhook subscriptions to create, and a web SDK to embed for the white-label flow. Deeper customisation and white labelling may carry a setup fee.
Deployment
Supported languages
Behind Vespia
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Vespia.
Frequently asked questions
What does Vespia actually do?
How wide is the geographic coverage?
How much does it cost?
Is there a free plan or a free trial?
Is there an API?
Who is behind Vespia and where is the data hosted?
Is a DPA available and are sub-processors published?
Is customer data used to train AI models?
Is Vespia still an independent product?
Should you pick Vespia?
Vespia built a genuinely complete answer to a narrow, painful problem: verifying companies rather than people, everywhere at once. The breadth is real, with registers in more than 300 jurisdictions, screening against over 4,000 watchlists, identity checks on 7,000+ document types, and a workflow that runs from first lookup to continuous monitoring and audit trail without leaving the platform. Its legal transparency is well above the market average: the terms and the Data Processing Agreement are published as PDFs, eleven sub-processors are named, technical and organisational measures are spelled out, and the publisher sits inside the EU with AWS hosting that keeps data in the EU by default.
Two caveats matter more than the rest. The first is factual and decisive: Vespia is no longer an independent product. Veriff announced its acquisition in February 2026, the Estonian company was struck from the register in June 2026, and the site is emptying page by page into Veriff's own domain. Anyone reading this today should expect to buy the capability through Veriff rather than through Vespia, and should treat the roadmap as Veriff's.
The second is contractual. The terms allow aggregated and anonymised use of customer data to develop the product, hand every piece of customer feedback to the vendor outright, and offer no documented way to keep data out of model training. For a tool that processes identity documents, bank statements and PEP status, that deserves a careful read before signing.
As a reference point, Vespia remains instructive: a compact, well-documented, API-first compliance stack with public entry pricing at 99 EUR and a seven-day trial. As a purchase, it is now a chapter of someone else's product.
- Choosing a selection results in a full page refresh.
- Opens in a new window.