
Complytek CLM
Complytek CLM is a unified KYC, AML and fraud platform for financial institutions, covering onboarding, screening, risk scoring, transaction monitoring and case management, with an agentic AI module called Butterfly that triages alerts inside existing systems.
What is Complytek CLM?
Complytek CLM is the client lifecycle management platform built by Cypriot vendor COMPLYTEK.AI LTD to carry a regulated firm through the whole anti-money-laundering cycle inside one system. Onboarding, KYC and KYB, due diligence, screening, risk scoring, transaction monitoring, investigation, case management, reporting and audit trails all run on the same data. That is the vendor's founding argument: these functions were historically bought from three separate suppliers and were never designed to work together.
The platform is documented as eight functional blocks. Onboarding runs through a white-label portal with CRM integration over API, liveness selfies, biometric matching and document verification. Customer due diligence screens against PEP, sanctions and adverse media lists and assigns numeric risk scores through SegmenTek, the vendor's segmentation algorithm. Transaction screening is handled by ScreenTek, which Complytek clocks at under 900 milliseconds for an individual and under 200 milliseconds for a business. Transaction monitoring ships with a rule library the product page counts as more than 300 and the homepage as more than 350, covering live and post-transaction detection. Enhanced due diligence re-screens monthly, quarterly or annually according to the client's risk profile. Workflow orchestration offers a drag-and-drop builder, case management routes alerts by severity or expertise with a full audit trail, and analytics run through Power BI.
Butterfly is the second half of the offer: agentic AI components that read data and resolve cases without disturbing the systems already in place. It absorbs repetitive low-cognitive work, pre-sorts alerts on contextual risk indicators, and drafts decision rationales aligned with the institution's own precedents so the audit trail stays consistent between analysts. Complytek sells it both as an addition to its platform and as a standalone module that plugs into any environment, which is aimed squarely at institutions locked into legacy stacks.
The product ships as SaaS or on-premise, supports SWIFT, SEPA and ISO20022, and claims ISO 27001:2022 certification, GDPR compliance and, for the agents, conformity with the EU AI Act. The vendor claims more than 100 SME and mid-market customers across the EU, UK, GCC and Africa, and names Bank of Cyprus, AstroBank, FIBANK and Windsor Brokers among them.
What it does
- Screen customers and payments against sanctions, PEP and adverse media lists in real time
- Monitor transactions live and after the fact, and generate suspicious activity reports
- Score and continuously re-score client risk from transaction behaviour
- Automate onboarding through a white-label portal with identity and document verification
- Triage and resolve low-value alerts with Butterfly AI agents
- Build compliance scenarios and workflows without a developer
- Explore and export compliance data through Power BI dashboards
When to use Complytek CLM / When not to
A quick filter to help you decide if Complytek CLM is the right fit.
When to use Complytek CLM
- Compliance teams at mid-market banks, EMIs, fintechs and payment firms that need onboarding, screening and monitoring on one set of data
- FX, trading and gaming operators working across several regulators at once, who need rules that differ by jurisdiction
- Institutions locked into a legacy AML stack that want agentic automation without replacing the systems they already run
- Professional services and accounting firms carrying AML obligations on behalf of their own clients
- Buyers who need an on-premise deployment rather than a hosted service, and who can run one
When not to use Complytek CLM
- Anyone expecting to sign up online: there is no self-service path, no free plan and no published price
- Small firms that need a budget figure before talking to a salesperson, since every number comes from a quote
- Teams looking for a mobile app, as the product exists only as a web platform and an API
- Buyers who want to read the service contract first, because the site publishes neither terms of service nor a legal notice
- Organisations that require a signed data processing agreement up front, as none is published or offered on the site
How to use Complytek CLM
A typical end-to-end flow, from setup to results.
- Request a demo or a free consultation, since there is no self-service sign-up
- Scope the modules you actually need, as the vendor bills only for what is selected
- Choose the delivery mode: SaaS, announced at 48 hours, or on-premise, announced at 45 days
- Import your client and transaction data and connect the source systems
- Pick the monitoring scenarios you want from the ready-made rule library
- Adjust risk factors, scoring weights and re-screening frequencies to your risk appetite
- Model your onboarding and investigation path in the drag-and-drop workflow builder
- Wire the iKYC API into your CRM or core banking system and test against the sandbox
- Route alerts and cases to analysts by severity or expertise, and add Butterfly agents for triage
- Build reporting in Power BI and export audit-ready case files
Pros & Cons
Pros
- The whole compliance chain comes from one vendor, which removes three contracts and three data models
- Compliance staff configure scenarios themselves: new rules are announced as implementable in under 24 hours with no IT support
- A ready-made rule library of 300 to 350 scenarios shortens the initial setup considerably
- A genuine choice between SaaS and on-premise, which is uncommon in this market
- Butterfly plugs into an existing stack, so agentic automation does not require replacing the AML system
- ISO 27001:2022, GDPR and EU AI Act compliance are claimed, and personal data is processed within the EEA
- A dedicated account manager and fully human support are promised, in explicit contrast to chatbot queues
Cons
- No price is published anywhere: there is no pricing page in the 61-page sitemap and no figure on any product page
- The one pricing link on the site, on the Salv comparison page, leads to a Replit development app that returns a 404
- Neither terms of service nor a legal notice exists; the company's legal identity appears only inside the privacy policy
- No data processing agreement is published or offered, although the vendor acts as processor for its clients
- No subprocessor is named: the privacy policy lists categories of recipients only
- Performance claims such as 80% fewer false positives, 40% less investigation time and 15% lower cost come with no stated method or scope
- The awards and accreditations page is made entirely of images, so no certifying body can be read from the text
Pricing & Plans
There is no free plan and no published price. Complytek does not operate a pricing page, and the only pricing link on the site, on its Salv comparison page, points to an external calculator that is offline. Pricing is established by quotation after a demonstration or a free consultation. The vendor states that each feature is optional and that a client pays only for the modules selected, and claims a cost 15% below traditional systems without naming a basis for that comparison. The API sandbox environment is included at no additional cost.
Data, GDPR & hosting
A consolidated view of how Complytek CLM handles your data.
GDPR overview
GDPR implementation is stated in concrete terms. The privacy policy invokes Regulation (EU) 679/2016 and Cypriot Law 125(I)/2018, and says data protection sits inside an ISO 27001:2022 certified system. It lists the legal bases under Article 6, enumerates the full set of data subject rights, commits to a one-month response extendable by two under Article 12.3, and undertakes to notify the Cypriot supervisory authority within 72 hours of a breach under Articles 33 and 34. Minors' data is not collected without verifiable parental consent under Article 8, though no minimum age is stated. Personal data is processed within the European Economic Area. The policy has been in force since 20 January 2025. As the company is established in Cyprus, no Article 27 representative is designated or required.
Who owns the data?
COMPLYTEK.AI LTD describes itself in two roles. It acts as controller for the data it collects directly, chiefly contact, identification, payment and recruitment data, and names a Chief Information Security Officer at dpo@complytek.ai, Aradippou, Cyprus, as the point of contact. Where third parties, usually companies, pass it personal data, it acts only as processor on their behalf, and it states plainly that those companies remain responsible for informing data subjects and for answering their rights requests. In practice, a client institution keeps ownership of the records it processes through the platform. No data processing agreement is published or offered, and no subcontractor is named.
Reuse rights
The privacy policy is written from the vendor's own side and does not grant, restrict or otherwise describe any right for a client to reuse data extracted from the platform. Complytek relies on consent, contractual performance, legal obligation and legitimate interest as its legal bases, and it states that it makes no decision based solely on automated processing, profiling included. Where it acts as processor, the client controller sets the terms. One point is left open on the product side: the site says machine learning modules improve risk scoring by learning from the client's own decisions and that the system learns from past cases, but it never says whether that learning stays inside the client's tenant or feeds shared models. There is no documented way to opt out of it.
Data retention & training
Hosting summary
The privacy policy makes one explicit commitment on location: personal data collected by Complytek is processed within the European Economic Area. Beyond that, nothing is specified. No country is named, no data centre is identified, and no hosting provider or subprocessor is disclosed. The policy lists categories of recipients, such as supervisory and judicial authorities, the company's auditor and lawyer, partner banks for payment data and training consultants, but names no organisation. Complytek states that data protection sits inside an ISO 27001:2022 certified information security management system, with access restricted to authorised staff on a need-to-know basis and confidentiality agreements in place. The on-premise deployment option implies that data can remain on the client's own infrastructure, but the site never presents this as a hosting guarantee. The website's own public IP resolves to a Cloudflare anycast address, which carries no information about where customer data is held.
Things to keep in mind
Risks and trade-offs to weigh before adopting Complytek CLM.
- No published price means the budget can only be discovered at the end of a sales cycle, which makes early comparison with competitors impossible
- With no terms of service and no legal notice, the contractual terms cannot be read before making contact
- No data processing agreement is published even though the vendor acts as processor for its clients: insist on one during negotiation
- Subprocessors are not named, only categories of recipients, so the real chain of custody over client data is not visible
- The models learn from the client's own decisions and past cases, but nothing states whether that learning stays inside the tenant, and no opt-out is documented
- Hosting is committed to the EEA but no country or data centre is named, and the site's public IP is a Cloudflare anycast address that tells you nothing about where data actually sits
- Automated triage that drafts decision rationales invites analysts to rubber-stamp the machine: the audit trail will look consistent whether or not anyone genuinely reviewed the case
Setup & Integrations
Technical difficulty
Two different levels of effort. On the business side, setup is deliberately light: scenarios come from a ready-made library, new rules are announced as implementable in under 24 hours, and the workflow builder works by drag and drop with no IT support required. On the technical side, the work is real: the API has to be wired into a CRM or core banking system, credentials obtained and the sandbox exercised, and the on-premise option assumes infrastructure and a team to run it. Deployment is announced at 48 hours for SaaS and 45 days on-premise. There is no self-service path.
Deployment
Integrations
Behind Complytek CLM
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Complytek CLM.
Frequently asked questions
What does the Complytek CLM platform actually cover?
What is Butterfly, and do I need to be a Complytek customer to use it?
Is it available as SaaS or on-premise?
How much does it cost?
Do I need developers to create a monitoring rule?
Is there an API?
Where is the data processed?
What certifications does the vendor hold?
Is there a free plan or a free trial?
Who is behind the product?
Should you pick Complytek CLM?
Complytek makes a coherent case. Instead of stitching together a verification vendor, a monitoring vendor and a case management vendor, a compliance team gets one chain on one data set, with a real choice between hosted and on-premise delivery, and an agentic layer in Butterfly that can be bolted onto a legacy stack rather than replacing it. The named client base in Cypriot and regional banking, the ISO 27001:2022 certification and the promise of a dedicated account manager with human support all point at a vendor that knows its market and sells to it seriously.
The reservations are about what the site does not publish rather than about the product. There is no price anywhere, and the single pricing link on the site leads to a development app that has gone offline, which is a poor signal on a page written to win a competitive comparison. There are no terms of service and no legal notice: the company's legal identity has to be recovered from the privacy policy. No data processing agreement is published and no subprocessor is named, which is unusual for a vendor that handles identity and payment data on behalf of regulated clients. Every performance figure, from 80% fewer false positives to 48-hour deployment, is stated without a method.
One point deserves care. The company's own account, its first web archive capture and the Cypriot commercial register give three different origin dates, which is why no constitution date is recorded here. None of this makes the platform weaker, but it does mean a buyer should expect to ask for the contract, the subprocessor list, a DPA and the basis of the performance claims in writing before signing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.