
Fundvis
Fundvis is a Luxembourg SaaS oversight platform for European financial institutions. It runs ICT provider, delegate and group oversight end to end, from onboarding and due diligence through monitoring to regulatory reporting against DORA, CSSF 22/806 and GDPR.
What is Fundvis?
Fundvis is a SaaS oversight platform for financial institutions, published by Fundvis S.A., a Luxembourg company entered on the trade register on 25 May 2022. Its stated purpose is to replace spreadsheet tracking of providers, delegates and funds with a single auditable workspace that stays aligned with European and local regulation.
Three product modules are exposed on the site: ICT Providers Oversight, Delegates Oversight and Groups Oversight. A fourth, Funds Oversight, appears in the footer without an active link. Each follows the same three-part cycle, described as built for onboarding, built for monitoring and built for reporting.
Onboarding brings pre-built DDQ templates, an invitation for the client and counterparties to collaborate, AI pre-filling from uploaded documents, automated due diligence checks and scoring, and digital approval with role-based signature and a complete audit trail. Monitoring adds AI risk scores that rank priorities, KPI collection through guided submissions with built-in validations and deadline reminders, an AI pre-check of supporting evidence, and incident management with automatic assignment. Reporting validates and consolidates the data, applies built-in templates for DORA, CSSF 22/806, GDPR and ISO, and exports to PDF, XLSX or a house template, with dashboards for management, boards and regulators.
The AI functions are named openly: Document Data Extraction, Data Validation against CSSF and EBA rules, an AI Excel Converter Agent, a Risk Scoring Agent, a Chatbot Assistant presented as a compliance co-pilot, and AI-generated reports. Underneath sits a unified data model: shared fields such as legal entity details, service scope, sub-outsourcing, locations, controls, dependencies, risk ratings and contacts are captured once and re-applied to every circular selected. An integrated API connection to the CSSF eDesk portal allows major incidents to be reported in one click and the register transmitted.
Customer segments described on the homepage include banks and custodians, depositary banks, ManCos and AIFMs, asset managers, insurance and private equity, and the company states the platform is not restricted to funds. Claimed operating figures are incidents acknowledged within 30 minutes and resolved in about 1.5 days. The about page names eight staff led by founder Leonhard Kossmann and four investors; one named testimonial, from the CEO of ACM Private Markets, addresses DORA compliance.
What it does
- Centralise ICT providers, delegates and their contracts in one register, ticking the regimes that apply (CSSF circulars, DORA, ISO 27001, GDPR).
- Pre-fill due diligence questionnaires by AI extraction from the documents uploaded.
- Compute and periodically re-assess a risk score according to the institution's own scoring logic.
- Declare, classify (A/B/C) and track ICT incidents, then transmit them to the CSSF through the eDesk API.
- Produce regulatory reports and board reports, exportable to PDF, XLSX or a house template.
- Generate an AI executive summary consolidating findings, scores and compliance status, with red-flag detection.
- Collect and validate provider KPIs, with deadline reminders and an AI pre-check of the evidence supplied.
When to use Fundvis / When not to
A quick filter to help you decide if Fundvis is the right fit.
When to use Fundvis
- Management companies (ManCos) and AIFMs that must evidence delegate oversight to the CSSF.
- Banks, PSF entities and depositary banks building an ICT third-party register for DORA.
- Insurance companies, asset managers and private equity firms consolidating providers, contracts, KPIs and incidents in a single place.
- Group compliance, procurement, IT and legal departments that have to map entities, processes, services and contracts across several subsidiaries.
- Any oversight team still working from spreadsheets: the AI Excel Converter Agent takes the existing files as its starting point.
When not to use Fundvis
- Teams that want to test a product on their own: there is no free plan, no announced free trial and no self-service sign-up, only a demo request.
- Organisations governed by US or Asian frameworks: the templates and validations are built around DORA, CSSF 22/806, GDPR, ISO and EBA rules.
- Buyers who need mobile access: no iOS or Android application exists and none is announced.
- Teams that need a localised interface: the site declares English only, with no other product language.
- Anyone looking for portfolio management or investment analytics: the product covers compliance and third-party oversight, not performance.
How to use Fundvis
A typical end-to-end flow, from setup to results.
- Request a demo through the HubSpot form linked from every page (Request a Demo / Book a Demo); the confirmation page announces a personalised live demo scheduled by the team.
- Bring the existing material in: the AI Excel Converter Agent takes over the spreadsheets already in use, which avoids a heavy IT project.
- Add an ICT provider or a delegate to the central register and tick the circulars and regimes that apply to it.
- Link that provider to the benefiting entity within the group, to the receiving function (IT, risk, compliance), to the service type and to the level of dependency.
- Launch due diligence from a pre-built DDQ template or upload your own, then invite colleagues and counterparties to complete it in real time.
- Let AI extraction pre-fill the questionnaire from the documents deposited, then apply your own scoring logic to the answers.
- Have the file approved digitally with role-based signature; the audit trail is written as you go.
- Follow the file day to day: built-in calendar of DDQ deadlines, real-time alerts and scheduled periodic re-assessments.
- Collect the KPIs, declare and classify incidents (A/B/C) and track their resolution.
- Produce the outputs, from regulatory register to board report or chatbot-generated report, and transmit to the CSSF through the eDesk API.
Pros & Cons
Pros
- End-to-end coverage in a single tool: onboarding, due diligence, contracts, KPIs, incidents and reporting.
- Precise, named regulatory anchoring (DORA, CSSF 22/806, GDPR, ISO, EBA rules) rather than generic compliance language.
- Integrated API connection to the CSSF eDesk portal, with major incident reporting in one click.
- Unified data model that avoids re-keying the same fields for every circular selected.
- Existing spreadsheets are taken over by AI conversion, so getting started does not require a heavy IT project.
- Announced EU-only hosting, with a physical Luxembourg option through DEEP/POST Group.
- Complete audit trail and role-based approvals at every step, from an active publisher: a Luxembourg company on the trade register since 2022, two roles opened in late 2025 and three press appearances.
Cons
- No public pricing whatsoever: no pricing page, no figure, no grid, and the complete sitemap proves the absence.
- No terms and conditions published: /terms, /legal and /imprint return genuine 404 pages.
- Privacy policy generated from a template, dated 3 November 2022, covering only the marketing website and not the platform, and carrying residue that does not fit a B2B product sold to banks (advertising partners, a CCPA section).
- Nothing published about model training on customer data, in either direction, no DPA mentioned and no sub-processor list.
- No named certification of the publisher: no ISO 27001, no SOC 2, no number, no certifying body; the single ISO 27001 mention is a framework the customer ticks inside the product.
- No self-service at all: the only way in is a demo request, and there is no public API documentation or developer portal.
- English-only interface with no other declared language, and a Funds Oversight module advertised in every footer with no page behind it.
Pricing & Plans
Fundvis publishes no price. There is no pricing page, /pricing returning a genuine 404 while none of the fifteen URLs listed in the sitemap points to one, and no amount appears anywhere on the site. No free plan and no free trial are announced. The single route in is the Request a Demo or Book a Demo form, so the product is sold under contract, with commercial terms established after the demonstration. Complementary services are mentioned without a price, notably training and agent customisation, for which the defined scope is said to determine the delivery timeframe. Any figure must therefore be obtained directly from the vendor.
Data, GDPR & hosting
A consolidated view of how Fundvis handles your data.
GDPR overview
The privacy policy carries a GDPR Data Protection Rights section listing the six rights: access, rectification, erasure, restriction, objection and portability. Legal bases are named explicitly: Article 6(1)(f) for the contact form, Article 6(1)(b) where the request aims at concluding a contract, and Article 6(1)(b) for job applications. The right to object refers to Article 21 and is exercised by a simple email to contact@fundvis.org, with a stated response time of one month. The homepage claims compliance with European regulatory frameworks including DORA, GDPR and ISO. What is missing is substantial: no named DPO, no data processing agreement, no sub-processor list, and no Article 27 representative (none is required, the publisher being EU-established). The policy dates from 3 November 2022, covers the marketing website only, and still contains template residue.
Who owns the data?
The site publishes no terms and conditions at all: /terms, /terms-of-service, /legal, /legal-notice and /imprint each return a genuine 404, and the complete 15-URL sitemap contains no such page. No published clause therefore says who owns the data loaded into the platform, what Fundvis may do with it, or with whom it may be shared. The privacy policy does not fill the gap: it applies only to the company's online activities and to visitors of the website, which is the marketing site rather than the platform, and it is silent on ownership. The FAQ claims EU-only hosting in isolated server environments, which is a hosting statement, not a property clause. Ownership terms have to be obtained contractually.
Reuse rights
Nothing can be checked here, because no contractual document is published. With no terms of use anywhere on the site, there is no reuse clause, no licence grant and no restriction available to read, so a prospective user cannot tell what they may export, reuse or share without asking. The privacy policy only lists purposes tied to the website itself: providing and improving the site, analysing usage, developing new products and services, communicating with visitors, sending emails and detecting fraud. It also carries template residue about advertising partners and a Californian CCPA section, which sit oddly on a B2B product sold to banks. Model training on customer data is never addressed, in either direction. The single concrete commitment concerns recruitment: application documents are automatically deleted six months after notification of the rejection decision when no employment contract is concluded.
Data retention & training
Hosting summary
Hosting is announced as EU-only and presented as compliant with CSSF circular 22/806 and DORA. The named locations are Frankfurt, Brussels and Paris, on AWS, Google Cloud and Azure, plus physical hosting in Luxembourg through DEEP/POST Group. Fundvis describes dedicated Tier 4 datacentres with isolated server environments. The announced controls are Google and Microsoft SSO, mandatory two-factor authentication, and encryption of all data at rest and in transit. The operating model is SaaS, reached through a browser, and the jurisdiction of the publisher is Luxembourg. One caveat matters for anyone relying on these statements: they come from the commercial FAQ, not from a dedicated security or trust page, since /security returns a genuine 404. No certification of the publisher, no audit report and no sub-processor list backs them up, and the Tier 4 certifications belong to the hosting providers named rather than to Fundvis.
Things to keep in mind
Risks and trade-offs to weigh before adopting Fundvis.
- Second-hand domain: the first Wayback capture is 25 September 2000, with a continuous series to 2003, while the current domain was registered on 3 March 2022 and the company incorporated on 25 May 2022. Twenty-one years and eight months of archived content have nothing to do with Fundvis, so the archive must not be read as company history.
- No contractual document is published: no terms and conditions, no legal notice, no data processing agreement, no sub-processor list, and no price, plan or trial. The absence is proven rather than assumed, by genuine 404 pages and by enumerating the fifteen URLs of the sitemap. Everything that would bind the vendor has to be obtained in negotiation.
- The privacy policy is template-generated (Free Privacy Policy Generator), dated 3 November 2022, and states that it covers only the marketing website, not the data processed inside the platform. It carries residue that is incoherent for a B2B product sold to banks: advertising partners, a Californian CCPA section and an under-13 children clause.
- Compliance is declared, never attested. Being fully aligned with Cloud Outsourcing Regulation 22/806 and DORA is a claim without an attestation; no certification of the publisher is named, with no number, body or report; the single occurrence of ISO 27001 on the site is a framework the customer ticks inside the product; and the Tier 4 datacentre certifications belong to the hosting providers (AWS, Google Cloud, Azure, DEEP/POST).
- Social proof is thinner than it looks. The Trusted by Europe's Leading Financial Institutions band links to aiqunited.com, mandg.com, raiffeisen.lu, alfi.lu and prudential.com with no case study, and ALFI is a Luxembourg trade association rather than a customer. The only named and checkable testimonial is Nic Mueller, CEO of ACM Private Markets. The operating figures, incidents acknowledged within 30 minutes and resolved in about 1.5 days, are unaudited and given without source or method.
- AI training on customer data is never mentioned, in either direction: no opt-out, no retention commitment, no denial. Combined with the missing DPA and sub-processor list, a compliance buyer has no written basis for assessing what the AI extraction, scoring and chatbot features do with the documents uploaded.
- Identity and scope require checking. The legal name Fundvis S.A. appears in none of the site's identity slots, the footer being reduced to a copyright line, and is established only by RCS B267872, GLEIF and North Data; the site address (LHoFT, 9 Rue du Laboratoire) differs from the more recent register address (11 Rue des Capucins, L-1313); the incorporation date of 25 May 2022 comes from an off-site register, a competing date of 5 May 2022 (the constitutive deed) having been discarded; and the Funds Oversight module sits in every footer behind a dead link, with no page in the sitemap.
Setup & Integrations
Technical difficulty
Low to moderate, on the vendor's own account. Fundvis is a browser-based SaaS with no installation and no on-premise deployment announced, and sign-in uses Google or Microsoft SSO with mandatory two-factor authentication. The platform ships with best-practice workflows out of the box, and the AI Excel Converter Agent takes over existing spreadsheets, which Fundvis presents as a rapid start without a heavy IT project. Training and agent customisation are offered as collaborative services. One reservation: no implementation duration is published, timelines being said to depend on the scope defined, so the real effort is known only after scoping.
Deployment
Integrations
Behind Fundvis
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Where is Fundvis based?
Where is the data hosted?
Is Fundvis only for investment funds?
Can Fundvis be used outside Luxembourg?
What does Fundvis integrate with?
Which regulatory frameworks are covered?
How long does implementation take?
What security controls are in place?
How much does Fundvis cost?
Is there a mobile application?
Should you pick Fundvis?
Fundvis is a niche tool with a very precise frame: European regulatory oversight, with a pronounced Luxembourg footprint through the CSSF, the LHoFT, LuxTrust and DEEP/POST. Its strength is the complete chain in one place, from onboarding a provider or a delegate to running due diligence, scoring and re-scoring the risk, collecting KPIs, handling incidents and filing the result with the CSSF through the eDesk API without leaving the platform. For a ManCo, an AIFM, a depositary bank or an insurer still running all of this on spreadsheets, that continuity is the argument.
Its structural weakness is documentary opacity. No published price, no terms and conditions, no legal notice, no data processing agreement, no sub-processor list, no named certification of the publisher. None of these absences is a gap in our reading: each was established by a real 404 and by enumerating every URL of the sitemap. The privacy policy that does exist was generated from a template in November 2022 and states plainly that it covers the marketing website only. Nothing is published, in either direction, on whether customer data feeds AI model training, which is a notable silence for a product built on AI extraction from compliance documents.
The publisher is young but demonstrably active: a Luxembourg company on the trade register since 25 May 2022, two positions opened in late 2025, three press appearances and one named customer testimonial.
The practical consequence is simple. Cost, contractual terms and data governance cannot be assessed from the website at all. A real evaluation runs through the demo and through the documents obtained in negotiation: ask in writing for the terms of use, the DPA, the sub-processor list, the retention policy and a written position on model training before committing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.