Fundvis logo
Gov Legal · Data Governance Quality

Fundvis

Fundvis is a Luxembourg SaaS oversight platform for European financial institutions. It runs ICT provider, delegate and group oversight end to end, from onboarding and due diligence through monitoring to regulatory reporting against DORA, CSSF 22/806 and GDPR.

Active GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is Fundvis?

Fundvis is a SaaS oversight platform for financial institutions, published by Fundvis S.A., a Luxembourg company entered on the trade register on 25 May 2022. Its stated purpose is to replace spreadsheet tracking of providers, delegates and funds with a single auditable workspace that stays aligned with European and local regulation.

Three product modules are exposed on the site: ICT Providers Oversight, Delegates Oversight and Groups Oversight. A fourth, Funds Oversight, appears in the footer without an active link. Each follows the same three-part cycle, described as built for onboarding, built for monitoring and built for reporting.

Onboarding brings pre-built DDQ templates, an invitation for the client and counterparties to collaborate, AI pre-filling from uploaded documents, automated due diligence checks and scoring, and digital approval with role-based signature and a complete audit trail. Monitoring adds AI risk scores that rank priorities, KPI collection through guided submissions with built-in validations and deadline reminders, an AI pre-check of supporting evidence, and incident management with automatic assignment. Reporting validates and consolidates the data, applies built-in templates for DORA, CSSF 22/806, GDPR and ISO, and exports to PDF, XLSX or a house template, with dashboards for management, boards and regulators.

The AI functions are named openly: Document Data Extraction, Data Validation against CSSF and EBA rules, an AI Excel Converter Agent, a Risk Scoring Agent, a Chatbot Assistant presented as a compliance co-pilot, and AI-generated reports. Underneath sits a unified data model: shared fields such as legal entity details, service scope, sub-outsourcing, locations, controls, dependencies, risk ratings and contacts are captured once and re-applied to every circular selected. An integrated API connection to the CSSF eDesk portal allows major incidents to be reported in one click and the register transmitted.

Customer segments described on the homepage include banks and custodians, depositary banks, ManCos and AIFMs, asset managers, insurance and private equity, and the company states the platform is not restricted to funds. Claimed operating figures are incidents acknowledged within 30 minutes and resolved in about 1.5 days. The about page names eight staff led by founder Leonhard Kossmann and four investors; one named testimonial, from the CEO of ACM Private Markets, addresses DORA compliance.

What it does

  • Centralise ICT providers, delegates and their contracts in one register, ticking the regimes that apply (CSSF circulars, DORA, ISO 27001, GDPR).
  • Pre-fill due diligence questionnaires by AI extraction from the documents uploaded.
  • Compute and periodically re-assess a risk score according to the institution's own scoring logic.
  • Declare, classify (A/B/C) and track ICT incidents, then transmit them to the CSSF through the eDesk API.
  • Produce regulatory reports and board reports, exportable to PDF, XLSX or a house template.
  • Generate an AI executive summary consolidating findings, scores and compliance status, with red-flag detection.
  • Collect and validate provider KPIs, with deadline reminders and an AI pre-check of the evidence supplied.
Audience

When to use Fundvis / When not to

A quick filter to help you decide if Fundvis is the right fit.

When to use Fundvis

  • Management companies (ManCos) and AIFMs that must evidence delegate oversight to the CSSF.
  • Banks, PSF entities and depositary banks building an ICT third-party register for DORA.
  • Insurance companies, asset managers and private equity firms consolidating providers, contracts, KPIs and incidents in a single place.
  • Group compliance, procurement, IT and legal departments that have to map entities, processes, services and contracts across several subsidiaries.
  • Any oversight team still working from spreadsheets: the AI Excel Converter Agent takes the existing files as its starting point.

When not to use Fundvis

  • Teams that want to test a product on their own: there is no free plan, no announced free trial and no self-service sign-up, only a demo request.
  • Organisations governed by US or Asian frameworks: the templates and validations are built around DORA, CSSF 22/806, GDPR, ISO and EBA rules.
  • Buyers who need mobile access: no iOS or Android application exists and none is announced.
  • Teams that need a localised interface: the site declares English only, with no other product language.
  • Anyone looking for portfolio management or investment analytics: the product covers compliance and third-party oversight, not performance.
Get started

How to use Fundvis

A typical end-to-end flow, from setup to results.

  1. Request a demo through the HubSpot form linked from every page (Request a Demo / Book a Demo); the confirmation page announces a personalised live demo scheduled by the team.
  2. Bring the existing material in: the AI Excel Converter Agent takes over the spreadsheets already in use, which avoids a heavy IT project.
  3. Add an ICT provider or a delegate to the central register and tick the circulars and regimes that apply to it.
  4. Link that provider to the benefiting entity within the group, to the receiving function (IT, risk, compliance), to the service type and to the level of dependency.
  5. Launch due diligence from a pre-built DDQ template or upload your own, then invite colleagues and counterparties to complete it in real time.
  6. Let AI extraction pre-fill the questionnaire from the documents deposited, then apply your own scoring logic to the answers.
  7. Have the file approved digitally with role-based signature; the audit trail is written as you go.
  8. Follow the file day to day: built-in calendar of DDQ deadlines, real-time alerts and scheduled periodic re-assessments.
  9. Collect the KPIs, declare and classify incidents (A/B/C) and track their resolution.
  10. Produce the outputs, from regulatory register to board report or chatbot-generated report, and transmit to the CSSF through the eDesk API.
Quick read

Pros & Cons

Pros

  • End-to-end coverage in a single tool: onboarding, due diligence, contracts, KPIs, incidents and reporting.
  • Precise, named regulatory anchoring (DORA, CSSF 22/806, GDPR, ISO, EBA rules) rather than generic compliance language.
  • Integrated API connection to the CSSF eDesk portal, with major incident reporting in one click.
  • Unified data model that avoids re-keying the same fields for every circular selected.
  • Existing spreadsheets are taken over by AI conversion, so getting started does not require a heavy IT project.
  • Announced EU-only hosting, with a physical Luxembourg option through DEEP/POST Group.
  • Complete audit trail and role-based approvals at every step, from an active publisher: a Luxembourg company on the trade register since 2022, two roles opened in late 2025 and three press appearances.

Cons

  • No public pricing whatsoever: no pricing page, no figure, no grid, and the complete sitemap proves the absence.
  • No terms and conditions published: /terms, /legal and /imprint return genuine 404 pages.
  • Privacy policy generated from a template, dated 3 November 2022, covering only the marketing website and not the platform, and carrying residue that does not fit a B2B product sold to banks (advertising partners, a CCPA section).
  • Nothing published about model training on customer data, in either direction, no DPA mentioned and no sub-processor list.
  • No named certification of the publisher: no ISO 27001, no SOC 2, no number, no certifying body; the single ISO 27001 mention is a framework the customer ticks inside the product.
  • No self-service at all: the only way in is a demo request, and there is no public API documentation or developer portal.
  • English-only interface with no other declared language, and a Funds Oversight module advertised in every footer with no page behind it.
Pricing

Pricing & Plans

Fundvis publishes no price. There is no pricing page, /pricing returning a genuine 404 while none of the fifteen URLs listed in the sitemap points to one, and no amount appears anywhere on the site. No free plan and no free trial are announced. The single route in is the Request a Demo or Book a Demo form, so the product is sold under contract, with commercial terms established after the demonstration. Complementary services are mentioned without a price, notably training and agent customisation, for which the defined scope is said to determine the delivery timeframe. Any figure must therefore be obtained directly from the vendor.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Fundvis handles your data.

GDPR overview

The privacy policy carries a GDPR Data Protection Rights section listing the six rights: access, rectification, erasure, restriction, objection and portability. Legal bases are named explicitly: Article 6(1)(f) for the contact form, Article 6(1)(b) where the request aims at concluding a contract, and Article 6(1)(b) for job applications. The right to object refers to Article 21 and is exercised by a simple email to contact@fundvis.org, with a stated response time of one month. The homepage claims compliance with European regulatory frameworks including DORA, GDPR and ISO. What is missing is substantial: no named DPO, no data processing agreement, no sub-processor list, and no Article 27 representative (none is required, the publisher being EU-established). The policy dates from 3 November 2022, covers the marketing website only, and still contains template residue.

Who owns the data?

The site publishes no terms and conditions at all: /terms, /terms-of-service, /legal, /legal-notice and /imprint each return a genuine 404, and the complete 15-URL sitemap contains no such page. No published clause therefore says who owns the data loaded into the platform, what Fundvis may do with it, or with whom it may be shared. The privacy policy does not fill the gap: it applies only to the company's online activities and to visitors of the website, which is the marketing site rather than the platform, and it is silent on ownership. The FAQ claims EU-only hosting in isolated server environments, which is a hosting statement, not a property clause. Ownership terms have to be obtained contractually.

Reuse rights

Nothing can be checked here, because no contractual document is published. With no terms of use anywhere on the site, there is no reuse clause, no licence grant and no restriction available to read, so a prospective user cannot tell what they may export, reuse or share without asking. The privacy policy only lists purposes tied to the website itself: providing and improving the site, analysing usage, developing new products and services, communicating with visitors, sending emails and detecting fraud. It also carries template residue about advertising partners and a Californian CCPA section, which sit oddly on a B2B product sold to banks. Model training on customer data is never addressed, in either direction. The single concrete commitment concerns recruitment: application documents are automatically deleted six months after notification of the rejection decision when no employment contract is concluded.

Data retention & training

Retention summary
Only one retention period is published, and it concerns recruitment rather than the product: application files are deleted automatically six months after the rejection decision is notified, unless a legitimate interest, namely the burden of proof under equal-treatment law, requires keeping them. Contact-form data is kept to handle the enquiry and any follow-up questions, then deleted after final processing where no legal storage obligation applies. Nothing at all is published for the data processed inside the platform: the policy, dated 3 November 2022, explicitly covers the marketing website only. There is no product retention policy, no deletion commitment at the end of a contract and no anonymisation rule on record, so any retention requirement has to be settled contractually.
GDPR contact

Hosting summary

Hosting is announced as EU-only and presented as compliant with CSSF circular 22/806 and DORA. The named locations are Frankfurt, Brussels and Paris, on AWS, Google Cloud and Azure, plus physical hosting in Luxembourg through DEEP/POST Group. Fundvis describes dedicated Tier 4 datacentres with isolated server environments. The announced controls are Google and Microsoft SSO, mandatory two-factor authentication, and encryption of all data at rest and in transit. The operating model is SaaS, reached through a browser, and the jurisdiction of the publisher is Luxembourg. One caveat matters for anyone relying on these statements: they come from the commercial FAQ, not from a dedicated security or trust page, since /security returns a genuine 404. No certification of the publisher, no audit report and no sub-processor list backs them up, and the Tier 4 certifications belong to the hosting providers named rather than to Fundvis.

Hosting countries
🇩🇩 Germany🇧🇪 Belgium🇫🇷 France🇱🇺 Luxembourg
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Fundvis.

  • Second-hand domain: the first Wayback capture is 25 September 2000, with a continuous series to 2003, while the current domain was registered on 3 March 2022 and the company incorporated on 25 May 2022. Twenty-one years and eight months of archived content have nothing to do with Fundvis, so the archive must not be read as company history.
  • No contractual document is published: no terms and conditions, no legal notice, no data processing agreement, no sub-processor list, and no price, plan or trial. The absence is proven rather than assumed, by genuine 404 pages and by enumerating the fifteen URLs of the sitemap. Everything that would bind the vendor has to be obtained in negotiation.
  • The privacy policy is template-generated (Free Privacy Policy Generator), dated 3 November 2022, and states that it covers only the marketing website, not the data processed inside the platform. It carries residue that is incoherent for a B2B product sold to banks: advertising partners, a Californian CCPA section and an under-13 children clause.
  • Compliance is declared, never attested. Being fully aligned with Cloud Outsourcing Regulation 22/806 and DORA is a claim without an attestation; no certification of the publisher is named, with no number, body or report; the single occurrence of ISO 27001 on the site is a framework the customer ticks inside the product; and the Tier 4 datacentre certifications belong to the hosting providers (AWS, Google Cloud, Azure, DEEP/POST).
  • Social proof is thinner than it looks. The Trusted by Europe's Leading Financial Institutions band links to aiqunited.com, mandg.com, raiffeisen.lu, alfi.lu and prudential.com with no case study, and ALFI is a Luxembourg trade association rather than a customer. The only named and checkable testimonial is Nic Mueller, CEO of ACM Private Markets. The operating figures, incidents acknowledged within 30 minutes and resolved in about 1.5 days, are unaudited and given without source or method.
  • AI training on customer data is never mentioned, in either direction: no opt-out, no retention commitment, no denial. Combined with the missing DPA and sub-processor list, a compliance buyer has no written basis for assessing what the AI extraction, scoring and chatbot features do with the documents uploaded.
  • Identity and scope require checking. The legal name Fundvis S.A. appears in none of the site's identity slots, the footer being reduced to a copyright line, and is established only by RCS B267872, GLEIF and North Data; the site address (LHoFT, 9 Rue du Laboratoire) differs from the more recent register address (11 Rue des Capucins, L-1313); the incorporation date of 25 May 2022 comes from an off-site register, a competing date of 5 May 2022 (the constitutive deed) having been discarded; and the Funds Oversight module sits in every footer behind a dead link, with no page in the sitemap.
Setup

Setup & Integrations

Technical difficulty

Low to moderate, on the vendor's own account. Fundvis is a browser-based SaaS with no installation and no on-premise deployment announced, and sign-in uses Google or Microsoft SSO with mandatory two-factor authentication. The platform ships with best-practice workflows out of the box, and the AI Excel Converter Agent takes over existing spreadsheets, which Fundvis presents as a rapid start without a heavy IT project. Training and agent customisation are offered as collaborative services. One reservation: no implementation duration is published, timelines being said to depend on the scope defined, so the real effort is known only after scoping.

Deployment

Web app

Integrations

DocuSign LuxTrust CSSF eDesk
Company

Behind Fundvis

Company name
Fundvis S.A.
Founded
25/05/2022
Country of origin
🇱🇺 Luxembourg
Headquarters
Luxembourg House of Financial Technology (LHoFT), 9 Rue du Laboratoire, 1911 Luxembourg
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇩 Germany
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Where is Fundvis based?
The site's FAQ gives the Luxembourg House of Financial Technology (LHoFT), 9 Rue du Laboratoire, 1911 Luxembourg. The Luxembourg trade register publishes a more recent address for Fundvis S.A. (RCS B267872): 11 Rue des Capucins, L-1313 Luxembourg. Both are in Luxembourg City, but the two sources do not agree on the street.
Where is the data hosted?
Hosting is announced as EU-only, with servers in Frankfurt, Brussels and Paris on AWS, Google Cloud and Azure, plus physical hosting in Luxembourg through DEEP/POST Group, in Tier 4 datacentres. The statement comes from the commercial FAQ; there is no dedicated security page behind it.
Is Fundvis only for investment funds?
No. Fundvis states that it serves the financial industry as a whole. Banks, insurers, ManCos, AIFMs, law firms and private equity companies all appear among the announced clientele, alongside fund-related workflows.
Can Fundvis be used outside Luxembourg?
Yes. The platform targets European frameworks such as DORA, GDPR and NIS as well as local regulations, and the FAQ states explicitly that the cloud SaaS platform is not limited to Luxembourg.
What does Fundvis integrate with?
Fundvis says it provides API connectivity to link with other applications and databases. The integrations named in clear text are DocuSign, LuxTrust and the CSSF eDesk portal; no other integration is listed by name on the site.
Which regulatory frameworks are covered?
DORA, CSSF circular 22/806 on cloud outsourcing, GDPR, ISO and EBA rules. These are the frameworks whose templates and validation rules are built into the reporting module.
How long does implementation take?
Fundvis says the platform comes ready with best-practice workflows out of the box and that the AI Excel Converter Agent takes over existing spreadsheets for a rapid start. No duration is published: timelines are said to depend on the scope defined with the customer.
What security controls are in place?
Google and Microsoft SSO, mandatory two-factor authentication, encryption of data at rest and in transit, and isolated server environments in Tier 4 datacentres. These controls are announced in the commercial FAQ, and no audit report or named certification of the publisher supports them.
How much does Fundvis cost?
No price is published. There is no pricing page and no amount anywhere on the site; access goes through a demo request and the product is sold under contract.
Is there a mobile application?
No. No iOS or Android application was found, and the site announces none. Fundvis is a browser-based web application.
Conclusion

Should you pick Fundvis?

Fundvis is a niche tool with a very precise frame: European regulatory oversight, with a pronounced Luxembourg footprint through the CSSF, the LHoFT, LuxTrust and DEEP/POST. Its strength is the complete chain in one place, from onboarding a provider or a delegate to running due diligence, scoring and re-scoring the risk, collecting KPIs, handling incidents and filing the result with the CSSF through the eDesk API without leaving the platform. For a ManCo, an AIFM, a depositary bank or an insurer still running all of this on spreadsheets, that continuity is the argument.

Its structural weakness is documentary opacity. No published price, no terms and conditions, no legal notice, no data processing agreement, no sub-processor list, no named certification of the publisher. None of these absences is a gap in our reading: each was established by a real 404 and by enumerating every URL of the sitemap. The privacy policy that does exist was generated from a template in November 2022 and states plainly that it covers the marketing website only. Nothing is published, in either direction, on whether customer data feeds AI model training, which is a notable silence for a product built on AI extraction from compliance documents.

The publisher is young but demonstrably active: a Luxembourg company on the trade register since 25 May 2022, two positions opened in late 2025, three press appearances and one named customer testimonial.

The practical consequence is simple. Cost, contractual terms and data governance cannot be assessed from the website at all. A real evaluation runs through the demo and through the documents obtained in negotiation: ask in writing for the terms of use, the DPA, the sub-processor list, the retention policy and a written position on model training before committing.