Coris
Coris is an AI merchant risk platform for the payments ecosystem, covering onboarding, underwriting, fraud detection and continuous portfolio monitoring. It is processor-agnostic, SOC 2 Type II certified, and sold only through a sales-led demo.
What is Coris?
Coris is an AI-driven merchant risk platform built by Coris, Inc. in Palo Alto, California, for the companies that onboard and monitor merchants: SaaS platforms with embedded payments, ISOs, payment facilitators, acquiring and sponsor banks, marketplaces, BNPL providers, B2B payments companies and lenders. It is not a payment processor and not a consumer product; it is the risk layer that sits alongside processors such as Stripe, Adyen, TSYS and Fiserv.
The offering breaks into five blocks. Risk Platform holds the rules engine, case management, a signal library, account tags, merchant rollups, an exposure calculator, reporting and a full audit trail. Merchant Intelligence, sold as MerchantProfiler, returns hundreds of structured signals per merchant: business registration and sanctions screening, AI-predicted MCC and NAICS classification, website screening and a SiteRating score, MerchantVision site inspection through Google Street View, litigation and bankruptcy checks, business closure detection, bank account verification, online reputation, device and IP intelligence, and email and phone validation. CorShield, the fraud model, scores the likelihood of business impersonation and first-party fraud from the applicant's email, IP address, phone, website and online reputation. Transaction Monitoring scores card and ACH payments in real time, applies transaction rules and controls payouts; it is reserved for payments customers. AI Agents summarise cases, answer questions about merchant history in plain language, follow written procedures to decide or escalate, and reach out to merchants, moving from assistive to fully autonomous as trust builds. Managed Risk, the newest block, has Coris run the whole risk programme on the customer's behalf, with the option to take it back in-house later.
Access is through the no-code Coris Portal or the Coris API, whose documentation is password-protected. The company claims more than 1.5 million merchants monitored, over 50 billion dollars in transaction volume, an 80% cut in manual reviews and 5x first-year ROI, and names customers including Weave, Quilt, Zift, Ignition, Kajabi, Tekmetric and Mindbody. It holds SOC 2 Type II certification. No pricing is published anywhere on the site.
What it does
- Automate merchant onboarding and underwriting decisions
- Verify business identity through registry checks, sanctions screening, TIN matching and bank verification
- Score merchant fraud risk, including business impersonation and first-party fraud
- Monitor card and ACH transactions in real time and hold or block risky payments
- Watch a portfolio continuously for business closures, litigation, adverse media and website changes
- Hand routine alerts and cases to AI agents that escalate edge cases to analysts
- Pause or delay merchant payouts automatically when risk rules trigger
When to use Coris / When not to
A quick filter to help you decide if Coris is the right fit.
When to use Coris
- Risk and compliance teams at SaaS platforms with embedded payments
- ISOs and payment facilitators onboarding merchants at volume
- Acquiring and sponsor banks that must keep continuous oversight of a partner portfolio
- Marketplaces, BNPL providers and lenders exposed to business impersonation fraud
- Fintechs launching payments without an in-house risk function, through the Managed Risk offering
When not to use Coris
- Individual merchants and small businesses: Coris serves the companies that underwrite them, not the merchants themselves
- Consumer-facing teams looking for personal fraud or identity protection
- Buyers who need published pricing or a self-serve signup, since every path leads to a sales demo
- Engineering teams that want to evaluate the API before contracting, as the developer documentation sits behind a password
- Organisations that require a signed DPA, a published subprocessor list or a guaranteed EU hosting region
How to use Coris
A typical end-to-end flow, from setup to results.
- Estimate the size of the problem with the free ROI Calculator and Merchant Exposure Calculator, both open without an account
- Request a demo through the contact form, the only entry point since there is no self-serve signup
- Scope the engagement commercially and sign an Order Form, which defines the modules, the term and the fees
- Let the Coris team handle the integration and setup, a phase the company frames as weeks rather than months
- Connect the payment processor, whether Stripe Connect, Adyen AfP, TSYS or Fiserv, to sync merchant and transaction data
- Connect the supporting stack: Salesforce, Zendesk, Intercom or Slack for outreach, Snowflake or Redshift for warehouse data
- Work with Coris risk experts to translate the underwriting policy into rules, thresholds and automated actions
- Run day-to-day work in the Coris Portal: merchant profiles, alerts, cases and portfolio dashboards
- Call the Coris API directly for merchant screening, onboarding and monitoring inside existing systems
- Start with assistive AI agents, then hand them routine decisions, and review performance in the periodic optimisation sessions
Pros & Cons
Pros
- Covers the full merchant lifecycle — onboarding, underwriting, monitoring and disputes — and can be adopted workflow by workflow rather than as an all-or-nothing suite
- Processor-agnostic by design, unlike risk tooling tied to a single processor's data
- Named, quantified customer results: Weave reports 89% fewer manual reviews, Quilt roughly two-thirds less review time, Tekmetric 70%, Zift 30%
- Unusually detailed feature disclosure, including a public page written specifically to state what the product is and is not
- SOC 2 Type II certified, with built-in audit trails on every action and event
- AI agents keep a human escalation path rather than removing analysts from the loop
- Founding team built risk systems at JP Morgan Chase, PayPal, Google and eBay, with wider team experience at Adyen, LinkedIn and ServiceTitan
Cons
- No pricing is published: the pricing URL returns a 404 and no tariff link exists anywhere on the site
- No free plan, no free trial and no self-serve signup — a sales demo is the only way in
- The API documentation sits behind a password, so technical evaluation is impossible before contracting
- No DPA is published, no subprocessor list exists, and the Vanta Trust Center renders only in JavaScript
- The word GDPR appears nowhere on the site, and no EU representative is designated
- The privacy policy dates from February 2023 and contains a visibly corrupted paragraph plus a Terms of Service link that points back to itself
- Payment obligations are non-cancellable and non-refundable, fees can be revised at each renewal on 60 days' notice, and the service is supplied as is with no published SLA
Pricing & Plans
There is no free plan and no free trial, and Coris publishes no price of any kind: the pricing URL returns a 404 and no tariff link appears anywhere on the site. Commercial terms are set individually in an Order Form signed by both parties, with invoices payable within thirty days of receipt. All payment obligations are stated as non-cancellable and non-refundable, late amounts carry a charge of 1.5% per month, and Coris reserves the right to revise fees or introduce new charges at the end of each contract term on sixty days' notice. Fees are quoted exclusive of taxes. Only two tools are available at no cost and without an account: the ROI Calculator and the Merchant Exposure Calculator.
- No public plan or price tier is published
- the commercial scope is defined in a signed Order Form
- Risk Platform — rules engine
- case management
- signal library
- reporting and audit trail
- Merchant Intelligence (MerchantProfiler) — structured merchant signals
- KYB verification and the CorShield fraud model
- Transaction Monitoring — real-time card and ACH scoring
- available to payments customers only
- AI Agents — assistive
- semi-automated and autonomous agents for risk workflows
- Managed Risk — risk operations run by Coris on the customer's behalf
- marked as a new offering
Data, GDPR & hosting
A consolidated view of how Coris handles your data.
GDPR overview
The site never uses the word GDPR. There is no compliance claim, no dedicated section, no Article 27 representative and no named data protection officer. The privacy policy, last updated 10 February 2023, does list rights that closely mirror the regulation — access, copies, rectification, erasure, restriction, objection, withdrawal of consent, portability, disclosure of recipients and the right to complain to an authority — but presents them as arising under applicable law generally rather than under EU law. Transfers to the United States, Europe or elsewhere rest on user consent, with no transfer mechanism named: no standard contractual clauses, no Data Privacy Framework. No DPA is published or offered and no subprocessor list exists. For customer records, Coris positions itself as a processor. The only certification claimed is SOC 2 Type II.
Who owns the data?
Under the Terms of Service, the customer owns and retains its Customer Data, its name and logos, and every intellectual property right attached to them. Coris retains the Services, the documentation, any technology it builds, its own trademarks, and the Usage Data derived from how the platform is used, excluding customer content. By contracting, the customer authorises Coris and its subprocessors to access, process, store and use Customer Data as needed to deliver the service. Feedback is licensed to Coris worldwide, royalty-free and sublicensable. For the merchant and end-customer records it processes, Coris acts as a processor and redirects data subjects to its own customer rather than answering them directly.
Reuse rights
The customer keeps its data and may reuse it without asking Coris for permission; nothing in the terms restricts what it does with its own Customer Data. Coris states that it does not sell, license or share personal data with unaffiliated third parties for their own marketing. It processes data to run accounts, provide support, bill, prevent abuse, meet legal obligations and, with consent, send marketing. Usage data is analysed to improve the platform, and any insight shared externally must be de-identified first. Anonymous data derived from personal data may be used for any lawful business purpose, including publicly. Do Not Track signals are not honoured. Customers may not resell the Services or use them to build a competing product.
Data retention & training
Hosting summary
The privacy policy states that Coris may store, process and transmit data in the United States and in locations around the world, including outside the user's own country, and that by using the service the user consents to transfers to facilities in the United States, Europe or elsewhere, including those of third parties. No hosting region is guaranteed, offered as an option or named beyond that. The official information page adds only that the platform has multi-cloud support, without naming a cloud provider or a data centre location. Consent is the sole basis given for international transfers: no standard contractual clauses, adequacy decision or Data Privacy Framework certification is mentioned. The Vanta Trust Center, which would normally answer these questions, renders entirely in JavaScript and returns no readable content. The website itself is served through Cloudflare and built on Webflow, which says nothing about where platform data lives.
Things to keep in mind
Risks and trade-offs to weigh before adopting Coris.
- Budgeting is impossible before engaging sales: no price exists publicly, and payment obligations are non-cancellable and non-refundable once signed
- Fees can be revised and new charges introduced at the end of each term on only sixty days' notice, so renewal costs are not predictable
- The service is supplied as is with no availability guarantee and no published SLA, while liability is capped at the fees paid over the preceding twelve months
- European buyers face a documentary gap: no DPA, no subprocessor list, no Article 27 representative, no named transfer mechanism, and no guaranteed hosting region
- The vendor's position on training models with customer data is never stated, and no opt-out is documented — a blind spot worth resolving contractually
- Automating underwriting decisions concentrates real consequences in rule configuration: a badly calibrated agent can decline legitimate merchants at scale before anyone notices
- Californian governing law and exclusive jurisdiction in Palo Alto make disputes costly for a non-US customer
Setup & Integrations
Technical difficulty
Low for the customer, but slow to start. There is no self-signup: setup begins with a sales cycle and a signed Order Form. Coris then handles the integration and setup itself, framing go-live as weeks rather than months, and its risk experts help translate the underwriting policy into rules. Day-to-day use requires no code through the Coris Portal, while technical teams can call the API instead. The practical obstacle is evaluation, not implementation: the developer documentation is password-protected, so integration effort cannot be assessed before contracting.
Deployment
Integrations
Behind Coris
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Coris.
Frequently asked questions
Who is Coris built for?
How much does Coris cost?
Is there a free trial or a free plan?
Does Coris replace my payment processor?
Is there an API, and can I read the documentation?
Where is customer data hosted?
Who owns the data I put into Coris?
Is my data used to train Coris models?
What certifications does Coris hold?
How long does deployment take?
Should you pick Coris?
Coris is a narrow, serious B2B product rather than a general-purpose AI tool. It addresses one problem — deciding whether a merchant should be onboarded, and noticing when that answer changes — and it addresses it across the whole lifecycle instead of stopping at a KYB check. The functional depth is real and unusually well documented: five product blocks, dozens of named signals, seventeen named integrations, and customer outcomes attributed to identifiable companies rather than to anonymous averages. Processor independence is a genuine differentiator for anyone running more than one acquiring relationship.
The reservations are commercial and documentary rather than functional. Nothing about the cost can be established before entering a sales cycle: there is no price, no trial and no self-serve path, and the API documentation is locked, which prevents even a technical assessment upfront. The legal corpus has aged — the privacy policy is from February 2023, carries a visibly corrupted paragraph, and never once mentions the GDPR. No DPA, no subprocessor list, no EU representative and no guaranteed hosting region will make a European buyer's procurement review slower than it needs to be. Marketing figures also drift slightly between pages, with merchant counts and country coverage stated differently on the homepage and on the company's own official information page.
For a risk team that already knows it needs this category, has a budget and can run a procurement cycle, Coris deserves a place on the shortlist alongside the KYB providers it names itself. For anyone still exploring, or bound by strict European data governance requirements, the questions to settle before signing are entirely predictable: price, contractual commitments, and everything the Trust Center would have answered had it been readable.
- Choosing a selection results in a full page refresh.
- Opens in a new window.