● Project demo — Cauce IA
Pre-credit compliance verification · Pre-incorporation research project · LATAM

Verified compliance and an auditable trace, before every credit decision.

Cauce installs inside the financial institution's infrastructure and verifies compliance on every credit decision before it is executed. It does not route applications, does not score the applicant and does not take the decision. Your customers' data never leaves your infrastructure.

Compliance verification Inside your infrastructure Auditable trace 7 LATAM jurisdictions
Credit pipeline · v2.3
trace #EC-48213
1Data extractionthe institution's
2Profiling & scoringthe institution's
3Compliance (CASE)halluc. 0.62%
4Issuancethe institution's
Check it yourself ▶
run the benchmark in your browser
7
LATAM jurisdictions · one integration
0
Decisions Cauce makes — it delivers signals, doesn't decide
−77.9%
Compliance false positives · reproducible reference run
15.57%
Undecidable cases · the provider chain is not enough to conclude
What Cauce does not do
  • It holds no contractual relationship and no contact with the credit applicant. Consent is obtained by the institution. The applicant is not aware that Cauce exists.
  • It does not receive, route, refer or distribute credit applications. It does not route to lenders and does not generate offers. It originates no business for the institution or for third parties.
  • It issues no credit recommendations, does not score the applicant and does not replace the institution's scoring engine.
  • It takes no part in the decision to grant or deny credit, and assumes no responsibility for it.
  • The software runs entirely inside the institution's infrastructure: Cauce does not process, store or access customer data outside that infrastructure, and no information leaves it. Sanctions and PEP screening runs inside that same perimeter.
  • It is not a regulated financial service and provides none of the services subject to registration or authorisation in the jurisdictions where it operates.
How it works

The institution's credit pipeline — and where Cauce operates.

Cauce is not the pipeline: it is one stage of it. The others belong to the institution.

📥

1 · Extraction

The institution obtains the applicant's data with the applicant's consent. Cauce takes no part and obtains no consent.

📊

2 · Profiling

The institution's own scoring engine. Cauce does not score the applicant and does not replace that engine.

⚖️

3 · Compliance verification

This is where Cauce operates. It checks the decision already reached against rules configured by the institution: due diligence, sanctions and PEP lists, limits and policy, consent. It requires human confirmation where the law demands it, generates the explanation of the decision, and keeps the audit trail.

🏦

4 · Issuance

The institution executes its decision. Cauce takes no part.

Product

A compliance layer over credit.

Cauce does not compete with the institution's decision engine: it verifies its decisions and keeps the evidence.

🧬

Self-evolution under control

Loop: execute → evaluate → modify → verify → retain, always in a sandbox and validated by CASE before production. It never changes live on its own — rollback and human oversight.

🔎

Full explainability

Every decision comes with a readable explanation traceable to the source data. Ready for XAI audits.

🌎

Multi-country

Configurable rules per jurisdiction: Ecuador, Mexico, Brazil, Colombia, Chile, Peru, Argentina.

API-first

Versioned REST/JSON, signed webhooks and a synthetic-data sandbox to integrate in days, not months.

Who it is for

Supervised institutions with their own credit pipeline.

Banks, credit unions and cooperatives, finance companies and supervised credit fintechs. Licensing is to the financial institution, never to the public: the only contractual customer is the supervised institution.

Public proof · CACE-Bench

Quality that’s measured, open and reproducible.

CACE-Bench is an open synthetic benchmark (MIT) for evaluating credit AI. Its reference run regenerates byte for byte from a single command: compliance false positives from 22.51% to 4.96% (−77.9%) over 23,000 synthetic cases, seed 0, with 95% Wilson intervals. In that same run, 15.57% of cases come out undecidable: the provider chain is not enough to conclude. Figures from a synthetic benchmark, illustrative of the method and not of production performance. Validation on production data has not been done.

0.62%
Hallucination (2.55% → 0.62%) · repository reference run
97.70%
Step-level correctness (86.98% → 97.70%) · repository
−77.9%
Repository reference run (22.51% → 4.96%) · byte-for-byte reproducible
View the code on GitHub View the archive on Zenodo — DOI 10.5281/zenodo.21394049 · v0.4.1
Compliance by design

Built for the regulator, not in spite of it.

The CASE compliance engine audits every AI decision and maps its metrics to the region's regulatory frameworks. Its methodology and a reproducible synthetic benchmark are open — CACE-Bench: measure us against our own standard. Encrypted data, consent and data-subject rights.

Bacen · COAF · Brazil CNBV · UIF · Mexico SFC · SES · UIAF · Colombia Superintendencia de Bancos · Ecuador SEPS · UAFE · Ecuador (COAC) SBS · UIF · Perú BCRA · UIF · Argentina CMF · Chile Data protection / XAI CACE-Bench · open standard ↗
Security & data

Trust through reproducibility, not through a seal.

On-premise or in the institution's own private cloud. No transfer of information outside the institution's infrastructure or outside the customer's jurisdiction. The regulatory obligation rests with the institution; Cauce produces the evidence with which it is demonstrated. Cauce is today a research project at a stage prior to incorporating a legal entity: we do not claim organizational certifications we do not yet hold.

What is true today

Encryption in transit and at rest. Data minimization: the demo persists no personal data and the benchmark runs on synthetic data. Per-tenant isolation. We do not resell or monetize data. Per-country residency as a design option.

Data role

Cauce acts as a processor by design: the controller is the obligated party. Non-delegation clause — scoring, the decision and the report to the FIU stay with the client. We deliver signals and attributions, not a solvency assessment.

Path to certification (post-incorporation)

On the roadmap, to begin once the entity is incorporated: SOC 2 Type II, ISO/IEC 27001, 27017 and 27018, ISO/IEC 42001; subprocessor registry, incident SLA and DPA templates. Current status: not audited — we will publish each milestone with its date.

About the project

A research project — with a name and a face.

Cauce is a project of Digital Economy Lab focused on regulatory verification prior to the credit decision in Latin America. It is at a stage prior to incorporating a legal entity: we say so plainly, because in RegTech traceability starts with transparency about who is behind it.

Authorship

The open CACE-Bench benchmark and the reference agent are authored by Ravil Akhtyamov — Head of research project, Digital Economy Lab.

Affiliation disclosure

Cauce and Digital Economy Lab are affiliated. To avoid conflict of interest, the lab does not audit Cauce deployments, and this affiliation is disclosed in the benchmark methodology. CACE-Bench evaluates third-party models and agents by the same standard.

Contact

[email protected] · Open CACE-Bench repository: github.com/rav11l/cace-bench

Put Cauce to the test on a real flow, at no cost.

Request a demo or early access to the pilot. We reply within 48 hours. The pilot is free; we define the scope and success metrics together.

✓ Thanks! We'll be in touch soon.
By submitting you agree to be contacted by the Cauce team. No spam.
Verification ready for your regulator — and checkable in your browser
Every control mapped to your country's rule. And the benchmark that measures it runs right here, no backend. Cauce verifies compliance and leaves a trace; the decision stays with the lender.

Verification by regulator

CountryRegulator · FIUVerifies before the decision
PeruSBS / UIF-PerúDue diligence and enhanced regime, sanctions and PEP lists (Res. SBS 2660-2015); human oversight and documentation of the logic and of the data sources in high-risk systems (Ley 31814 and DS 115-2025-PCM; deadline for the financial sector: 10.09.2026).
ChileCMF / UAFDue diligence, sanctions and PEP lists (Ley 19.913); right to object to decisions based solely on automated processing and, where the exceptions apply, guarantees of human intervention, expression of the data subject's point of view and review (Ley 21.719, art. 8° bis; full effect expected 01.12.2026).
BrazilBACEN / COAFIndependent model validation, backtesting and documentation of stress testing (Res. CMN 4.557/2017, arts. 9 and 12); right to request review of automated decisions (LGPD art. 20).
MexicoCNBV / UIFKYC and a 10-year file; risk-based customer classification with semi-annual reassessment and automated monitoring and alerting mechanisms (Reglas de la LFPIORPI, as amended by Acuerdo 115/2026, DOF 07.08.2026; staged entry into force 30.11.2026 · 01.03.2027 · 01.06.2027).
ColombiaSFC · SES / UIAFRisk-based due diligence and reporting through the UIAF system (SARLAFT 4.0 — Circular Externa 027/2020); open finance system under implementation (Decreto 0368/2026).
EcuadorSEPS · SB / UAFEDue diligence, sanctions and PEP lists, consent and limits; right not to be subject to decisions based wholly or partly on automated assessment (LOPDP art. 20); a specific rule on AI and personal data requiring a prior impact assessment and an audit of the system (Resolución SPDP-SPD-2026-0009-R, RO 19.02.2026).
ArgentinaBCRA / UIFRisk-based due diligence (Res. UIF 14/2023), sanctions and PEP lists; model inventory, explainability, independent validation and assessment of external AI providers (BCRA supervisory guidance on AI, June 2026 — supervisory expectations, not binding rules).

This is not legal advice and not a certification of compliance: the regulatory obligation rests with the institution, and compliance must be assessed with local counsel.

Run the benchmark right here

CACE-Bench is pure Python: it runs in your browser via Pyodide. Reproducible run, seed 0, no server.
On click, it loads the engine once and runs 800 synthetic cases here.
And against your own pipeline?
Change two functions and run it in ~an hour:
python examples/benchmark_your_pipeline.py --demo --n 3000 python examples/benchmark_your_pipeline.py --endpoint https://tu.api/verify See the adapter (Case → Narrative) →
Figures illustrative of the method on synthetic data, not production; validation on production data has not been done.