Complytek CLM logo
Security Fraud · Workflow Automation

Complytek CLM

Complytek CLM is a unified KYC, AML and fraud platform for financial institutions, covering onboarding, screening, risk scoring, transaction monitoring and case management, with an agentic AI module called Butterfly that triages alerts inside existing systems.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Complytek CLM?

Complytek CLM is the client lifecycle management platform built by Cypriot vendor COMPLYTEK.AI LTD to carry a regulated firm through the whole anti-money-laundering cycle inside one system. Onboarding, KYC and KYB, due diligence, screening, risk scoring, transaction monitoring, investigation, case management, reporting and audit trails all run on the same data. That is the vendor's founding argument: these functions were historically bought from three separate suppliers and were never designed to work together.

The platform is documented as eight functional blocks. Onboarding runs through a white-label portal with CRM integration over API, liveness selfies, biometric matching and document verification. Customer due diligence screens against PEP, sanctions and adverse media lists and assigns numeric risk scores through SegmenTek, the vendor's segmentation algorithm. Transaction screening is handled by ScreenTek, which Complytek clocks at under 900 milliseconds for an individual and under 200 milliseconds for a business. Transaction monitoring ships with a rule library the product page counts as more than 300 and the homepage as more than 350, covering live and post-transaction detection. Enhanced due diligence re-screens monthly, quarterly or annually according to the client's risk profile. Workflow orchestration offers a drag-and-drop builder, case management routes alerts by severity or expertise with a full audit trail, and analytics run through Power BI.

Butterfly is the second half of the offer: agentic AI components that read data and resolve cases without disturbing the systems already in place. It absorbs repetitive low-cognitive work, pre-sorts alerts on contextual risk indicators, and drafts decision rationales aligned with the institution's own precedents so the audit trail stays consistent between analysts. Complytek sells it both as an addition to its platform and as a standalone module that plugs into any environment, which is aimed squarely at institutions locked into legacy stacks.

The product ships as SaaS or on-premise, supports SWIFT, SEPA and ISO20022, and claims ISO 27001:2022 certification, GDPR compliance and, for the agents, conformity with the EU AI Act. The vendor claims more than 100 SME and mid-market customers across the EU, UK, GCC and Africa, and names Bank of Cyprus, AstroBank, FIBANK and Windsor Brokers among them.

What it does

  • Screen customers and payments against sanctions, PEP and adverse media lists in real time
  • Monitor transactions live and after the fact, and generate suspicious activity reports
  • Score and continuously re-score client risk from transaction behaviour
  • Automate onboarding through a white-label portal with identity and document verification
  • Triage and resolve low-value alerts with Butterfly AI agents
  • Build compliance scenarios and workflows without a developer
  • Explore and export compliance data through Power BI dashboards
Audience

When to use Complytek CLM / When not to

A quick filter to help you decide if Complytek CLM is the right fit.

When to use Complytek CLM

  • Compliance teams at mid-market banks, EMIs, fintechs and payment firms that need onboarding, screening and monitoring on one set of data
  • FX, trading and gaming operators working across several regulators at once, who need rules that differ by jurisdiction
  • Institutions locked into a legacy AML stack that want agentic automation without replacing the systems they already run
  • Professional services and accounting firms carrying AML obligations on behalf of their own clients
  • Buyers who need an on-premise deployment rather than a hosted service, and who can run one

When not to use Complytek CLM

  • Anyone expecting to sign up online: there is no self-service path, no free plan and no published price
  • Small firms that need a budget figure before talking to a salesperson, since every number comes from a quote
  • Teams looking for a mobile app, as the product exists only as a web platform and an API
  • Buyers who want to read the service contract first, because the site publishes neither terms of service nor a legal notice
  • Organisations that require a signed data processing agreement up front, as none is published or offered on the site
Get started

How to use Complytek CLM

A typical end-to-end flow, from setup to results.

  1. Request a demo or a free consultation, since there is no self-service sign-up
  2. Scope the modules you actually need, as the vendor bills only for what is selected
  3. Choose the delivery mode: SaaS, announced at 48 hours, or on-premise, announced at 45 days
  4. Import your client and transaction data and connect the source systems
  5. Pick the monitoring scenarios you want from the ready-made rule library
  6. Adjust risk factors, scoring weights and re-screening frequencies to your risk appetite
  7. Model your onboarding and investigation path in the drag-and-drop workflow builder
  8. Wire the iKYC API into your CRM or core banking system and test against the sandbox
  9. Route alerts and cases to analysts by severity or expertise, and add Butterfly agents for triage
  10. Build reporting in Power BI and export audit-ready case files
Quick read

Pros & Cons

Pros

  • The whole compliance chain comes from one vendor, which removes three contracts and three data models
  • Compliance staff configure scenarios themselves: new rules are announced as implementable in under 24 hours with no IT support
  • A ready-made rule library of 300 to 350 scenarios shortens the initial setup considerably
  • A genuine choice between SaaS and on-premise, which is uncommon in this market
  • Butterfly plugs into an existing stack, so agentic automation does not require replacing the AML system
  • ISO 27001:2022, GDPR and EU AI Act compliance are claimed, and personal data is processed within the EEA
  • A dedicated account manager and fully human support are promised, in explicit contrast to chatbot queues

Cons

  • No price is published anywhere: there is no pricing page in the 61-page sitemap and no figure on any product page
  • The one pricing link on the site, on the Salv comparison page, leads to a Replit development app that returns a 404
  • Neither terms of service nor a legal notice exists; the company's legal identity appears only inside the privacy policy
  • No data processing agreement is published or offered, although the vendor acts as processor for its clients
  • No subprocessor is named: the privacy policy lists categories of recipients only
  • Performance claims such as 80% fewer false positives, 40% less investigation time and 15% lower cost come with no stated method or scope
  • The awards and accreditations page is made entirely of images, so no certifying body can be read from the text
Pricing

Pricing & Plans

There is no free plan and no published price. Complytek does not operate a pricing page, and the only pricing link on the site, on its Salv comparison page, points to an external calculator that is offline. Pricing is established by quotation after a demonstration or a free consultation. The vendor states that each feature is optional and that a client pays only for the modules selected, and claims a cost 15% below traditional systems without naming a basis for that comparison. The API sandbox environment is included at no additional cost.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Complytek CLM handles your data.

GDPR overview

GDPR implementation is stated in concrete terms. The privacy policy invokes Regulation (EU) 679/2016 and Cypriot Law 125(I)/2018, and says data protection sits inside an ISO 27001:2022 certified system. It lists the legal bases under Article 6, enumerates the full set of data subject rights, commits to a one-month response extendable by two under Article 12.3, and undertakes to notify the Cypriot supervisory authority within 72 hours of a breach under Articles 33 and 34. Minors' data is not collected without verifiable parental consent under Article 8, though no minimum age is stated. Personal data is processed within the European Economic Area. The policy has been in force since 20 January 2025. As the company is established in Cyprus, no Article 27 representative is designated or required.

Who owns the data?

COMPLYTEK.AI LTD describes itself in two roles. It acts as controller for the data it collects directly, chiefly contact, identification, payment and recruitment data, and names a Chief Information Security Officer at dpo@complytek.ai, Aradippou, Cyprus, as the point of contact. Where third parties, usually companies, pass it personal data, it acts only as processor on their behalf, and it states plainly that those companies remain responsible for informing data subjects and for answering their rights requests. In practice, a client institution keeps ownership of the records it processes through the platform. No data processing agreement is published or offered, and no subcontractor is named.

Reuse rights

The privacy policy is written from the vendor's own side and does not grant, restrict or otherwise describe any right for a client to reuse data extracted from the platform. Complytek relies on consent, contractual performance, legal obligation and legitimate interest as its legal bases, and it states that it makes no decision based solely on automated processing, profiling included. Where it acts as processor, the client controller sets the terms. One point is left open on the product side: the site says machine learning modules improve risk scoring by learning from the client's own decisions and that the system learns from past cases, but it never says whether that learning stays inside the client's tenant or feeds shared models. There is no documented way to opt out of it.

Data retention & training

Retention summary
Complytek keeps personal data for as long as the purpose of processing requires, plus any permitted linked purpose. Some periods are stated: offers that do not lead to an agreement are kept for 12 months, job applications for 12 months, and IP and MAC addresses collected over the company Wi-Fi for 3 months. Cookies follow the categories set out in the cookies policy. Data held under contractual or legal obligations is kept beyond the expiry of those obligations for as long as the applicable framework requires, with no figure given. Data processed on consent is kept until consent is withdrawn or the need ends. Information that is no longer necessary is securely destroyed or anonymised. These periods cover data where Complytek is controller; where it acts as processor, retention is set by the client.
Trains on customer data
Unclear
GDPR contact

Hosting summary

The privacy policy makes one explicit commitment on location: personal data collected by Complytek is processed within the European Economic Area. Beyond that, nothing is specified. No country is named, no data centre is identified, and no hosting provider or subprocessor is disclosed. The policy lists categories of recipients, such as supervisory and judicial authorities, the company's auditor and lawyer, partner banks for payment data and training consultants, but names no organisation. Complytek states that data protection sits inside an ISO 27001:2022 certified information security management system, with access restricted to authorised staff on a need-to-know basis and confidentiality agreements in place. The on-premise deployment option implies that data can remain on the client's own infrastructure, but the site never presents this as a hosting guarantee. The website's own public IP resolves to a Cloudflare anycast address, which carries no information about where customer data is held.

Hosting regions
EEA
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Complytek CLM.

  • No published price means the budget can only be discovered at the end of a sales cycle, which makes early comparison with competitors impossible
  • With no terms of service and no legal notice, the contractual terms cannot be read before making contact
  • No data processing agreement is published even though the vendor acts as processor for its clients: insist on one during negotiation
  • Subprocessors are not named, only categories of recipients, so the real chain of custody over client data is not visible
  • The models learn from the client's own decisions and past cases, but nothing states whether that learning stays inside the tenant, and no opt-out is documented
  • Hosting is committed to the EEA but no country or data centre is named, and the site's public IP is a Cloudflare anycast address that tells you nothing about where data actually sits
  • Automated triage that drafts decision rationales invites analysts to rubber-stamp the machine: the audit trail will look consistent whether or not anyone genuinely reviewed the case
Setup

Setup & Integrations

Technical difficulty

Two different levels of effort. On the business side, setup is deliberately light: scenarios come from a ready-made library, new rules are announced as implementable in under 24 hours, and the workflow builder works by drag and drop with no IT support required. On the technical side, the work is real: the API has to be wired into a CRM or core banking system, credentials obtained and the sandbox exercised, and the on-premise option assumes infrastructure and a team to run it. Deployment is announced at 48 hours for SaaS and 45 days on-premise. There is no self-service path.

Deployment

Web appAPI

Integrations

Power BI
Company

Behind Complytek CLM

Company name
COMPLYTEK.AI LTD
Founded
INFORMATION_NOT_FOUND
Country of origin
🇨🇾 Cyprus
Headquarters
178 Omirou, 1st Floor, 7102, Aradippou, Larnaca, Cyprus
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Complytek CLM.

S Salv
FAQ

Frequently asked questions

What does the Complytek CLM platform actually cover?
Onboarding, KYC and KYB, customer and enhanced due diligence, sanctions and PEP screening, risk scoring, live and post-transaction monitoring, fraud detection, alerts and case management, reporting and audit trails, all running on one data set rather than on separate systems.
What is Butterfly, and do I need to be a Complytek customer to use it?
Butterfly is Complytek's agentic AI module. It absorbs repetitive low-cognitive work, pre-sorts alerts by contextual risk and drafts decision rationales aligned with your own precedents. It is sold both as an addition to the Complytek platform and as a standalone module that plugs into an existing environment, so you do not have to be a customer already.
Is it available as SaaS or on-premise?
Both. Complytek announces deployment in 48 hours for the SaaS version and 45 days for the on-premise version.
How much does it cost?
No price is published. Pricing comes from a quotation after a demonstration or a free consultation. The vendor claims a cost 15% below traditional systems, but does not name what it is comparing against, and the pricing calculator linked from its comparison page is offline.
Do I need developers to create a monitoring rule?
No. The platform ships with 300 to 350 ready-made rules, offers a drag-and-drop workflow builder, and states that compliance teams can implement a new rule in under 24 hours without IT support.
Is there an API?
Yes. The iKYC API is publicly documented at api.ikyc.eu and covers transaction screening, ongoing and ad-hoc monitoring, electronic document verification, digital identity verification, fraud risk assessment and biometric facial recognition. A sandbox environment is included at no extra cost.
Where is the data processed?
The privacy policy states that personal data is processed within the European Economic Area. No specific country or data centre is named, and no hosting subcontractor is disclosed.
What certifications does the vendor hold?
Complytek claims ISO 27001:2022 certification and GDPR compliance for itself, and states that the Butterfly agents comply with the EU AI Act, Regulation (EU) 2024/1689. The accreditations page shows further logos, but they are published as images and cannot be read from the page text.
Is there a free plan or a free trial?
Neither is documented. The entry point is a demonstration or a free consultation, and the API sandbox is available to customers at no additional cost.
Who is behind the product?
COMPLYTEK.AI LTD, based at 178 Omirou in Aradippou, Larnaca, Cyprus. The company grew out of i-Spiral, a software vendor founded in 2007, and is co-founded by Christos Ttiniozou, chief executive, and Anastasios Ttiniozou, chief operating officer.
Conclusion

Should you pick Complytek CLM?

Complytek makes a coherent case. Instead of stitching together a verification vendor, a monitoring vendor and a case management vendor, a compliance team gets one chain on one data set, with a real choice between hosted and on-premise delivery, and an agentic layer in Butterfly that can be bolted onto a legacy stack rather than replacing it. The named client base in Cypriot and regional banking, the ISO 27001:2022 certification and the promise of a dedicated account manager with human support all point at a vendor that knows its market and sells to it seriously.

The reservations are about what the site does not publish rather than about the product. There is no price anywhere, and the single pricing link on the site leads to a development app that has gone offline, which is a poor signal on a page written to win a competitive comparison. There are no terms of service and no legal notice: the company's legal identity has to be recovered from the privacy policy. No data processing agreement is published and no subprocessor is named, which is unusual for a vendor that handles identity and payment data on behalf of regulated clients. Every performance figure, from 80% fewer false positives to 48-hour deployment, is stated without a method.

One point deserves care. The company's own account, its first web archive capture and the Cypriot commercial register give three different origin dates, which is why no constitution date is recorded here. None of this makes the platform weaker, but it does mean a buyer should expect to ask for the contract, the subprocessor list, a DPA and the basis of the performance claims in writing before signing.